Around 16:00 UTC saturday, and again around 5:00 UTC sunday multiple nodes in the eqiad search cluster were pegging cpu at 100%. elastic1027 was involved both times, but not certain yet if the node itself was the problem.
First time around restarting elasticsearch on elastic1027 resolved the issue, although it took around 20 minutes after the restart for things to clear up.
Second time around I shifted all more_like and regex traffic to codfw. That didn't seem to be enough to lighten the load, so I also shifted all enwiki traffic except comp_suggest and prefix to codfw. Things look to be under control now.
Related incident report: https://wikitech.wikimedia.org/wiki/Incident_documentation/20190413-elasticsearch