Troubleshooting Agent Performance Issues
search cancel

Troubleshooting Agent Performance Issues

book

Article ID: 292454

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Step-by-step guidance on troubleshooting Agent performance issues.

Environment

  • App Control Console: All Versions
  • App Control Agent: All Supported Versions
  • Microsoft Windows: All Supported Versions
  • Apple MacOS: All Supported Versions
  • Linux: All Supported Versions

Resolution

Initial Steps

  1. Verify the endpoint
  2. Verify the issue can be recreated with the Agent service fully stopped and the driver unloaded
    • If the issue persists, resolve the underlying issue first before proceeding.
    • If the issue does not persist, proceed with troubleshooting.

Recent Issues

  1. Windows
  2. Linux

General Guidance/Continued Investigation

  1. Application specific considerations:
  2. Verify the Agent's CL Version is up-to-date to ensure any/all changes are applied to the Agent.
  3. Check for Custom Rules that should be avoided due to negative impacts on Agent performance, examples:
    • Using Authenticated User in Custom Rules will result in unnecessary Rule Expansion
    • Performance Optimization Rules should avoid including Interesting Files to prevent stalls on executions.
  4. Upgrade to the latest Agent version to eliminate performance enhancements and other Resolved Issues.
    • Implementing workarounds or exclusions for Resolved Issues may reduce the security posture of the Agent.
  5. For Windows, use Procmon to identify processes that could be included in a Performance Optimization Rule.
    • A Performance Optimization Rule will ignore Modifying Operations (Write, Write Delayed, Delete, Rename, Create New, Mmap Write) on the Path or File by the specified Process.

 

If the issue persists, collect & provide the following information in a Support case:

Additional Information

  • Agent Performance Logs should be collected from the latest available Agent version while still able to replicate the issue.