This will not really help you, but I just saw a similar thing.
The CPU usage of one (out of 6) witness appliances increased from a steady 40%, suddenly to over 80% (for no apparent reason, nobody made changes on Saturday...)
It kept that 80% usage level until Tuesday, then there was the only suspicous event (/bin/hostd crashed). Only some time later the vSAN cluster complained about the connection to the appliance.
Appliance was rebooted, running at 20% usage steadily since Tuesday.