RE: Sophos intercept X advanced

Hi Abhimanyu,

"Recently, we deployed Sophos Intercept X Advanced for one of our customers. Now, they are facing system slowdowns. Could you please help me resolve this issue?

Parents Reply Children
  •                     

    Please find the attached screenshot  for your reference and please do let me know how we can resolve this issue.

  • That view isn't the best one in TaskManager without expanding at least one of the "Sophos Endpoint Defense Software" items it's hard to say for sure which is which process:

    "Sophos System Protection" - SSPService.exe
    and
    "Sophos Endpoint Defense" - SEDService.exe 
    have the same description, so unless they are expanded it's hard to say for sure.

    In later versions they are now "Service" and "Software" to differentiate as shown below but they used to both be "Software", which is what you have.  This is the newer view:

    I assume the one with higher memory is SSPService.exe though which makes sense if SophosFileScanner.exe is also using CPU.

    For me this looks like Scanning is the first thing to focus on.

    Create a CSV of what is being scanned as mentioned in the previous comment.

    Thanks.

  • Hi  ,

    Customer is using SSD and also they are not using 3rd party antivirus solution.

  • Did you manage to obtain a CSV of what is being scanned having enabled "Debug" level for "Scan Summaries" for the process: SophosFileScanner.exe, under the logging section in Endpoint Self Help (ESH)?

    You could equally enable the CSV creation by running the following commands as ESH essentially just sets and unsets reg values, e.g.:

    New-ItemProperty -Path "HKLM:\SOFTWARE\Sophos\Logging\SFS\Scan Summaries" -Name "LogLevel" -Value 0 -Force

    Disable it after a few minutes during the issue with:

    Remove-ItemProperty -Path "HKLM:\SOFTWARE\Sophos\Logging\SFS\Scan Summaries" -Name "LogLevel" -Force

    You can then consider the newly created CSV files under: C:\ProgramData\Sophos\Sophos File Scanner\Logs\