Sophos Endpoint realtime filescan on server causes high io write with $$$ files

Hello Sophos community,

is anybody able to tell me, why Sophos Endpoint needs a pretty noticable amount of write io directly on disk?

I can see the following in the servers ressource monitor every minute, as soon as realtime filescanner service is online:

Sophos is writing into a temporary folder with some .$$$ files. At first it looked fishy to me, but then I figured, that Sophos produces such temporary files for "complex scanning operations".

But why the heck do they need to be on disk? I would rather see them in RAM?

AND: Is there any way to figure out, what Sophos is scanning at the moment such high io is produced?

I came across this issue, because I am trying to find the bottleneck for our CAD software performance and it seems to lead me to io write performance. Sadly it wasn't as simple as just excluding the CAD share from real time scanning, just so you know.

Do others also see this behaviour? Is there a logical reasoning for this and is there a good approach to reduce the amount of io write requests from Sophos Endpoint on our servers?

I appreciate your feedback!

Kind regards,


[edited by: DuS at 3:18 PM (GMT -8) on 22 Nov 2022]