# High CPU Usage on Elastic Defend and Kibana Processes

**URL:** <https://discuss.elastic.co/t/high-cpu-usage-on-elastic-defend-and-kibana-processes/386663>\
**Category:** Elastic Security\
**Tags:** docker, elastic-agent, defend-for-containers\
**Created:** [June 2, 2026, 11:35pm UTC](https://discuss.elastic.co/t/high-cpu-usage-on-elastic-defend-and-kibana-processes/386663 "2026-06-02T23:35:40Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![YousefNein](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yousefnein/32/145549_2.png) [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Post date:** [June 2, 2026, 11:35pm UTC](https://discuss.elastic.co/t/high-cpu-usage-on-elastic-defend-and-kibana-processes/386663/1 "2026-06-02T23:35:40Z")

</div>

Hello,

I have two problems related to CPU usage being very high with two ES related processes. I'm currently using 3 ES nodes on the same machine using Docker. 1 Master hot/content, 1 warm, and 1 cold.

The machine has 50 GB of RAM and 14 CPU cores with a 1.4 TB and an S3 for the warm and cold data.

I have used similar setups, but never I have seen the CPU is being used like this, it's usually the RAM. As you can see from my screenshot, the two top processes are elastic-endpoint (Elastic Defend agent) and "MainThread" (It's `/var/lib/docker/rootfs/overlayfs/<container-id>/usr/share/kibana/node/default/bin/node` which is **Kibana** , and Idk why it's called that in the `system.process` event dataset, while being different in something like `endpoint.events*` datasets)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d818fb88b49312566816ca868a78f1900c3de90a.png)
