# Elasticsearch heap Memory WARNING in elk docker

**URL:** <https://discuss.elastic.co/t/elasticsearch-heap-memory-warning-in-elk-docker/277419>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [June 30, 2021, 6:54am UTC](https://discuss.elastic.co/t/elasticsearch-heap-memory-warning-in-elk-docker/277419 "2021-06-30T06:54:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ranu\_shekhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranu_shekhar/32/50134_2.png) [@ranu\_shekhar](https://discuss.elastic.co/u/ranu_shekhar)\
**Post date:** [June 30, 2021, 6:54am UTC](https://discuss.elastic.co/t/elasticsearch-heap-memory-warning-in-elk-docker/277419/1 "2021-06-30T06:54:37Z")

</div>

Hi,  
I am using elasticsearch 7.10.0. I have 3 nodes in my cluster. But in one of the node among 3, we are receiving given below warning logs:  
\*\*{"type": "server", "timestamp": "2021-06-30T04:01:53,805Z", "level": "WARN", "component": "o.e.m.j.JvmGcMonitorService", "cluster.name": "nfvi-elkstack", "node.name": "data2", "message": "[gc][young][6718527][787252] duration [1.9s], collections [1]/[2.1s], total [1.9s]/[7.2h], memory [3.5gb]-\>[2.9gb]/[5gb], all\_pools {[young] [656mb]-\>[20mb]/[0b]}{[old] [2.8gb]-\>[2.8gb]/[5gb]}{[survivor] [28mb]-\>[59mb]/[0b]}", "cluster.uuid": "7yrxdBQBRPinZlUz6CwDRw", "node.id": "6JnyYl3PTgqXFthT17wPAw" }

Is there any way to resolve this because due to this CPU Utilization for this particular node is coming very high.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 30, 2021, 6:55am UTC](https://discuss.elastic.co/t/elasticsearch-heap-memory-warning-in-elk-docker/277419/2 "2021-06-30T06:55:41Z")

</div>

What is the output from the `_cluster/stats?pretty&human` API?

---

<div class="post-metadata">

**Author:** ![ranu\_shekhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranu_shekhar/32/50134_2.png) [@ranu\_shekhar](https://discuss.elastic.co/u/ranu_shekhar)\
**Post date:** [June 30, 2021, 6:58am UTC](https://discuss.elastic.co/t/elasticsearch-heap-memory-warning-in-elk-docker/277419/3 "2021-06-30T06:58:05Z")

</div>

> [@warkolm](#):
>
> \_cluster/stats?pretty&human

{"\_nodes":{"total":3,"successful":3,"failed":0},"cluster\_name":"nfvi-elkstack","cluster\_uuid":"7yrxdBQBRPinZlUz6CwDRw","timestamp":1625035659072,"status":"green","indices":{"count":238,"shards":{"total":788,"primaries":394,"replication":1.0,"index":{"shards":{"min":2,"max":6,"avg":3.310924369747899},"primaries":{"min":1,"max":3,"avg":1.6554621848739495},"replication":{"min":1.0,"max":1.0,"avg":1.0}}},"docs":{"count":2097202739,"deleted":334944},"store":{"size\_in\_bytes":865627576770,"reserved\_in\_bytes":0},"fielddata":{"memory\_size\_in\_bytes":2009272,"evictions":0},"query\_cache":{"memory\_size\_in\_bytes":1051393983,"total\_count":973926615,"hit\_count":93019708,"miss\_count":880906907,"cache\_size":11497,"cache\_count":1552335,"evictions":1540838},"completion":{"size\_in\_bytes":0},"segments":{"count":9005,"memory\_in\_bytes":381411016,"terms\_memory\_in\_bytes":130261152,"stored\_fields\_memory\_in\_bytes":98710448,"term\_vectors\_memory\_in\_bytes":0,"norms\_memory\_in\_bytes":6245824,"points\_memory\_in\_bytes":0,"doc\_values\_memory\_in\_bytes":146193592,"index\_writer\_memory\_in\_bytes":515950884,"version\_map\_memory\_in\_bytes":396,"fixed\_bit\_set\_memory\_in\_bytes":108472,"max\_unsafe\_auto\_id\_timestamp":1625011201270,"file\_sizes":{}},"mappings":{"field\_types":[{"name":"alias","count":252,"index\_count":84},{"name":"binary","count":12,"index\_count":2},{"name":"boolean","count":3721,"index\_count":140},{"name":"byte","count":87,"index\_count":87},{"name":"date","count":3534,"index\_count":223},{"name":"double","count":2548,"index\_count":84},{"name":"flattened","count":10,"index\_count":2},{"name":"float","count":5010,"index\_count":114},{"name":"geo\_point","count":588,"index\_count":84},{"name":"geo\_shape","count":1,"index\_count":1},{"name":"integer","count":52,"index\_count":4},{"name":"ip","count":1540,"index\_count":84},{"name":"keyword","count":58431,"index\_count":229},{"name":"long","count":147017,"index\_count":212},{"name":"nested","count":17,"index\_count":7},{"name":"object","count":132325,"index\_count":209},{"name":"scaled\_float","count":8933,"index\_count":85},{"name":"short","count":7,"index\_count":4},{"name":"text","count":4742,"index\_count":165}]},"analysis":{"char\_filter\_types":,"tokenizer\_types":,"filter\_types":,"analyzer\_types":,"built\_in\_char\_filters":,"built\_in\_tokenizers":,"built\_in\_filters":,"built\_in\_analyzers":}},"nodes":{"count":{"total":3,"coordinating\_only":0,"data":2,"data\_cold":2,"data\_content":2,"data\_hot":2,"data\_warm":2,"ingest":3,"master":1,"ml":3,"remote\_cluster\_client":3,"transform":2,"voting\_only":0},"versions":["7.10.0"],"os":{"available\_processors":36,"allocated\_processors":36,"names":[{"name":"Linux","count":3}],"pretty\_names":[{"pretty\_name":"CentOS Linux 8 (Core)","count":3}],"mem":{"total\_in\_bytes":13958643712,"free\_in\_bytes":166309888,"used\_in\_bytes":13792333824,"free\_percent":1,"used\_percent":99}},"process":{"cpu":{"percent":35},"open\_file\_descriptors":{"min":588,"max":12964,"avg":8729}},"jvm":{"max\_uptime\_in\_millis":6736124784,"versions":[{"version":"15.0.1","vm\_name":"OpenJDK 64-Bit Server VM","vm\_version":"15.0.1+9","vm\_vendor":"AdoptOpenJDK","bundled\_jdk":true,"using\_bundled\_jdk":true,"count":3}],"mem":{"heap\_used\_in\_bytes":7449201120,"heap\_max\_in\_bytes":11274289152},"threads":391},"fs":{"total\_in\_bytes":1571892805632,"free\_in\_bytes":491849428992,"available\_in\_bytes":491849428992},"plugins":,"network\_types":{"transport\_types":{"netty4":3},"http\_types":{"netty4":3}},"discovery\_types":{"zen":3},"packaging\_types":[{"flavor":"default","type":"docker","count":3}],"ingest":{"number\_of\_pipelines":3,"processor\_stats":{"convert":{"count":244,"failed":0,"current":0,"time\_in\_millis":9},"csv":{"count":244,"failed":0,"current":0,"time\_in\_millis":16},"gsub":{"count":0,"failed":0,"current":0,"time\_in\_millis":0},"remove":{"count":244,"failed":0,"current":0,"time\_in\_millis":0},"script":{"count":0,"failed":0,"current":0,"time\_in\_millis":0}}}}}

---

<div class="post-metadata">

**Author:** ![ranu\_shekhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranu_shekhar/32/50134_2.png) [@ranu\_shekhar](https://discuss.elastic.co/u/ranu_shekhar)\
**Post date:** [June 30, 2021, 7:02am UTC](https://discuss.elastic.co/t/elasticsearch-heap-memory-warning-in-elk-docker/277419/4 "2021-06-30T07:02:18Z")

</div>

From cluster stats everything seems fine. But I can see this process has very high cpu utilization:  
sysadm 13372 13297 99 Apr13 ? 95-04:40:22 /usr/share/elasticsearch/jdk/bin/java -Xshare:auto -Des.networkaddress.cache.ttl=60 -Des.networkaddress.cache.negative.ttl=10 -XX:+AlwaysPreTouch -Xss1m -Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djna.nosys=true -XX:-OmitStackTraceInFastThrow -XX:+ShowCodeDetailsInExceptionMessages -Dio.netty.noUnsafe=true -Dio.netty.noKeySetOptimization=true -Dio.netty.recycler.maxCapacityPerThread=0 -Dio.netty.allocator.numDirectArenas=0 -Dlog4j.shutdownHookEnabled=false -Dlog4j2.disable.jmx=true -Djava.locale.providers=SPI,COMPAT -Xms1g -Xmx1g -XX:+UseG1GC -XX:G1ReservePercent=25 -XX:InitiatingHeapOccupancyPercent=30 -Djava.io.tmpdir=/tmp/elasticsearch-10070937545416279791 -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=data -XX:ErrorFile=logs/hs\_err\_pid%p.log -Xlog:gc\*,gc+age=trace,safepoint:file=logs/gc.log:utctime,pid,tags:filecount=32,filesize=64m -Des.cgroups.hierarchy.override=/ -Xms5G -Xmx5G -XX:MaxDirectMemorySize=2684354560 -Des.path.home=/usr/share/elasticsearch -Des.path.conf=/usr/share/elasticsearch/config -Des.distribution.flavor=default -Des.distribution.type=docker -Des.bundled\_jdk=true -cp /usr/share/elasticsearch/lib/\* org.elasticsearch.bootstrap.Elasticsearch -Ebootstrap.memory\_lock=false -Expack.security.http.ssl.enabled=false -Ecluster.routing.allocation.disk.watermark.flood\_stage=1gb -Enode.name=data2 -Escript.max\_compilations\_rate=2048/1m -Expack.security.authc.token.enabled=false -Ecluster.initial\_master\_nodes=master1 -Enode.store.allow\_mmap=false -Epath.repo=/usr/share/elasticsearch/backups -Ecluster.routing.allocation.disk.watermark.high=5gb -Expack.security.transport.ssl.enabled=false -Ediscovery.seed\_hosts=master1:9300 -Ecluster.name=nfvi-elkstack -Enode.master=false -Ecluster.routing.allocation.disk.watermark.low=10gb -Expack.security.enabled=false -Expack.security.audit.enabled=false  
sysadm 14764 13372 0 Apr13 ? 00:00:00 /usr/share/elasticsearch/modules/x-pack-ml/platform/linux-x86\_64/bin/controller

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 1, 2021, 1:53am UTC](https://discuss.elastic.co/t/elasticsearch-heap-memory-warning-in-elk-docker/277419/5 "2021-07-01T01:53:15Z")

</div>

Can you check the hot threads for that node?

Please also format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2021, 1:53am UTC](https://discuss.elastic.co/t/elasticsearch-heap-memory-warning-in-elk-docker/277419/6 "2021-07-29T01:53:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
