cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2500
Views
35
Helpful
4
Replies

We are seeing very high memeory utilization on our ISE vm

cae_technology
Level 1
Level 1

Anyone with any idea what may be causing this ?

 

Name Process ID Physical Memory java 47204 6,943,592 kB jsvc 123935 6,336,788 kB java 46761 3,469,308 kB oracle_10981_cp 10981 3,225,292 kB oracle_53661_cp 53661 3,207,040 kB ora_dbw0_cpm10 22474 3,145,184 kB ora_dbw1_cpm10 22476 3,140,212 kB oracle_48793_cp 48793 2,481,108 kB ora_p001_cpm10 22518 1,764,248 kB ora_p000_cpm10 22516 1,730,164 kB

 

total memory: 32761988 kB free memory: 1451824 kB cached: 8170056 kB swap-cached: 958064 kB output of free command: total used free shared buff/cache available Mem: 32761988 19899980 1451824 6833116 11410184 5398980 Swap: 8191996 8191992 4

 

Displaying ISE application status ....
*****************************************
ISE PROCESS NAME STATE PROCESS ID
--------------------------------------------------------------------
Database Listener running 21929
Database Server running 134 PROCESSES
Application Server running 92224
Profiler Database running 114285
ISE Indexing Engine running 46761
AD Connector running 41166
M&T Session Database running 46021
M&T Log Processor running 47204
Certificate Authority Service running 13065
EST Service running 127569
SXP Engine Service disabled
Docker Daemon running 23887
TC-NAC Service disabled

2 Accepted Solutions

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni

This does not look out of the ordinary to me for a 3615 template/size node, or even larger for that matter. The way that Linux uses memory and displays "free" memory is misleading. The buffer/cache can be considered free memory .

There have been memory leaks in the past though that show up over loner uptimes, which ISE Version and patch are you on? The larger question is really if you are seeing any service impact, if so then TAC is the correct course. 

View solution in original post

I would not be considered about what you are seeing right now, but as a preventative measure you should look at scheduling a change to implement patch 5. There is a memory leak that was recently fixed along with about 90 other caveats.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv07101

 

2.7 patch 5 release notes and resolved caveats
https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/release_notes/b_ise_27_RN.html#Cisco_Concept.dita_102b1d23-d390-4b44-9554-5dd972b679da

 

View solution in original post

4 Replies 4

Damien Miller
VIP Alumni
VIP Alumni

This does not look out of the ordinary to me for a 3615 template/size node, or even larger for that matter. The way that Linux uses memory and displays "free" memory is misleading. The buffer/cache can be considered free memory .

There have been memory leaks in the past though that show up over loner uptimes, which ISE Version and patch are you on? The larger question is really if you are seeing any service impact, if so then TAC is the correct course. 

Thank you Damien

 

Cisco Application Deployment Engine OS Release: 3.0
ADE-OS Build Version: 3.0.7.057
ADE-OS System Architecture: x86_64

Copyright (c) 2005-2019 by Cisco Systems, Inc.
All rights reserved.


Version information of installed applications
---------------------------------------------

Cisco Identity Services Engine
---------------------------------------------
Version : 2.7.0.356
Build Date : Thu Nov 14 02:21:59 2019
Install Date : Wed Dec 2 16:06:06 2020


*****************************************

 

No Impact at the moment

I would not be considered about what you are seeing right now, but as a preventative measure you should look at scheduling a change to implement patch 5. There is a memory leak that was recently fixed along with about 90 other caveats.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv07101

 

2.7 patch 5 release notes and resolved caveats
https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/release_notes/b_ise_27_RN.html#Cisco_Concept.dita_102b1d23-d390-4b44-9554-5dd972b679da

 

Thank you and will try to upgrade to patch 5 and see