Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
lluner
Advisor
Jump to solution

Problem performance blade forensics

Gentlemen,

I'm receiving complaints about slowness on some machines using the forensic blade, especially I/O, based on the information provided. How can I perform the analysis in this case?

Endpoint version: 88.72.2001

Procedures already performed

1. I ran the diagnostics several times and have already made the exclusions.
2. I created a specific policy for the machine in question, setting the "Tuning" policy.

 

forensics4.pngforensics3.pngForensics2.pngForensics1.png

0 Kudos
2 Solutions

Accepted Solutions
the_rock
MVP Gold
MVP Gold

Hm...since you made all the exceptions, might be worth check with TAC.

Andy

View solution in original post

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Short of testing E89.00 to see if EPS-59766 is a potential factor here I would suggest engaging with TAC on this.

CCSM R77/R80/ELITE

View solution in original post

5 Replies
the_rock
MVP Gold
MVP Gold

Does it happen only on some machines randomly?

Andy

0 Kudos
lluner
Advisor

Hi andy 

They complain about the machine's slowness and it shows this information, both I/O and the process that is consuming a lot. I believe that the checkpoint could have a thoubleshooting to identify or some configuration regarding this forensic blade that always consumes a lot of I/O, it is worth noting that the disk is NVME

0 Kudos
dukenukemz
Explorer

Does the same thing happen on machines with 16GB of ram? it looks like your 8GB of ram is maxed out. On the policy > Behavioral protection > Advanced SEttings > Select Low Memory Mode.

 

See if that helps

0 Kudos
the_rock
MVP Gold
MVP Gold

Hm...since you made all the exceptions, might be worth check with TAC.

Andy

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Short of testing E89.00 to see if EPS-59766 is a potential factor here I would suggest engaging with TAC on this.

CCSM R77/R80/ELITE

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events