Sophos Endpoint realtime filescan on server causes high io write with $$$ files

Hello Sophos community,

is anybody able to tell me, why Sophos Endpoint needs a pretty noticable amount of write io directly on disk?

I can see the following in the servers ressource monitor every minute, as soon as realtime filescanner service is online:

Sophos is writing into a temporary folder with some .$$$ files. At first it looked fishy to me, but then I figured, that Sophos produces such temporary files for "complex scanning operations".

But why the heck do they need to be on disk? I would rather see them in RAM?

AND: Is there any way to figure out, what Sophos is scanning at the moment such high io is produced?

I came across this issue, because I am trying to find the bottleneck for our CAD software performance and it seems to lead me to io write performance. Sadly it wasn't as simple as just excluding the CAD share from real time scanning, just so you know.

Do others also see this behaviour? Is there a logical reasoning for this and is there a good approach to reduce the amount of io write requests from Sophos Endpoint on our servers?

I appreciate your feedback!

Kind regards,

David



typos...
[edited by: DuS at 3:18 PM (GMT -8) on 22 Nov 2022]
Parents Reply
  • In that case, finding out the files being scanned is the way to go.

    Just running Process Monitor when the behaviour is occurring will probably make it reasonably obvious but the debug logging of SFS will be the most definitive.

    There is this reg key: HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\EndpointDefense\EventLog | VerboseLogging = 1 you can set  and restart SSPService. The files scanned are logged to the ApplicationEvent log but that will probably be too noisy and trample all over your event log. It may also not be apparent as to which files scanned are causing the temp files.

    For that reason, enabling the logging of SophosFileScanner (debug) is probably best.  You can also do it from Endpoint Self Help now I believe under the "Tools" tab -> Product Logging -> SFS section.

Children
No Data