# Elasticsearch process is killed by OOM killer

**URL:** <https://discuss.elastic.co/t/elasticsearch-process-is-killed-by-oom-killer/217792>\
**Category:** Elasticsearch\
**Created:** [February 4, 2020, 11:40am UTC](https://discuss.elastic.co/t/elasticsearch-process-is-killed-by-oom-killer/217792 "2020-02-04T11:40:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashok6](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@ashok6](https://discuss.elastic.co/u/ashok6)\
**Post date:** [February 4, 2020, 11:40am UTC](https://discuss.elastic.co/t/elasticsearch-process-is-killed-by-oom-killer/217792/1 "2020-02-04T11:40:04Z")

</div>

Hi,

We have a 32GB c5.4xlarge ( 4 nodes cluster ) for the elastic search and the elastic search process is getting killed after a period of 3 weeks and there is no enough memopry left to restart the process. So had to manually clear the cache and reduce the heap memory settings to get the process started.

localhost kernel: [2444278.080081] elasticsearch[1 invoked oom-killer: gfp\_mask=0x201da, order=0, oom\_score\_adj=0

Xmx and Xms is 15G and GC settings as below.

-XX:+UseConcMarkSweepGC  
-XX:CMSInitiatingOccupancyFraction=75  
-XX:+UseCMSInitiatingOccupancyOnly

Other settings:

bootstrap.memory\_lock: true  
MAX\_LOCKED\_MEMORY=unlimited  
MAX\_OPEN\_FILES=65536  
MAX\_MAP\_COUNT=262144  
MAX\_THREADS=8192

Can you advice whether any other settings to be made to avoid the OOM killer to crash the elasticsearch process.

Thanks,  
A

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [February 4, 2020, 12:15pm UTC](https://discuss.elastic.co/t/elasticsearch-process-is-killed-by-oom-killer/217792/2 "2020-02-04T12:15:07Z")

</div>

Which version of Elasticsearch are you using? Older releases in the 7.x series allowed off-heap allocation of up to the heap size; this has been reduced to half the heap size in releases newer than 7.3 IIRC. You may want to reduce the `-Xms` and `-Xmx` values from its current values of `15GB`.

---

<div class="post-metadata">

**Author:** ![ashok6](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@ashok6](https://discuss.elastic.co/u/ashok6)\
**Post date:** [February 4, 2020, 1:10pm UTC](https://discuss.elastic.co/t/elasticsearch-process-is-killed-by-oom-killer/217792/3 "2020-02-04T13:10:15Z")

</div>

Hi Magnus,

Thanks.

Im using Elasticsearch 7.5. is the rule of allocating ~50% of available RAM is not reqd for this version so elastic will have enough for in-memory processing ?

Can i reduce this to 30% of total RAM ?

Thanks,  
A

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [February 4, 2020, 1:17pm UTC](https://discuss.elastic.co/t/elasticsearch-process-is-killed-by-oom-killer/217792/4 "2020-02-04T13:17:57Z")

</div>

Sure. Unless your nodes really need a large amount of heap space (e.g. for large aggregations, or to ingest very big documents) you can reduce the allocated heap space. Make sure you monitor heap space in Kibana's monitoring app to detect when memory gets tight. This typically shows up as the heap size being at or higher than the occupancy fraction for long periods of time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2020, 1:17pm UTC](https://discuss.elastic.co/t/elasticsearch-process-is-killed-by-oom-killer/217792/5 "2020-03-03T13:17:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
