Running out of fielddata without enabling it

Apologize, I didn't see your first question about how we knew it, the cluster didnt actually crash, we started seeing queries fail because we were out of fielddata, and we knew because our application was throwing the error Error: fielddata too large. We cleared the fielddata cache and everything returned to normal. We are already looking at setting smarter values for our field data cache size and breaker values.

I didn't realize that the fielddata gave a breakdown by actual field, however all of these usages point to the "_uid" field, which is not even a field that exists in our mapping.

It is metadata, things like file names and permissions.

this is the mapping: