# Elasticsearch high cpu usage every hourly

**URL:** <https://discuss.elastic.co/t/elasticsearch-high-cpu-usage-every-hourly/22970>\
**Category:** Elasticsearch\
**Created:** [March 29, 2015, 11:57am UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage-every-hourly/22970 "2015-03-29T11:57:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vincent\_park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincent_park/32/800_2.png) [@vincent\_park](https://discuss.elastic.co/u/vincent_park)\
**Post date:** [March 29, 2015, 11:57am UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage-every-hourly/22970/1 "2015-03-29T11:57:29Z")

</div>

we have 8 clustered nodes and each nodes have 1 replica.  
total document size is about 4GB and 1,984,173 docs.

I was suffering from very high CPU usage 80%~90% every hourly.  
It is held for 5 min.

there is no other process except es on each server.  
there is no other cron job even at that time.

I thought there are something wrong with es process.  
maybe external attacks or gc problem.. I don't know.

It happened every hourly.  
I don't know what's going on elasticsearch at this time!!  
somebody help me, tell me what happened in there. please..

```
$ ./elasticsearch -v 
Version: 1.4.2, Build: 927caff/2014-12-16T14:11:12Z, JVM: 1.7.0_75 

$ java -version 
java version "1.7.0_75" 
Java(TM) SE Runtime Environment (build 1.7.0_75-b13) 
Java HotSpot(TM) 64-Bit Server VM (build 24.75-b04, mixed mode) 

```

and I installed plugins - HQ, bigdesk, head, kopf, sense

heres bigdesk graphs at cpu peak time:  
\<nabble\_img src="es\_cpu\_high.png" border="0"/\>

---

<div class="post-metadata">

**Author:** ![aaronmefford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaronmefford/32/460_2.png) [@aaronmefford](https://discuss.elastic.co/u/aaronmefford)\
**Post date:** [March 31, 2015, 4:43pm UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage-every-hourly/22970/2 "2015-03-31T16:43:39Z")

</div>

From what I can see in your graphs I noticed two things. You seem to have  
a spike in search requests at that time, a spike in http traffic, and a  
cache eviction right at the beginning of it.

Are you certain you don't have an external user with a cron job that runs  
at the top of the hour? Perhaps a large scan and scroll query that dumps  
alot of data?

Take a look at your network graphs to see if you have a correlated spike in  
traffic to your Elasticsearch cluster. I wouldn't expect with a cluster  
that size that you don't have any users, probably quite a few users. It  
would not be unreasonable to expect that one such user is doing something  
beyond what you had intended and causing stress on your system.

On Monday, March 30, 2015 at 8:37:54 PM UTC-6, vincent Park wrote:

> we have 8 clustered nodes and each nodes have 1 replica.  
> total document size is about 4GB and 1,984,173 docs.
> 
> I was suffering from very high CPU usage 80%~90% every hourly.  
> It is held for 5 min.
> 
> there is no other process except es on each server.  
> there is no other cron job even at that time.
> 
> I thought there are something wrong with es process.  
> maybe external attacks or gc problem.. I don't know.
> 
> It happened every hourly.  
> I don't know what's going on elasticsearch at this time!!  
> somebody help me, tell me what happened in there. please..
> 
> ```
> $ ./elasticsearch -v 
> Version: 1.4.2, Build: 927caff/2014-12-16T14:11:12Z, JVM: 1.7.0_75 
> 
> $ java -version 
> java version "1.7.0_75" 
> Java(TM) SE Runtime Environment (build 1.7.0_75-b13) 
> Java HotSpot(TM) 64-Bit Server VM (build 24.75-b04, mixed mode) 
> 
> ```
> 
> and I installed plugins - HQ, bigdesk, head, kopf, sense
> 
> heres bigdesk graphs at cpu peak time:  
> \<  
> [http://elasticsearch-users.115913.n3.nabble.com/file/n4072788/es\_cpu\_high.png](http://elasticsearch-users.115913.n3.nabble.com/file/n4072788/es_cpu_high.png)\>
> 
> --  
> View this message in context:  
> [http://elasticsearch-users.115913.n3.nabble.com/elasticsearch-high-cpu-usage-every-hourly-tp4072788.html](http://elasticsearch-users.115913.n3.nabble.com/elasticsearch-high-cpu-usage-every-hourly-tp4072788.html)  
> Sent from the Elasticsearch Users mailing list archive at [Nabble.com](http://Nabble.com).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/aca13c50-3c3a-4630-a941-4116dc31e55e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/aca13c50-3c3a-4630-a941-4116dc31e55e%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:22am UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage-every-hourly/22970/3 "2017-07-06T00:22:42Z")

</div>


