# Elasticsearch high CPU Utilization

**URL:** <https://discuss.elastic.co/t/elasticsearch-high-cpu-utilization/203881>\
**Category:** Elasticsearch\
**Created:** [October 16, 2019, 4:00pm UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-utilization/203881 "2019-10-16T16:00:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jayabal\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jayabal_k/32/41905_2.png) [@Jayabal\_K](https://discuss.elastic.co/u/Jayabal_K)\
**Post date:** [October 16, 2019, 4:00pm UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-utilization/203881/1 "2019-10-16T16:00:14Z")

</div>

Hi,  
I have a elastic setup which consists of 5 datanode, 1 master and 1 client node.  
Each datanode consists of 1.5 vCPU, and 4GB Memory. My indexing rate is 10K logs per second.  
During the indexing time the CPU usage of the datanode are high (90%).

When I try to query the document parallelly during the indexing time. I getting client request error for my queries.

> {  
> "statusCode": 504,  
> "error": "Gateway Time-out",  
> "message": "Client request timeout"  
> }

And also the datanodes are getting strucked.  
Below is the output of the _GET /\_nodes/hot\_threads_  
Please help me solve the CPU usage issue.

```
::: {elasticsearch-data-2}{rqtu_kkYTsODGIRnls535w}{NIJMJ2CiQ3K8sKar9-GW_g}{10.24.2.5}{10.24.2.5:9300}{xpack.installed=true}
   Hot threads at 2019-10-16T14:49:19.663, interval=500ms, busiestThreads=3, ignoreIdleThreads=true:
   
   32.2% (161ms out of 500ms) cpu usage by thread 'elasticsearch[elasticsearch-data-2][search][T#1]'
     5/10 snapshots sharing following 28 elements
       app//org.elasticsearch.search.aggregations.AggregatorFactory$MultiBucketAggregatorWrapper$1.collect(AggregatorFactory.java:140)
       app//org.elasticsearch.search.aggregations.bucket.BucketsAggregator.collectExistingBucket(BucketsAggregator.java:84)

   
   30.2% (150.9ms out of 500ms) cpu usage by thread 'elasticsearch[elasticsearch-data-2][write][T#2]'
     2/10 snapshots sharing following 36 elements     
                                   
   
   25.7% (128.5ms out of 500ms) cpu usage by thread 'elasticsearch[elasticsearch-data-2][[latest-map][4]: Lucene Merge Thread #2106]'
     5/10 snapshots sharing following 5 elements
       app//org.apache.lucene.index.IndexWriter.mergeMiddle(IndexWriter.java:4412)
       app//org.apache.lucene.index.IndexWriter.merge(IndexWriter.java:4061)

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 16, 2019, 4:58pm UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-utilization/203881/2 "2019-10-16T16:58:45Z")

</div>

That sounds like a very low amount of resources for that kind of indexing rate so I am not surprised you are having issues. You should also make sure you have 3 master eligible nodes in the cluster as having only one is very bad and can lead to data loss.

---

<div class="post-metadata">

**Author:** ![Jayabal\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jayabal_k/32/41905_2.png) [@Jayabal\_K](https://discuss.elastic.co/u/Jayabal_K)\
**Post date:** [October 17, 2019, 5:27am UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-utilization/203881/3 "2019-10-17T05:27:41Z")

</div>

Could you please share me resource allocation recommendation for this kind use-case.  
FYI, we are running the cluster in kubernetes environment as statefulset.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 17, 2019, 5:31am UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-utilization/203881/4 "2019-10-17T05:31:50Z")

</div>

Have a look at the following:

> **[Quantitative Cluster Sizing](https://www.elastic.co/webinars/elasticsearch-sizing-and-capacity-planning#)**
>
> This webinar covers the capacity planning frameworks, methodologies, and best practices used by the solutions architects at Elastic. You will learn how to estimate the architecture requirements for typical Elasticsearch use cases.

> **[Optimizing Storage Efficiency in Elasticsearch](https://www.elastic.co/webinars/optimizing-storage-efficiency-in-elasticsearch)**
>
> This video covers the different types of nodes we use in Hot/Warm/Cold architectures and discuss their characteristics and the factors that determine how much data each node type can hold and how you go about optimizing for this.

> **[How many shards should I have in my Elasticsearch cluster?](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster)**
>
> If you are looking for practical guidelines around how many indices and shards to have in your cluster, this blog post will help you avoid common pitfalls.

[https://www.elastic.co/blog/sizing-hot-warm-architectures-for-logging-and-metrics-in-the-elasticsearch-service-on-elastic-cloud](https://www.elastic.co/blog/sizing-hot-warm-architectures-for-logging-and-metrics-in-the-elasticsearch-service-on-elastic-cloud)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2019, 5:31am UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-utilization/203881/5 "2019-11-14T05:31:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
