cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2221
Views
0
Helpful
2
Replies

Cisco AMP taking too much memory

mdm0110
Level 1
Level 1

Hello. I have a bunch of VMWare hosted servers that AMP is hogging memory on. Most noticeably, it's really hogging it up on several servers that have 4GB of memory, to the point where I get constant Nagios alerts about memory usage. Previous, I could uninstall AMP and reinstall it (since this required no downtime/rebooting of the servers). But this only lasts 3-4 weeks and then it starts happening again. 

I don't want to post the whole SFC just yet until I can redact company information, but this is one thing that I am seeing constantly in here. I don't know if it is related. 

"(2071781796, +59843 ms) Jul 13 00:28:11 [4448]: ERROR: ProcessFileChecksum pStr: (null), pProcessStr: \\?\C:\Windows\System32\cscript.exe is NULL. Skipping over for 2 type
(2071841796, +60000 ms) Jul 13 00:29:11 [4448]: ERROR: ProcessList::Add: WARNING: Terminating an existing process cachent that was not expected: PID: 146092, ticksStarted: 132216162
(2071841796, +0 ms) Jul 13 00:29:11 [4444]: ERROR: ProcessList::Add: WARNING: Terminating an existing process cachent that was not expected: PID: 145344, ticksStarted: 131050406
(2071841796, +0 ms) Jul 13 00:29:11 [4444]: ERROR: ProcessFileChecksum pStr: (null), pProcessStr: \\?\C:\Windows\System32\cscript.exe is NULL. Skipping over for 2 type
(2071841953, +157 ms) Jul 13 00:29:11 [1964]: ERROR: PipeCommon.cpp:HandlePipeIO:68: GetOverlappedResult failed : 109 : The pipe has been ended." 

2 Replies 2

mdm0110
Level 1
Level 1

I think I managed to scrub all the IP's, domain names, user names, etc.. Hopefully. 

mdm0110
Level 1
Level 1

It's also worth mentioning that I can stop the Cisco Secure Endpoint service and the memory usage IMMEDIATELY falls to about 30%. Then, after starting the service again, it stays around 37%. It just seems like about once a month, something happens and it pegs out, and I can't tell what it is