Skip to content

Backend Stopped Processing Data After Memory Increase – High CPU Usage (>500%) on event-processor-manager, event-processor-worker #1856

@karlbrown87

Description

@karlbrown87

Acknowledgements

Describe the bug

After increasing memory limits for the following Docker Swarm services:

  • utmstack_backend
  • utmstack_opensearch
  • utmstack_web-pdf
    the backend stopped processing incoming data.
    No logs or events have been ingested or processed in the last 12 hours.
    During investigation, we observed abnormal CPU utilization on the following services:
  • event-processor-manager
  • event-processor-worker (if applicable, adjust if needed)
    Both services were consistently consuming over 500% CPU

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

  • Backend should continue processing and indexing data after memory reallocation
  • No interruption in log ingestion pipeline

Current Behavior

  • No data ingestion in the last 12 hours
  • No new logs indexed in OpenSearch
  • Backend API responsive but not processing events
  • event-processor-manager/worker CPU usage > 500%
  • System load significantly elevated
  • No automatic recovery observed

Reproduction Steps

docker service update utmstack_backend --limit-memory 4096M --reserve-memory 4096M
docker service update utmstack_node1 --limit-memory 10240M --reserve-memory 10240M
docker service update utmstack_web-pdf --limit-memory 4096M --reserve-memory 4096M

Possible Solution

No response

Additional Information/Context

No response

UTMStack Version

11.2.3

Operating System and version

Ubuntu 24.04

Hypervisor and Version | Server Vendor and Model

AWS

Browser and version

Chrome

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions