Enabling the 'Treat match as intrusion' or 'Log matching traffic' logging options might cause high CPU usage
Last Modified: 2023-08-31 08:35:41 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Enabling the 'Treat match as intrusion' or 'Log matching traffic' logging options might cause high CPU usage
Technical Articles ID:
KB90177
Last Modified: 2023-08-31 08:35:41 Etc/GMT Environment
Endpoint Security (ENS) Firewall 10.x
Problem
High CPU use might occur with our processes on systems where either of the following options is enabled on Firewall rules that generate many events:
The Event Viewer for the Windows Application Event Log might show a high number of
Solution
If you enable these logging options in Firewall rules that trigger much event activity, it might cause performance issues. So, enable the logging options only on Firewall rules that don't generate a high number of events. If you encounter this scenario and disable the logging options on a Firewall rule that triggers many events, it might take time to flush the backlog of events before you see the CPU usage decrease.
Related Information
Relevant excerpt from the "Add Rule or Edit Rule, Add Group or Edit Group" section of the Endpoint Security 10.7 Interface Reference Guide: Treat match as intrusion: Treats traffic that matches the rule as an intrusion and displays an alert.
Best practice: Don't enable this option for an Allow rule, because it generates many alerts. Affected ProductsLanguages:This article is available in the following languages: |
|