Troubleshooting Agent Performance Issues
search cancel

Troubleshooting Agent Performance Issues

book

Article ID: 292454

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Step-by-step guidance on troubleshooting Agent performance issues.

Environment

  • App Control Console: All Versions
  • App Control Agent: All Supported Versions
  • Microsoft Windows: All Supported Versions
  • Apple MacOS: All Supported Versions
  • Linux: All Supported Versions

Resolution

  1. Verify initial troubleshooting steps/details:
    1. Endpoint is using a supported and compatible Agent version.
    2. Agent Exclusions are present in any installed third-party security applications (e.g. antivirus, firewall, real-time scanner, vulnerability scanner, etc.).
    3. Agent is fully Initialized, as the Initialization process itself can be resource intensive.
    4. Verify the issue is able to be recreated with the Agent service fully stopped and the driver unloaded
      • If the issue persists, note relevant details (time to complete task, etc) with the Agent fully stopped and unloaded.
      • Proceed with troubleshooting.
    5. If using Windows Agent 8.9.x, add the two Agent Configs as outlined here.
    6. If using Linux Agent 8.8.x, downgrade and verify the issue persists with the latest Linux Agent 8.7.x version.
  2. Check for Custom Rules that should be avoided due to negative impacts on Agent performance.
  3. Verify whether any available Rapid Configs would apply in Rules > Software Rules > Rapid Configs and enable accordingly. Some examples include:
  4. If troubleshooting a Windows performance issue:
    1. Verify configs for Windows Updates that take a long time to install.
    2. Review guidance when Agent is scanning large files (.vmdk, .vhd, .bak, etc)
    3. Use Procmon to identify processes that could be included in a Performance Optimization Rule.
  5. If troubleshooting a Linux performance issue:
    1. Verify the Agent's db-wal growth is not negatively impacting performance.
    2. Verify the Linux System Performance Rapid Config is properly configured and applied.
  6. If troubleshooting Citrix devices, follow the Performance Hits and Slow Login on Citrix Devices steps.
  7. Verify the Agent's CL Version is up-to-date to ensure any/all changes are applied to the Agent.

If the issue persists:

Additional Information

  • A Performance Optimization Rule will ignore all file operations on the Path or File by the specified Process, except file executions.
  • Whenever possible, Agent Performance Logs should be collected from the latest available Agent version while still able to replicate the issue.