<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Fabian , in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090306#M988364</link>
    <description>&lt;P&gt;Hello Fabian ,&lt;/P&gt;
&lt;P&gt;During the traffic inspection if the snort consumes the CPU , then its very normal . Snort handles the traffic inspection and thus if the inspection is happening and if the CPU is bit high that time , then its very normal. Is the usage is always high every-time or is it goes down gradually during off business hours ?&lt;/P&gt;
&lt;P&gt;If the usage goes down during off hours then there is nothing to worry. Snort will consume CPU when the &amp;nbsp;detection is happening and its fine.&lt;/P&gt;
&lt;P&gt;Regards with the database usage , can you see the usage kind of hitting 90% or above ?&lt;/P&gt;
&lt;P&gt;Are you seeing some latency in the Web UI , that we can verify using the database troubleshooting . Run the following command from the FMC cli.&lt;/P&gt;
&lt;P&gt;FMC@123# DBCheck.pl&lt;/P&gt;
&lt;P&gt;See if you are observing any fatal errors in the output.If you are seeing any Fatal errors then it can be a problem with the database,then please open a TAC case to troubleshoot it .&lt;/P&gt;
&lt;P&gt;Rate if this answer helps.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jul 2017 06:50:47 GMT</pubDate>
    <dc:creator>Jetsy Mathew</dc:creator>
    <dc:date>2017-07-24T06:50:47Z</dc:date>
    <item>
      <title>Firepower Management Center - very high CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090303#M988361</link>
      <description>&lt;P&gt;hello team,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i want to use the FMC with Firepower. Now i tested the system with only 1 firepower module (hardware) and i always have a CPU usage with an average of 80%. It's so high, that my system is to slow to handle it. The Software of the FMC and firepower is all actual and updated.&lt;/P&gt;
&lt;P&gt;The FMC has its own server. ESXI, 8core CPU, 32GB RAM and 500GB HD. So i doubled the hardware that you need to handle it. no effect!&lt;/P&gt;
&lt;P&gt;I added 2 pictures from the usage.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please help me. Dont know what can help now. Thats only one module and i want to use maybe 5 in the future with the same FMC.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;best regards, Fabian&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 07:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090303#M988361</guid>
      <dc:creator>fabian.seeber</dc:creator>
      <dc:date>2022-03-10T07:24:29Z</dc:date>
    </item>
    <item>
      <title>Hello Fabian,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090304#M988362</link>
      <description>&lt;P&gt;Hello Fabian,&lt;/P&gt;
&lt;P&gt;Based on the software version that you are using check the compatibility of the software versions that you are using. Make sure the system requirements met according to the release notes. Also use the &lt;STRONG&gt;top&lt;/STRONG&gt; command in the Firepower cli to confirm the process which are consuming high cpu.&lt;/P&gt;
&lt;P&gt;Also check the policies that you have configured. You can try creating a test rule and apply the Balanced Security &amp;amp; Connectivity rules &amp;nbsp;to confirm if the policies are causing the CPU spike.&lt;/P&gt;
&lt;P&gt;Let me know if you have any questions.&lt;/P&gt;
&lt;P&gt;Rate if this answer helps.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 13:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090304#M988362</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2017-07-20T13:15:51Z</dc:date>
    </item>
    <item>
      <title>Hello Jetsy,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090305#M988363</link>
      <description>&lt;P&gt;Hello Jetsy,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for your answer. I checked the the asa processes and took a screenshot. There is an average of maybe 3% CPU usage. As you can see is that the command "snort" uses the most CPU. I tried dirrent software version and always got this high usage. sometimes its more, and sometimes its not that much.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What can you say about the campatibility? There is no information at the cisco hp about the hardware. Only: 8GB RAM, 4 core CPU and 250GB HD. And i think i have enough power. the FMC is running at a single virtual machine on his own server! there is nothing else on this machine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I think that the database is using this high cpu level. because every time i logged in at the web interface, the usage raises up.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;best regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Fabian&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 05:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090305#M988363</guid>
      <dc:creator>fabian.seeber</dc:creator>
      <dc:date>2017-07-21T05:50:56Z</dc:date>
    </item>
    <item>
      <title>Hello Fabian ,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090306#M988364</link>
      <description>&lt;P&gt;Hello Fabian ,&lt;/P&gt;
&lt;P&gt;During the traffic inspection if the snort consumes the CPU , then its very normal . Snort handles the traffic inspection and thus if the inspection is happening and if the CPU is bit high that time , then its very normal. Is the usage is always high every-time or is it goes down gradually during off business hours ?&lt;/P&gt;
&lt;P&gt;If the usage goes down during off hours then there is nothing to worry. Snort will consume CPU when the &amp;nbsp;detection is happening and its fine.&lt;/P&gt;
&lt;P&gt;Regards with the database usage , can you see the usage kind of hitting 90% or above ?&lt;/P&gt;
&lt;P&gt;Are you seeing some latency in the Web UI , that we can verify using the database troubleshooting . Run the following command from the FMC cli.&lt;/P&gt;
&lt;P&gt;FMC@123# DBCheck.pl&lt;/P&gt;
&lt;P&gt;See if you are observing any fatal errors in the output.If you are seeing any Fatal errors then it can be a problem with the database,then please open a TAC case to troubleshoot it .&lt;/P&gt;
&lt;P&gt;Rate if this answer helps.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 06:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090306#M988364</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2017-07-24T06:50:47Z</dc:date>
    </item>
    <item>
      <title>Nice tip Jetsy - I hadn't</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090307#M988365</link>
      <description>&lt;P&gt;Nice tip Jetsy - I hadn't seen that one.&lt;/P&gt;
&lt;P&gt;n.b. note the &lt;STRONG&gt;#&lt;/STRONG&gt; prompt - it must be run with root privileges so just "sudo su" first to change to superuser.&lt;/P&gt;
&lt;P&gt;Here's the output from a healthy FMC:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;BR /&gt;Cisco Fire Linux OS v6.2.1 (build 6)&lt;BR /&gt;Cisco Firepower Management Center for VMWare v6.2.1 (build 342)&lt;BR /&gt;&lt;BR /&gt;admin@sfvdc:~$ sudo su&lt;BR /&gt;Password: &lt;BR /&gt;root@sfvdc:/Volume/home/admin# DBCheck.pl&lt;BR /&gt;running database integrity check with the following options:&lt;BR /&gt;- use exception directory /usr/local/sf/etc/db_exceptions&lt;BR /&gt;- check refererences&lt;BR /&gt;- check enterprise objects&lt;BR /&gt;- check schema&lt;BR /&gt;- check required data&lt;BR /&gt;- log to stderr&lt;BR /&gt;getting filenames from [/usr/local/sf/etc/db_updates/index]&lt;BR /&gt;getting filenames from [/usr/local/sf/etc/db_updates/base-6.2.1]&lt;BR /&gt;getting exceptions from [/usr/local/sf/etc/db_exceptions/db_exceptions.yaml]&lt;BR /&gt;After Checking DB, Warnings: 0, Fatal Errors: 0&lt;BR /&gt;root@sfvdc:/Volume/home/admin# &lt;/PRE&gt;</description>
      <pubDate>Mon, 24 Jul 2017 07:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090307#M988365</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-24T07:03:07Z</dc:date>
    </item>
    <item>
      <title>dear jetsy and marvin,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090308#M988366</link>
      <description>&lt;P&gt;dear jetsy and marvin,&lt;/P&gt;
&lt;P&gt;thanks for the answers. I will check the DB in the next hour. But i already did that weeks ago with no effect and without any errors.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Marvin, whats your CPU usage average and which hardware do you use with your FMC?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;best regards&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 07:28:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090308#M988366</guid>
      <dc:creator>fabian.seeber</dc:creator>
      <dc:date>2017-07-24T07:28:11Z</dc:date>
    </item>
    <item>
      <title>i did it - no effect. no</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090309#M988367</link>
      <description>&lt;P&gt;i did it - no effect. no fatal errors. I attached a screenshot.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;@Jetsy&lt;/P&gt;
&lt;P&gt;Yes, the health monitor at the webinterface always alerts the CPU usage at over 90%.&lt;/P&gt;
&lt;P&gt;I attached a screenshot for that, too.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 08:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090309#M988367</guid>
      <dc:creator>fabian.seeber</dc:creator>
      <dc:date>2017-07-24T08:18:26Z</dc:date>
    </item>
    <item>
      <title>@fabian.seeber@web.de  </title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090310#M988369</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[@fabian.seeber@web.de]&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My office FMC runs as a VM with the minimal specs. (8 GB of RAM, 4 vCPUs and 250 GB hard drive). Load is averaging about 8% per core.&lt;/P&gt;
&lt;P&gt;I'm only monitoring one 5512-X (corporate office with about 50 users and 20 Mbps of Internet) a couple of lab ASAs that don't have much if any traffic day to day.&lt;/P&gt;
&lt;P&gt;I also checked a customer FMC that's another VM. They have 2 production data centers with ASA 5525-X HA pairs in each and a corporate office with a third. They are pushing a good bit more traffic and their FMC load is 2% per core across 8 cores.&lt;/P&gt;
&lt;P&gt;Haver you customized your IPS policies much? Most of my IPS&amp;nbsp;policies are "Balanced Security and Connectivity" and we almost never do much customization at the IPS policy level. I could see the Snort process being affected by customization there.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 12:20:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090310#M988369</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-24T12:20:04Z</dc:date>
    </item>
    <item>
      <title>Thats crazy. I doubled the</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090311#M988370</link>
      <description>&lt;P&gt;Thats crazy. I doubled the minimal hardware specs with the VM.&lt;/P&gt;
&lt;P&gt;There is only a 5506-X ASA connected. Nothing special. Only about 50 users in the network an 5 Mbps internet. So we dont have much traffic. Everxthing is normal (HD, RAM, Network...) only the CPU using is that high on every CPU.&lt;/P&gt;
&lt;P&gt;I tried now to sync the firepower and FMC time from the DC. Maybe that helps - atm it restarts the FMC.&lt;/P&gt;
&lt;P&gt;We dont have that much IPS policies. At the beginning we disabled IPS and had the same problem.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 13:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090311#M988370</guid>
      <dc:creator>fabian.seeber</dc:creator>
      <dc:date>2017-07-24T13:04:30Z</dc:date>
    </item>
    <item>
      <title>I wonder if it could be</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090312#M988371</link>
      <description>&lt;P&gt;I wonder if it could be something with respect to VMware and the hardware you are using.&lt;/P&gt;
&lt;P&gt;Is the server type and associated hardware one you have used in other ESXi installations?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 15:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090312#M988371</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-24T15:31:45Z</dc:date>
    </item>
    <item>
      <title>the hardware is okay... i</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090313#M988372</link>
      <description>&lt;P&gt;the hardware is okay... i used it for other ESXi installations in the past.&lt;/P&gt;
&lt;P&gt;Yesterday, I sync the FMC and FP time with the domaincontroler. In the night, the avarage was at about 20%. Now after i logged in to the webinterface - 90%. Everytime i want to see something from the web or the database. its slow and the average raises up to 95% per CPU.&lt;/P&gt;
&lt;P&gt;I tried to reinstall - no effect.&lt;/P&gt;
&lt;P&gt;tried another server - no effect.&lt;/P&gt;
&lt;P&gt;tried with or without updates - no effect.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 06:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090313#M988372</guid>
      <dc:creator>fabian.seeber</dc:creator>
      <dc:date>2017-07-25T06:07:06Z</dc:date>
    </item>
    <item>
      <title>Hello Fabian</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090314#M988373</link>
      <description>&lt;P&gt;Hello Fabian&lt;/P&gt;
&lt;P&gt;If you are facing issues while accessing the GUI , then this can be due to slow queries.&lt;/P&gt;
&lt;P&gt;We need the troubleshoot file to verify the database slow queries.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 08:46:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090314#M988373</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2017-07-25T08:46:40Z</dc:date>
    </item>
    <item>
      <title>where can i get the</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090315#M988374</link>
      <description>&lt;P&gt;where can i get the troubleshoot file?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 09:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090315#M988374</guid>
      <dc:creator>fabian.seeber</dc:creator>
      <dc:date>2017-07-25T09:10:08Z</dc:date>
    </item>
    <item>
      <title>Hello Fabian ,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090316#M988378</link>
      <description>&lt;P&gt;Hello Fabian ,&lt;/P&gt;
&lt;P&gt;Open a cisco TAC case and submit the troubleshoot file as per the following link.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote-SourceFire-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote-SourceFire-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Let me know if you have any questions&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 09:12:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090316#M988378</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2017-07-25T09:12:13Z</dc:date>
    </item>
    <item>
      <title>We tested another server now</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090317#M988379</link>
      <description>&lt;P&gt;We tested another server now with 3 times more power than the other one... now it works good. it has 9% average cpu usage and it's possible to work with the system.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks a lot for your help and time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 12:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3090317#M988379</guid>
      <dc:creator>fabian.seeber</dc:creator>
      <dc:date>2017-07-26T12:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: @fabian.seeber@web.de</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3933726#M988380</link>
      <description>Sorry to ask this here.. but i think my issue is some what similar.&lt;BR /&gt;In my FMC managing 2 FTD devices i am getting the error "High Memory Utilization Physical + Swap". How can i resolve this ? is it possible to free memory from CLI without disrupting production environment.</description>
      <pubDate>Wed, 02 Oct 2019 10:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3933726#M988380</guid>
      <dc:creator>NeWGuy1109</dc:creator>
      <dc:date>2019-10-02T10:50:33Z</dc:date>
    </item>
    <item>
      <title>FMC Resources</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3933747#M988382</link>
      <description>&lt;P&gt;You cannot free memory from cli practically speaking.&lt;/P&gt;
&lt;P&gt;The FMC can reload without affecting connections through the managed devices. So if it's a VM, you can shutdown the FMC, increase the allocated memory and then restart it.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 11:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center-very-high-cpu-usage/m-p/3933747#M988382</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-02T11:18:29Z</dc:date>
    </item>
  </channel>
</rss>

