# Strange behavior of ElasticSearch

**URL:** <https://discuss.elastic.co/t/strange-behavior-of-elasticsearch/22207>\
**Category:** Elasticsearch\
**Created:** [February 17, 2015, 2:17pm UTC](https://discuss.elastic.co/t/strange-behavior-of-elasticsearch/22207 "2015-02-17T14:17:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![opendoc](https://avatars.discourse-cdn.com/v4/letter/o/f19dbf/32.png) [@opendoc](https://discuss.elastic.co/u/opendoc)\
**Post date:** [February 17, 2015, 2:17pm UTC](https://discuss.elastic.co/t/strange-behavior-of-elasticsearch/22207/1 "2015-02-17T14:17:13Z")

</div>

Hello everyone,

for 2 days, I have a strange behavior with ElasticSearch. This is the  
context:

- 1 clsuter with 3 node
- os : debian
- version 1.4.0 (official package)
- OS mem : 12 Go
- JMX : 8 Go
- CPU : Intel(R) Xeon(R) CPU E5-2650 0 @ 2.00GHz
- Nb CPU : 9

From 7 am Monday, I was an increase in the use of RAM. Recycling the  
JMX is from once per day to once every 2 hours. I have no explanation.  
The CPU is overused. The response time is 10 ms instead of 3,5mns.  
Restarting each node has not changed anything.

Do you have a method or tools to diagnose ElasticSearch behavior ?  
Should I upgrade to version 1.4.3 ?

Thank you.

Alex

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/54E34D69.6070800%40opendoc.net](https://groups.google.com/d/msgid/elasticsearch/54E34D69.6070800%40opendoc.net).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![opendoc](https://avatars.discourse-cdn.com/v4/letter/o/f19dbf/32.png) [@opendoc](https://discuss.elastic.co/u/opendoc)\
**Post date:** [February 17, 2015, 8:18pm UTC](https://discuss.elastic.co/t/strange-behavior-of-elasticsearch/22207/2 "2015-02-17T20:18:44Z")

</div>

Hello everyone,

I activated the index\_search\_slowlog.log. Is it possible to log the IP  
of the machine in the slowlog ?

Thank you.

Alex.

On 17/02/15 15:17, Alexandre wrote:

> Hello everyone,
> 
> for 2 days, I have a strange behavior with Elasticsearch. This is the  
> context:
> 
> - 1 clsuter with 3 node
> - os : debian
> - version 1.4.0 (official package)
> - OS mem : 12 Go
> - JMX : 8 Go
> - CPU : Intel(R) Xeon(R) CPU E5-2650 0 @ 2.00GHz
> - Nb CPU : 9
> 
> From 7 am Monday, I was an increase in the use of RAM. Recycling the  
> JMX is from once per day to once every 2 hours. I have no explanation.  
> The CPU is overused. The response time is 10 ms instead of 3,5mns.  
> Restarting each node has not changed anything.
> 
> Do you have a method or tools to diagnose Elasticsearch behavior ?  
> Should I upgrade to version 1.4.3 ?
> 
> Thank you.
> 
> Alex

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/54E3A224.4020908%40opendoc.net](https://groups.google.com/d/msgid/elasticsearch/54E3A224.4020908%40opendoc.net).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 17, 2015, 10:15pm UTC](https://discuss.elastic.co/t/strange-behavior-of-elasticsearch/22207/3 "2015-02-17T22:15:05Z")

</div>

How many indices in the cluster, how many shards, how much data is that in  
GB?

On 18 February 2015 at 01:17, Alexandre [infos@opendoc.net](mailto:infos@opendoc.net) wrote:

> Hello everyone,
> 
> for 2 days, I have a strange behavior with Elasticsearch. This is the  
> context:
> 
> - 1 clsuter with 3 node
> - os : debian
> - version 1.4.0 (official package)
> - OS mem : 12 Go
> - JMX : 8 Go
> - CPU : Intel(R) Xeon(R) CPU E5-2650 0 @ 2.00GHz
> - Nb CPU : 9
> 
> From 7 am Monday, I was an increase in the use of RAM. Recycling the JMX  
> is from once per day to once every 2 hours. I have no explanation. The CPU  
> is overused. The response time is 10 ms instead of 3,5mns. Restarting each  
> node has not changed anything.
> 
> Do you have a method or tools to diagnose Elasticsearch behavior ? Should  
> I upgrade to version 1.4.3 ?
> 
> Thank you.
> 
> Alex
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> msgid/elasticsearch/54E34D69.6070800%[40opendoc.net](http://40opendoc.net).  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X959\_QgNPKb\_wqG8M7Hbb-N8T%2BYJYfNyTp8ofGAmOhcYA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X959_QgNPKb_wqG8M7Hbb-N8T%2BYJYfNyTp8ofGAmOhcYA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![opendoc](https://avatars.discourse-cdn.com/v4/letter/o/f19dbf/32.png) [@opendoc](https://discuss.elastic.co/u/opendoc)\
**Post date:** [February 18, 2015, 11:17am UTC](https://discuss.elastic.co/t/strange-behavior-of-elasticsearch/22207/4 "2015-02-18T11:17:17Z")

</div>

Hi Mark,

I currently have five indexes with 5 shards by index :

1 : 7.24MB  
2 : 257MB  
3 : 623kB  
4 : 30.2MB  
5 : 629MB

I think it's nothing for Elasticsearch.

I activated the slow log and found that the http bing robots are  
researching for 50 hours !

The problem is fixed now. Stats search is now 3.5ms.

Thank you Mark.

Good day.

Alex.

On 17/02/15 23:15, Mark Walkom wrote:

> How many indices in the cluster, how many shards, how much data is that  
> in GB?
> 
> On 18 February 2015 at 01:17, Alexandre \<[infos@opendoc.net](mailto:infos@opendoc.net)  
> [mailto:infos@opendoc.net](mailto:infos@opendoc.net)\> wrote:
> 
> ```
> Hello everyone,
> 
> for 2 days, I have a strange behavior with ElasticSearch. This is
> the context:
> 
> - 1 clsuter with 3 node
> - os : debian
> - version 1.4.0 (official package)
> - OS mem : 12 Go
> - JMX : 8 Go
> - CPU : Intel(R) Xeon(R) CPU E5-2650 0 @ 2.00GHz
> - Nb CPU : 9
> 
> From 7 am Monday, I was an increase in the use of RAM. Recycling
> the JMX is from once per day to once every 2 hours. I have no
> explanation. The CPU is overused. The response time is 10 ms instead
> of 3,5mns. Restarting each node has not changed anything.
> 
> Do you have a method or tools to diagnose ElasticSearch behavior ?
> Should I upgrade to version 1.4.3 ?
> 
> Thank you.
> 
> Alex
> 
> --
> You received this message because you are subscribed to the Google
> Groups "elasticsearch" group.
> To unsubscribe from this group and stop receiving emails from it,
> send an email to elasticsearch+unsubscribe@__googlegroups.com
> <mailto:elasticsearch%2Bunsubscribe@googlegroups.com>.
> To view this discussion on the web visit
> https://groups.google.com/d/ __msgid/elasticsearch/54E34D69.__ 6070800%40opendoc.net
> <https://groups.google.com/d/msgid/elasticsearch/54E34D69.6070800%40opendoc.net>.
> For more options, visit https://groups.google.com/d/__optout
> <https://groups.google.com/d/optout>.
> 
> ```
> 
> --  
> You received this message because you are subscribed to the Google  
> Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send  
> an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com)  
> [mailto:elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X959\_QgNPKb\_wqG8M7Hbb-N8T%2BYJYfNyTp8ofGAmOhcYA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X959_QgNPKb_wqG8M7Hbb-N8T%2BYJYfNyTp8ofGAmOhcYA%40mail.gmail.com)  
> [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X959\_QgNPKb\_wqG8M7Hbb-N8T%2BYJYfNyTp8ofGAmOhcYA%40mail.gmail.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X959_QgNPKb_wqG8M7Hbb-N8T%2BYJYfNyTp8ofGAmOhcYA%40mail.gmail.com?utm_medium=email&utm_source=footer).  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/54E474BD.7040404%40opendoc.net](https://groups.google.com/d/msgid/elasticsearch/54E474BD.7040404%40opendoc.net).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:31am UTC](https://discuss.elastic.co/t/strange-behavior-of-elasticsearch/22207/5 "2017-07-06T00:31:57Z")

</div>


