# Query for top xx usage elasticsearch nodes

**URL:** <https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [March 23, 2026, 9:14am UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581 "2026-03-23T09:14:56Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [March 23, 2026, 9:14am UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581/1 "2026-03-23T09:14:56Z")

</div>

Trying to create a query for my cluster elasticsearch nodes.  
I want it to show nodes that is more than xx% of cpu or memory or JVM heap or free space left in %

1. Not sure if I have selected the correct field for CPU , jvm and fs.
2. Unsure which memory field to select.
3. Also having issue wit the EVAL. PLEASE help!!!

```auto
POST /_query?format=txt
{
  "query": """
  FROM ABCD:.monitoring-*
| WHERE @timestamp > NOW() - 8 hours
    AND (node_stats.process.cpu.percent) > 50
    OR (node_stats.jvm.mem.heap_used_percent) > 50
| STATS 
      process_cpu = AVG(node_stats.process.cpu.percent),
      jvm_mem = AVG(node_stats.jvm.mem.heap_used_percent),
      fs_avail = AVG(elasticsearch.node.stats.fs.total.available_in_bytes)
    BY elasticsearch.node.name
    EVAL fs_avail_gb = ROUND((TO_DOUBLE(fs_avail) / 1,073,741,824) * 100, 2)
| WHERE process_cpu > 50
| SORT process_cpu DESC
| LIMIT 100
    """
}

```

---

<div class="post-metadata">

**Author:** ![Rafa\_Silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafa_silva/32/147814_2.png) [@Rafa\_Silva](https://discuss.elastic.co/u/Rafa_Silva)\
**Post date:** [March 23, 2026, 4:42pm UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581/2 "2026-03-23T16:42:54Z")

</div>

Hi

You’re close the main issue is mixing raw fields and aggregated values.

A few key points:  
CPU → node\_stats.process.cpu.percent (correct)  
JVM → node\_stats.jvm.mem.heap.used\_percent  
Memory (OS) → node\_stats.os.mem.used\_percent  
FS → don’t use only available space, calculate percentage used:

```auto
(available_in_bytes / total_in_bytes)

```

The issue with EVAL happens because you’re trying to calculate after aggregation.

Key insight: do all calculations inside STATS, not after.

---

<div class="post-metadata">

**Author:** ![dot-mike](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dot-mike/32/143339_2.png) [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Post date:** [March 23, 2026, 6:44pm UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581/3 "2026-03-23T18:44:04Z")

</div>

I can't believe @Rafa_Silva you are still using AI generate your answers, instead actually writing a proper human answer. Disgusting.

The information you provided is wrong!

* * *

Anyway, @Whoami1980  
from the [official Elasticsearch documentation for Elastic Stack Monitoring Integration](https://www.elastic.co/docs/reference/integrations/elasticsearch) you can see these are the fields we need:

- `node_stats.process.cpu.percent`
- `node_stats.jvm.mem.heap_used_percent`
- `elasticsearch.node.stats.fs.total.available_in_bytes`

This means your fields are correct.

I can see that "8 hours" is not valid temporal unit, you can see this from here: [ES|QL time spans | Elasticsearch Reference](https://www.elastic.co/docs/reference/query-languages/esql/esql-time-spans#esql-time-spans-table)

And you also trying to use `EVAL` function within `STATS` function. That is not allowed.. You can read about [Basic ES|QL syntax | Elasticsearch Reference](https://www.elastic.co/docs/reference/query-languages/esql/esql-syntax)

Also numbers with comma are not allowed.

Below is the fixed ES|QL query. Note that this with the official ES Monitoring stack and not the built-in one (legacy and depricated), so the dataset is in `metrics-elasticsearch.stack_monitoring.node_stats-default`. replace as needed.

```auto
FROM metrics-elasticsearch.stack_monitoring.node_stats-default
| WHERE @timestamp >= NOW()-8h
| STATS 
      process_cpu = AVG(node_stats.process.cpu.percent),
      jvm_mem = AVG(node_stats.jvm.mem.heap_used_percent),
      fs_avail = AVG(elasticsearch.node.stats.fs.total.available_in_bytes)
    BY elasticsearch.node.name
| EVAL fs_avail = ROUND((TO_DOUBLE(fs_avail) / 1073741824) * 100, 2)
| WHERE (process_cpu > 50 OR jvm_mem > 50)
| SORT process_cpu DESC
| LIMIT 100

```

---

<div class="post-metadata">

**Author:** ![Rafa\_Silva](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rafa_silva/32/147814_2.png) [@Rafa\_Silva](https://discuss.elastic.co/u/Rafa_Silva)\
**Post date:** [March 23, 2026, 7:08pm UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581/4 "2026-03-23T19:08:29Z")

</div>

Hi!

Thank you for correcting some incorrect information I posted.

But my answers are not generated by AI.

I've even commented here at some point about the use of these mechanisms.

Thank you again for the correction.

---

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [March 25, 2026, 3:31am UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581/5 "2026-03-25T03:31:53Z")

</div>

@dot-mike  
Thanks!!! The query did work.

However was trying to find @Rafa_Silva suggestion to use memory below but to no avail.  
Memory (OS) → node\_stats.os.mem.used\_percent

whats the correct field for the free memory in percentage?  
thanks!

---

<div class="post-metadata">

**Author:** ![dot-mike](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dot-mike/32/143339_2.png) [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Post date:** [March 25, 2026, 10:01am UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581/6 "2026-03-25T10:01:34Z")

</div>

> [@Whoami1980](#):
>
> However was trying to find @Rafa_Silva suggestion to use memory below but to no avail.  
> Memory (OS) → node\_stats.os.mem.used\_percent

It's not availabel because this person was using AI to answer and he was dreaming this was reality.

> [@Whoami1980](#):
>
> whats the correct field for the free memory in percentage?

Take a look at [Elasticsearch | Elastic integrations](https://www.elastic.co/docs/reference/integrations/elasticsearch#node-stats)

here you can see 3 available paramaters:  
elasticsearch.node.stats.os.cgroup.memory.control\_group  
elasticsearch.node.stats.os.cgroup.memory.limit.bytes  
elasticsearch.node.stats.os.cgroup.memory.usage.bytes \<--- probably what you want.

---

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [March 27, 2026, 6:43am UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581/7 "2026-03-27T06:43:54Z")

</div>

@dot-mike

Thanks. understood. now i will have to try to do get the %

Btw. i was looking at the integration link but i didnt find anything on alerts or snapshot. or i should be looking at another page. i tried but to no avail. ☹

[official Elasticsearch documentation for Elastic Stack Monitoring Integration](https://www.elastic.co/docs/reference/integrations/elasticsearch)

---

<div class="post-metadata">

**Author:** ![dot-mike](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dot-mike/32/143339_2.png) [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Post date:** [March 29, 2026, 2:14pm UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581/8 "2026-03-29T14:14:30Z")

</div>

> [@Whoami1980](#):
>
> Thanks. understood. now i will have to try to do get the %

You should be able to caluclate it with the fields I've provided in my answer 😉 I will not do the homework for you.

> [@dot-mike](#):
>
> here you can see 3 available paramaters:  
> elasticsearch.node.stats.os.cgroup.memory.control\_group  
> elasticsearch.node.stats.os.cgroup.memory.limit.bytes  
> elasticsearch.node.stats.os.cgroup.memory.usage.bytes \<--- probably what you want.
