# Exaggerated consumption of ES instance

**URL:** <https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616>\
**Category:** Elasticsearch\
**Created:** [March 27, 2023, 1:08pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616 "2023-03-27T13:08:07Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![OscarFilho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oscarfilho/32/109740_2.png) [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Post date:** [March 27, 2023, 1:08pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/1 "2023-03-27T13:08:07Z")

</div>

Hello!  
I have an Elastic cloud cluster where I have 2 instances. Each instance is 120GB in size and works as replicas in different Availability Zones for redundancy.

Something strange happened that I can't understand what it could be:  
Instance 4 started consuming twice the size of instance 3 and I didn't change any cluster properties.  
With this exaggerated consumption (doubled) I had an unavailability of access to my cluster because the instance that was twice in size practically reached the space limit and it had the indexes that control authentication in my cluster.

 ![elk-instance4-double-instance3](https://us1.discourse-cdn.com/elastic/original/3X/0/4/04e7b425652114d17976a4d794c49b275cb20b37.png)

The only thing I did was hire Data Tier Warm with 760GB in size in a single Availability Zone. After that I just configured the index rotation policy to use this new layer.

Could anyone help me understand what might be going on and how to resolve it?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 27, 2023, 3:11pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/2 "2023-03-27T15:11:49Z")

</div>

Hi @OscarFilho

Intereting a 4GB i3 Can only have 120GB Disk ... could be a bug in the UI

Go into Kibana - Dev Tools and Run these commands and report back

`GET /_cat/nodes/?v&h=name,du,dt,dup,hp,hc,rm,rp,r`

`GET _cat/allocation/?v`

`GET /_cat/indices/?v&s=pri.store.size:desc`

---

<div class="post-metadata">

**Author:** ![OscarFilho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oscarfilho/32/109740_2.png) [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Post date:** [March 27, 2023, 6:06pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/3 "2023-03-27T18:06:25Z")

</div>

Tks for your reply.

Bellow i put the output of each command:

**GET /\_cat/nodes/?v&h=name,du,dt,dup,hp,hc,rm,rp,r**

```auto
name du dt dup hp hc rm rp r
instance-0000000006 63gb 760gb 8.29 66 1.2gb 4gb 77 rw
instance-0000000004 132.2gb 204gb 64.82 47 930.6mb 4gb 93 himrst
instance-0000000001 42.5mb 10gb 0.42 76 255.4mb 1gb 96 lr
instance-0000000003 71.3gb 120gb 59.46 72 1.3gb 4gb 99 himrst
tiebreaker-0000000005 45.7mb 12gb 0.37 73 250.3mb 1gb 82 mv

```

**GET \_cat/allocation/?v**

```auto
shards disk.indices disk.used disk.avail disk.total disk.percent host ip node
   169 62.9gb 63gb 696.9gb 760gb 8 172.22.143.205 172.22.143.205 instance-0000000006
   447 68.3gb 132.3gb 71.6gb 204gb 64 172.25.247.199 172.25.247.199 instance-0000000004
   447 68.1gb 71.4gb 48.5gb 120gb 59 172.22.140.23 172.22.140.23 instance-0000000003
   169 UNASSIGNED

```

**GET /\_cat/indices/?v&s=pri.store.size:desc** : [https://file.io/48YhDhkiXFRV](https://file.io/48YhDhkiXFRV)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 27, 2023, 6:13pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/4 "2023-03-27T18:13:03Z")

</div>

> [@OscarFilho](#):
>
> GET /\_cat/indices/?v&s=pri.store.size:desc

Can you share this on a _gist_ on github or on pastebin? The site you shared will delete the file once someone download, so other people that may help will not be able to see and provide some insight.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 27, 2023, 6:33pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/5 "2023-03-27T18:33:30Z")

</div>

@OscarFilho

I did take a look at the \_cat/indices it looks pretty normal EXCEPT

You have a lot of unassigned shards because you have a Warm tier with just 1 node and your indices have a replica so there is no node to put the replicas on. 1st I would add another warm node and let it balance / assigned the missing shards and take a look. Or if you truly only want 1 primary ... i.e. not resilience in the warm you need to set the Replicas to 0 and also do that in the ILM, I would not recommend this... best to just add another small warm node.

Then I would suggest Opening a Support Ticket... something is not right ☹

What concerns me is that a 4GB i3 should not have 204 GB of Disk it should just have 120.

I would put all this information in the support ticket.

---

<div class="post-metadata">

**Author:** ![OscarFilho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oscarfilho/32/109740_2.png) [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Post date:** [March 27, 2023, 6:39pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/6 "2023-03-27T18:39:13Z")

</div>

> [@leandrojmp](#):
>
> pastebin

Here is: [https://pastebin.com/FVMVi04K](https://pastebin.com/FVMVi04K)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 27, 2023, 6:44pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/7 "2023-03-27T18:44:01Z")

</div>

@OscarFilho

Put that 2nd Warm Node in ... I think it will balance and go down.

I think somehow that one hot is "holding" on to those unassigned replicas waiting to go to warm. because the math adds up... the extra space is equal to the unassigned shards...

---

<div class="post-metadata">

**Author:** ![OscarFilho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oscarfilho/32/109740_2.png) [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Post date:** [March 27, 2023, 6:50pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/8 "2023-03-27T18:50:56Z")

</div>

> [@stephenb](#):
>
> I would put all this information in the support ticket.

Thanks for the answer!

You are right to be weird about the storage size.  
Elastic support increased the size of instance 4 yesterday, because it reached the maximum configuration of this instance, which was 120GB of space.

Now, the point that I find super strange is that on node 3 it allocates only 60GB and on node 4 (hot replica) it allocates twice as much.  
How does this relate to the warm layer I left without redundancy (only 1 node)?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 27, 2023, 7:20pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/9 "2023-03-27T19:20:54Z")

</div>

Thanks, makes sense from support... not sure if they told you or not but you should have added 2 warm nodes... not 1.

> [@OscarFilho](#):
>
> How does this relate to the warm layer I left without redundancy (only 1 node)?

Believe The hot is holding the Replicas waiting to move to warm they can not be `ASSIGNED` to warm

Its these..

` 169 UNASSIGNED`

Warm should have 2 nodes... try it, I think you will see it all fix.

Basically, you said more ~169 Indices to warm... which is actually about 338 Shards or so, Primary + Replica... the replicas can't move they are taking space but are stuck waiting to be assigned.

Put the additional Warm in and 95% sure it will fix itself.

---

<div class="post-metadata">

**Author:** ![OscarFilho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oscarfilho/32/109740_2.png) [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Post date:** [March 28, 2023, 5:09pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/10 "2023-03-28T17:09:54Z")

</div>

Tks so much for your answer!  
I'll try this later!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2023, 5:10pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616/11 "2023-04-25T17:10:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
