This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

High CPU Usage - SEDService.exe offline

Hi, I have an annoying problem with the Sophos Endpoint Agent. When I am connected to the internet everything is fine. However, when I unplug the cable and am offline, the load on SEDService.exe goes way up. I have now noticed that under C:\ProgramData\Sophos\Endpoint Defense\Data\Event Journals\SophosED\Dns several .bin files are permanently created 100Mb in size and then zipped as .xz files. This takes a lot of performance and is certainly not the way it should be. Does anyone know the problem or have an idea which setting causes this? As soon as the Internet is available again, the utilization of the process goes down and no more files are created in the path.

There are various blocking entries in the sed log. Do they have anything to do with this?
What could it be?



This thread was automatically locked due to age.
Parents
  • Hi Mori,

    Thanks for reaching out to the Sophos Community Forum. 

    I believe you have an "XDR" license active. The event journals are used to record device activity so that data can be ingested into Sophos Central and the Threat Analysis Center. 

    When your device disconnects from the network, any data meant to be transmitted to Sophos Central is written to local files so it can be communicated later when the system reconnects. 

    Regarding the blocking entries in the sed log, could you provide a few lines from the logs? Feel free to send this to me via private message if you do not wish to post them here. 

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Hi Mori,

    Thanks for reaching out to the Sophos Community Forum. 

    I believe you have an "XDR" license active. The event journals are used to record device activity so that data can be ingested into Sophos Central and the Threat Analysis Center. 

    When your device disconnects from the network, any data meant to be transmitted to Sophos Central is written to local files so it can be communicated later when the system reconnects. 

    Regarding the blocking entries in the sed log, could you provide a few lines from the logs? Feel free to send this to me via private message if you do not wish to post them here. 

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children