We had the exact same symptoms with one of our clients. The underlying issue was due to a network ACL blocking traffic. We initially found logs that indicated an issue with Forensics data not being uploaded. This pointed us towards checking connections from the CPHE clients with the Connectivity Tool ("C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Common\bin\CheckConnectivity.exe"). After seeing multiple fails we had our Network team whitelist the proper domains based off SK116590.
After adding the domains we no longer see CPU performance issues from the "Endpoint Forensic Recorder service". Hope this helps at least one person.