# ES High cpu issues

**URL:** <https://discuss.elastic.co/t/es-high-cpu-issues/143563>\
**Category:** Elasticsearch\
**Created:** [August 8, 2018, 4:31pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563 "2018-08-08T16:31:12Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![naresh\_career399](https://avatars.discourse-cdn.com/v4/letter/n/dec6dc/32.png) [@naresh\_career399](https://discuss.elastic.co/u/naresh_career399)\
**Post date:** [August 8, 2018, 4:31pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/1 "2018-08-08T16:31:12Z")

</div>

We are getting high cpu alerts on ES nodes every day first I though like beacause of heap size, I changed it to 31g coz my machines are 64g but it does not resolved the cpu issues.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 8, 2018, 4:47pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/2 "2018-08-08T16:47:25Z")

</div>

What load is the cluster under? How much data do you have in the cluster? What appears to be causing the high CPU usage if you call the [node hot threads API](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/cluster-nodes-hot-threads.html)?

---

<div class="post-metadata">

**Author:** ![naresh\_career399](https://avatars.discourse-cdn.com/v4/letter/n/dec6dc/32.png) [@naresh\_career399](https://discuss.elastic.co/u/naresh_career399)\
**Post date:** [August 8, 2018, 6:02pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/3 "2018-08-08T18:02:47Z")

</div>

This is 17 node cluster and we have 4852 indices and 18330 shards.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 8, 2018, 6:30pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/4 "2018-08-08T18:30:46Z")

</div>

Which version of Elasticsearch are you using? What does the hot threads show when a node is busy?

---

<div class="post-metadata">

**Author:** ![nareshm\_399](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nareshm_399/32/55066_2.png) [@nareshm\_399](https://discuss.elastic.co/u/nareshm_399)\
**Post date:** [August 8, 2018, 6:35pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/5 "2018-08-08T18:35:19Z")

</div>

54.4% (271.9ms out of 500ms) cpu usage by thread 'elasticsearch[search][T#17]'  
10/10 snapshots sharing following 2 elements  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)  
java.lang.Thread.run(Thread.java:745)

52.4% (262ms out of 500ms) cpu usage by thread 'elasticsearch[][search][T#14]'  
10/10 snapshots sharing following 2 elements  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)  
java.lang.Thread.run(Thread.java:745)

51.3% (256.3ms out of 500ms) cpu usage by thread 'elasticsearch[][search][T#29]'  
3/10 snapshots sharing following 17 elements  
org.apache.lucene.search.Weight$DefaultBulkScorer.scoreAll(Weight.java:221)  
org.apache.lucene.search.Weight$DefaultBulkScorer.score(Weight.java:172)  
org.apache.lucene.search.BulkScorer.score(BulkScorer.java:39)  
org.apache.lucene.search.IndexSearcher.search(IndexSearcher.java:821)  
org.apache.lucene.search.IndexSearcher.search(IndexSearcher.java:535)  
org.elasticsearch.search.query.QueryPhase.execute(QueryPhase.java:384)  
org.elasticsearch.search.query.QueryPhase.execute(QueryPhase.java:113)  
org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:410)  
org.elasticsearch.search.action.SearchServiceTransportAction$SearchQueryScrollTransportHandler.messageReceived(SearchServiceTransportAction.java:384)  
org.elasticsearch.search.action.SearchServiceTransportAction$SearchQueryScrollTransportHandler.messageReceived(SearchServiceTransportAction.java:381)  
org.elasticsearch.transport.TransportRequestHandler.messageReceived(TransportRequestHandler.java:33)  
org.elasticsearch.transport.RequestHandlerRegistry.processMessageReceived(RequestHandlerRegistry.java:75)  
org.elasticsearch.transport.netty.MessageChannelHandler$RequestHandler.doRun(MessageChannelHandler.java:300)  
org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37)  
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)  
java.lang.Thread.run(Thread.java:745)

---

<div class="post-metadata">

**Author:** ![nareshm\_399](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nareshm_399/32/55066_2.png) [@nareshm\_399](https://discuss.elastic.co/u/nareshm_399)\
**Post date:** [August 8, 2018, 6:36pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/6 "2018-08-08T18:36:19Z")

</div>

We are using ES 2.3 version.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 8, 2018, 6:37pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/7 "2018-08-08T18:37:12Z")

</div>

It seems to be busy with search. What type of queries are you running? What is the use case?

---

<div class="post-metadata">

**Author:** ![nareshm\_399](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nareshm_399/32/55066_2.png) [@nareshm\_399](https://discuss.elastic.co/u/nareshm_399)\
**Post date:** [August 8, 2018, 6:52pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/8 "2018-08-08T18:52:05Z")

</div>

If i use coordinating node on my cluster, Is that useful for this problem?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 8, 2018, 7:44pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/9 "2018-08-08T19:44:20Z")

</div>

I can not tell because I do not know what the problem is.

---

<div class="post-metadata">

**Author:** ![naresh\_career399](https://avatars.discourse-cdn.com/v4/letter/n/dec6dc/32.png) [@naresh\_career399](https://discuss.elastic.co/u/naresh_career399)\
**Post date:** [August 9, 2018, 3:14pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/10 "2018-08-09T15:14:46Z")

</div>

Queries are related to , we are running anti-virus app so we ll collect the samples like urls, hos,domain, ips.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 9, 2018, 3:28pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/11 "2018-08-09T15:28:40Z")

</div>

What type of queries are you running? Can you provide some samples? Are you using wildcard queries, scripted fields or complex scoring?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2018, 3:28pm UTC](https://discuss.elastic.co/t/es-high-cpu-issues/143563/12 "2018-09-06T15:28:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
