# Elasticsearch Master Node JVM reaching 99%

**URL:** <https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907>\
**Category:** Elasticsearch\
**Created:** [July 20, 2020, 2:41pm UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907 "2020-07-20T14:41:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![rsmith013](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rsmith013](https://discuss.elastic.co/u/rsmith013)\
**Post date:** [July 20, 2020, 2:41pm UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/1 "2020-07-20T14:41:29Z")

</div>

I am running a 3 Master 8 Data node cluster.  
Elasticsearch Version 7.8.0

The cluster bumps along happily for several days with the regular sawtooth JVM pattern then suddenly ramps up and then hits 99%.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/6/3662ccec60d3582929098e8fade789858568be7e.png)

This leads to issues performing normal operations. A restart puts the memory back to normal levels but I can't figure out what causes it. I have seen before that a memory leak in a previous version caused similar issues but I would have thought that the GC would keep the JVM usage within comfortable limits.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 20, 2020, 3:50pm UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/2 "2020-07-20T15:50:54Z")

</div>

Would you capture a heap dump the next time the heap maxes out like that? Let us know when you've got it and we'll arrange a way to send it in.

---

<div class="post-metadata">

**Author:** ![rsmith013](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rsmith013](https://discuss.elastic.co/u/rsmith013)\
**Post date:** [July 30, 2020, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/3 "2020-07-30T09:28:22Z")

</div>

@DavidTurner It has happened again on all 3 of my master nodes. I see there is now a 7.8.1, might that fix it?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 30, 2020, 9:46am UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/4 "2020-07-30T09:46:59Z")

</div>

I doubt it since I don't think anything has changed recently in this area. I asked for heap dumps above -- without them, we can't really say what the problem is, and without knowing that we can't really say anything about a fix.

---

<div class="post-metadata">

**Author:** ![rsmith013](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rsmith013](https://discuss.elastic.co/u/rsmith013)\
**Post date:** [July 30, 2020, 9:48am UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/5 "2020-07-30T09:48:10Z")

</div>

I have captured one. What is the best way to send it to you.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 30, 2020, 10:08am UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/6 "2020-07-30T10:08:14Z")

</div>

Great, thanks. I've sent you a direct message with an upload link.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 30, 2020, 6:15pm UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/7 "2020-07-30T18:15:44Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f0f2c5c97ecd01728bd46457120cf7e247880364.png)

Looks to me like you're using the third-party ReadonlyREST plugin and it's gone haywire, but I can't say much more than that as it's not something we support. I recommend using the official security features instead, they're included by default, they don't cost anything and AFAIK don't suffer from this kind of problem.

---

<div class="post-metadata">

**Author:** ![rsmith013](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rsmith013](https://discuss.elastic.co/u/rsmith013)\
**Post date:** [July 30, 2020, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/8 "2020-07-30T18:48:28Z")

</div>

Thanks for looking into it. I am keeping an eye on the native security. At the moment, we are making use of IP filtering and LDAP integration, which we would lose if we went to stack native security. Although, if this lasts too long, a loss of convenience outweighs a stable cluster.

Thanks,

Richard

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2020, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-master-node-jvm-reaching-99/241907/9 "2020-08-27T18:48:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
