<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4732635#M7193</link>
    <description>&lt;P&gt;Thanks for the advice! I'll have to get the client back on my devices and wait some number of days, and get others to try this out as we get new reports.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2022 15:21:29 GMT</pubDate>
    <dc:creator>ac513</dc:creator>
    <dc:date>2022-12-05T15:21:29Z</dc:date>
    <item>
      <title>CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days uptime</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4731584#M7190</link>
      <description>&lt;P&gt;A few months back, we deployed Cisco Secure Endpoint 8.0.1 to our pilot Windows group and then our production Windows group. In testing there were seemingly no issues; However, eventually we began to notice that after these upgrades, Windows 10 (mostly 21H2) and Windows 11 devices (mostly 21H2, some 22H2) would begin to show significant symptoms of slowness including (but not limited to):&lt;/P&gt;&lt;P&gt;* Window dragging/resizing becomes slow. As in, if all other system animations and video playback are displaying at 60fps as per usual, then window dragging/resizing looks like it's going at about 10-20fps. Just choppy and super unresponsive.&lt;/P&gt;&lt;P&gt;* Print jobs could sometimes take several minutes to process, sometimes fail due to vague memory problems in error messages.&lt;/P&gt;&lt;P&gt;* Opening emails in Outlook could take an entire second or two, rather than instant or mere milliseconds.&lt;/P&gt;&lt;P&gt;* Other LoB software at random taking a very long time to respond/work.&lt;/P&gt;&lt;P&gt;When these slowdowns are happening, there are no obvious resource constraints. For example on my own machine -- 20-30% of my i7-9700k CPU in use (not abnormal because I run tons of programs and VMs), 50% of 32GB RAM free, and marginal disk activity on a Samsung EVO 970 SSD. This is normal for my system, and I never see CPU/RAM/disk anywhere close to being maxed out when these slowdowns occur.&lt;/P&gt;&lt;P&gt;A simple reboot will eliminate the issues for some time, but once the machine has 4-5 or more days of uptime again, all slowdowns return.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;All of these symptoms immediately cease and stay resolved if I uninstall Cisco Secure Endpoint.&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;As a test, I got a version 8.1.3 connector installer. I removed Secure Endpoint on an affected machine (mine, Win11 22H2), and then installed 8.1.3. After 4-5 days, the same slowdown symptoms begin again.&lt;/P&gt;&lt;P&gt;I saw that 8.1.3's release notes mentioned a few fixes related to performance/memory leaks, but none of them seemingly had any effect on these symptoms in my test case.&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.amp.cisco.com/Release%20Notes.pdf" target="_blank" rel="noopener"&gt;https://docs.amp.cisco.com/Release%20Notes.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So far as policy options, here is what we configure. No functional changes since July 2021 when we enabled Behavioral Protection, everything we have has been in place for over a year with no issues on version 7 clients.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ac513_0-1670021931186.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169796i7535593785873E1D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ac513_0-1670021931186.png" alt="ac513_0-1670021931186.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anyone else seeing this behavior with the version 8 clients for Secure Endpoint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 23:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4731584#M7190</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2022-12-02T23:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4731811#M7191</link>
      <description>&lt;P&gt;Please try this workaround to determine if this slowdown is related to the Secure Client UI component which is the graphical interface for Secure Endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Manually on one of your endpoints with Secure Endpoint 8.x.x installed that is experiencing this drastic slowdown&amp;nbsp; navigate to &lt;STRONG&gt;Windows Tool Bar&lt;/STRONG&gt; and in the left bottom corner click on the connector UI icon and select QUIT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2366.png" style="width: 872px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169805i0BD408F6F079ACA5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_2366.png" alt="Screenshot_2366.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Navigate to your policy under&lt;STRONG&gt; Management --- &amp;gt; Policies --- &amp;gt; Advanced Settings --- &amp;gt; Client User Interface (UI)&amp;nbsp;&lt;/STRONG&gt; and uncheck &lt;STRONG&gt;Start Client User Interface. &lt;/STRONG&gt;Please note that this will take affect on next reboot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2367.png" style="width: 875px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169804iF1DB4ED44CAFE2B0/image-dimensions/875x334?v=v2" width="875" height="334" role="button" title="Screenshot_2367.png" alt="Screenshot_2367.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By quitting this graphical interface you are not affecting functionality of secure endpoint and everything remains the same with all services running and still protecting your endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you see improvement or even complete recovery and no more issues please test one more thing by re-enabling the User UI and adding this ExPrev exclusion and apply this exclusion to your policy. Please make sure you sync the policy and either reboot your endpoint or restart the Secure Client for the ExPrev Policy to take the affect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2368.png" style="width: 871px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169806i07F9CC62999814AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_2368.png" alt="Screenshot_2368.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 16:06:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4731811#M7191</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2022-12-03T16:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4732635#M7193</link>
      <description>&lt;P&gt;Thanks for the advice! I'll have to get the client back on my devices and wait some number of days, and get others to try this out as we get new reports.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 15:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4732635#M7193</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2022-12-05T15:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4733511#M7196</link>
      <description>&lt;P&gt;Just heard back from a few test cases, and they claim that the slowdowns stopped as soon as the systray menu was closed out. Will have to add that exclusion next and see if it continues to help.&lt;/P&gt;&lt;P&gt;That's... a wildly problematic bug it sounds like. Surely this is a known bug and Cisco is working on it? (or at least I hope so, considering this suggestion was at the ready)&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 18:09:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4733511#M7196</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2022-12-06T18:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4733629#M7198</link>
      <description>&lt;P&gt;Yes we are currently actively working on this issue but so far we have very limited data collected as this issue seems to be sporadic and triggered differently. For example in your case you reported it takes couple days to get to that state,&amp;nbsp; some customers reported they can get to that state in few hours and we also have customers that have no issue at all.&lt;BR /&gt;&lt;BR /&gt;If the exploit prevention exclusion will not work for you I would suggest keep the UI disabled in the policy to prevent this issue. You can also open TAC case and get update through the case notes or stay put and I will update this thread as soon as I hear back about any new progress on this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 22:34:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4733629#M7198</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2022-12-06T22:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4737485#M7211</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Same problem here.&lt;/P&gt;&lt;P&gt;Try the exclusion but do not work on long term.&lt;BR /&gt;Just close the UI on a computer with the problem (and the exclusion), it solves the problem instantly.&lt;/P&gt;&lt;P&gt;I suppose the user haven't notifications when UI is closed...&lt;/P&gt;&lt;P&gt;Kind regards,&lt;BR /&gt;Ludo&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 23:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4737485#M7211</guid>
      <dc:creator>LudoD</dc:creator>
      <dc:date>2022-12-12T23:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4738032#M7212</link>
      <description>&lt;P&gt;Correct, NO UI = Notification.&lt;/P&gt;
&lt;P&gt;BTW: Lots of customers have the notification disabled anyway to not disturbed the end user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now as far for the latest, we have so far great success with several customers where we implemented exclusion to Script Control via back end as that's the only solution for Script Control. And based on those test it seems that Script Control which is separate from Exploit Prevention causing this. If things goes well we should have global fix released with in a week. Again there is no set date on this and once I gain more inlet I will update this thread.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you like to test this out you can try disable Script Control on small test group of computers to see the difference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Once the policy synchronize make sure to either restart the Secure Client or reboot the endpoint for the changes to take effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 18:27:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4738032#M7212</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2022-12-13T18:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4738053#M7213</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;If you like to test this out you can try disable Script Control on small test group of computers to see the difference.&lt;/BLOCKQUOTE&gt;&lt;P&gt;Would it need to be literally set to Disabled, or would Audit also provide the same results in a test case? (if unknown, that's fine)&lt;/P&gt;&lt;P&gt;Also as a heads up to everyone -- The Windows default Cisco-managed exclusions will be updated tomorrow as well. They include the system tray, plus a few extra things.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/214809-cisco-maintained-exclusion-list-changes.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/214809-cisco-maintained-exclusion-list-changes.html&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;C:\Windows\System32\omadmclient.exe&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;.automaticDestinations-ms&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;csc_ui.exe&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT size="2"&gt;for Exploit Prevention&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT size="2"&gt;Lastly, had one very weird symptom. Using 8.1.3 and all scanning modes set to Audit, I noticed that Secure Endpoint was keeping a hold onto M365 Apps for enterprise. I was trying to manually update the package, and it kept saying "apps can't close". Removed Secure Endpoint, and it kicked right through and updated. Closing&amp;nbsp;the systray menu did nothing for this one. First I've seen that, and I don't know if the above exclusions will account for this.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 19:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4738053#M7213</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2022-12-13T19:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4738955#M7216</link>
      <description>&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;As I promised here is the newest update:&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;The Engineering Team would be adding a ExPrev and a Script Control Exclusion for &lt;STRONG&gt;csc_ui.exe&lt;/STRONG&gt; for all the regions later today&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; line-height: 22px; margin: 12px 0px 12px 0px;"&gt;&lt;SPAN&gt;EU, APJC, NAM are scheduled for 11:00am MDT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; line-height: 22px; margin: 12px 0px 12px 0px;"&gt;&lt;STRONG&gt;Patch release notes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; line-height: 22px; margin: 12px 0px 12px 0px;"&gt;In policy.xml, csc_ui.exe is being added to exclude_app_list and script_control exclude list globally / by default in the exprev settings&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; line-height: 22px; margin: 12px 0px 12px 0px;"&gt;This was identified as one of the possible reasons for the Windows Performance Issue related to the new Secure Client UI (8.x and above) Since this is a trusted process, we see no harm in excluding this.&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; line-height: 22px; margin: 12px 0px 12px 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; line-height: 22px; margin: 12px 0px 12px 0px;"&gt;&lt;STRONG&gt;This will still apply:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; line-height: 22px; margin: 12px 0px 12px 0px;"&gt;Once the policy synchronize make sure to either restart the Secure Client or reboot the endpoint for the changes to take effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 17:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4738955#M7216</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2022-12-14T17:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4739105#M7217</link>
      <description>&lt;P&gt;We've pushed 8.1.3 to our production devices that were currently still on 8.0.1.&amp;nbsp; Devices should be rebooting soon (Windows Updates) so the new exclusions can take effect as well to go along with the newer client.&lt;/P&gt;&lt;P&gt;Here's hoping we see some better results out there!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 23:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4739105#M7217</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2022-12-14T23:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4748534#M7231</link>
      <description>&lt;P&gt;Unfortunately, not much change in behavior has been observed with both 1) client version 8.1.3, and 2) the new Cisco-maintained exclusions that included csc_ui.exe.&lt;/P&gt;&lt;P&gt;For example, I left my machine running over the weekend after our holiday. Coming in this morning with 4 days of uptime, window dragging was back to a choppy 20-ish fps and Outlook items were taking 2 or more entire seconds to open.&amp;nbsp; These problems immediately went away upon closing &amp;amp; reopening the Cisco Secure Client system tray icon.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 14:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4748534#M7231</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2023-01-03T14:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4749254#M7236</link>
      <description>&lt;P&gt;At this point I would suggest to open TAC case as we will need to investigate this further and gather some additional logs. Diagnostic Bundle will be one of them, but there will be some Windows Internal Tools that we need to run as well to get idea what is going with the operating system. Procmon, RAMMap, vmmap will be one of those tools that we will need to utilize to gather more Intel on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 18:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4749254#M7236</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-01-04T18:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4753787#M7237</link>
      <description>&lt;P&gt;I've opened a TAC case. Right now they're just looking at DART bundles for individual devices, not sure if our case is being linked up with others' in regards to this issue.&lt;/P&gt;&lt;P&gt;Has there been any other updates you can share from the engineering team? I see the ExPrev/Script Control global exclusions for csc_ui.exe were stated to be "one of the possible reasons", so are there other pieces still being actively investigated for this issue? Anything we can look at and try to rule out? (If you're able to divulge that info, that is)&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 16:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4753787#M7237</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2023-01-12T16:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4754554#M7240</link>
      <description>&lt;P&gt;Yes this will actually be investigated individually case by case. Majority customers with this issue reported that after we apply the fix globally their issue was mitigated. In such a cases like yours we will keep investigate and we will collect some additional information including recording of the issue for our DEV team. Also, I did found your case and already spoke with the engineer assigned to your case what will be the next steps. Thank you for you patience.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 22:39:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4754554#M7240</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-01-13T22:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4759222#M7267</link>
      <description>&lt;P&gt;Appreciate that! Still running 3 test scenarios to report back in our TAC case, but for anyone else following this thread/situation and was curious, here's some smoking guns I've found:&lt;BR /&gt;&lt;BR /&gt;1) The slowdowns &lt;EM&gt;are reproducible&lt;/EM&gt; on a Win11 22H2 machine of mine at home, with nothing of significance installed/running on it in the background. Based on this, I'd feel confident in saying the slowdowns are not an interaction between Secure Endpoint and any of our organization's configurations, deployed apps, policies, etc.&lt;/P&gt;&lt;P&gt;2) On my primary company machine where this has been reproducible, the issue &lt;EM&gt;goes away entirely&lt;/EM&gt; when moving it to a policy with the Secure Client UI disabled and all other settings matching our usual production policy.&lt;/P&gt;&lt;P&gt;So the issue is ongoing, and this pretty much solidifies the Secure Client UI (csc_ui.exe) being the common denominator to me. (I know previously in this thread, it was stated to be "suspected") Now the exact root cause, who knows...&lt;/P&gt;&lt;P&gt;Here's hoping a new client release may be on the horizon with some improvements. I was watching our console like a hawk, and noticed a version 8.1.5 client become available for our policies. However, it disappeared less than an hour later and never came back. Not sure if this was a glitch in automation, or if a planned release was delayed at the last minute?&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 23:56:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4759222#M7267</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2023-01-21T23:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4764100#M7281</link>
      <description>&lt;P&gt;Just wanted to chime in and say we are also experiencing this issue with 8.1.3. In my case, I have a very beefy Dell Precision T5810 with an nVidia Quadro M4000, so to see choppiness when dragging a window is quite shocking. The issue starts for me after only a couple hours of uptime. I can confirm killing the tray UI does resolve the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 15:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4764100#M7281</guid>
      <dc:creator>MakoWish</dc:creator>
      <dc:date>2023-01-27T15:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4764126#M7282</link>
      <description>&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;For any issues related to this I would highly suggest open a TAC case. I would also recommend to check for the exclusion and just verify that it is presented which you should be able to get from the &lt;STRONG&gt;policy.xml&lt;/STRONG&gt; &lt;EM&gt;(only Admin will be able to do that unless it's otherwise allowed).&lt;/EM&gt;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;You should see this in the policy.xml&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&lt;STRONG&gt;&amp;lt;exclude&amp;gt;csc_ui.exe&amp;lt;/exclude&amp;gt; &amp;lt;&amp;lt;&amp;lt; ----------------------------------- Global Exclusion&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;additionally I would gather some other helpful info such as, how many computers are being impacted, full procmon logs with time stamps before and after turning the UI off. Recording during WebEx session with your engineer will be also helpful.&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; line-height: 22px; margin: 12px 0px 12px 0px;"&gt;&lt;SPAN&gt;This issue will be now investigated on a separate manner individually case by case to figured out what is causing this slow down that is related to the User Interface &lt;STRONG&gt;(UI)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 16:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4764126#M7282</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-01-27T16:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4770496#M7298</link>
      <description>&lt;P&gt;Thanks for confirming it's being seen elsewhere, so hopefully this gets additional traction. Still working with TAC and collecting procmon captures, but what I've found on my own since my last post:&lt;/P&gt;&lt;P&gt;1) Issue continues to be consistently reproducible with Secure Endpoint 8.1.3 on a clean, unmanaged Windows 11 device. (not on our org network, no org software/configs, etc)&lt;/P&gt;&lt;P&gt;2) Issue also reproducible with 8.1.5 (released days ago), which I suspected as the Secure Client UI version did not change (5.0.00622).&lt;/P&gt;&lt;P&gt;Same as you've seen and as I've mentioned before, closing the Secure Client UI/tray resolves all issues.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 15:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4770496#M7298</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2023-02-07T15:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4794703#M7409</link>
      <description>&lt;P&gt;Update from TAC:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;Just wanted to let you know that Internal Team contacted to Devs and they are now working together on this issue. Devs are working deeper with the Exploit Prevention engine and its interaction with the csc_ui.exe process, so that they can isolate it and check if this is independent of this engine or not and perform the next internal tests.&lt;/P&gt;&lt;P&gt;Fortunately, the setup of the internal lab was successfully, &lt;STRONG&gt;this is now reproducible for the Devs and Internal team requests and the ongoing tests.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thank you for your time while the Internal Team and Devs are managing this ongoing investigation.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 14:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4794703#M7409</guid>
      <dc:creator>ac513</dc:creator>
      <dc:date>2023-03-15T14:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: CSE 8.0.1 and 8.1.3 causing significant slowdown after 4-5 days up</title>
      <link>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4794743#M7410</link>
      <description>&lt;P&gt;Thank you for the follow-up&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 14:36:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cse-8-0-1-and-8-1-3-causing-significant-slowdown-after-4-5-days/m-p/4794743#M7410</guid>
      <dc:creator>LudoD</dc:creator>
      <dc:date>2023-03-15T14:36:19Z</dc:date>
    </item>
  </channel>
</rss>

