Currently have Sophos Central with Sophos Endpoint running on several machines here, i was the first to update to the latest Windows 10 1903 Update and noticed after the machine sitting idle for a while that the above service is consuming a lot of RAM.
Any solutions to this?
Sadly still no where with this - still communicating with Sophos on this one.
Hi Gareth Johnstone
Can you please PM me the support case number so that I can look into it for you?
Community Team Lead, Support & Services| Sophos Technical Support Support Videos | Product Documentation | @SophosSupport | Sign up for SMS Alerts If a post solves your question use the 'Verify Answer' button.
I will need to contact my team regarding this to check if we have seen many reports similar to this issue.
Same issue for me. I'm testing Win 10 1903 on my machine and SSPService.exe uses a load of RAM.
Same issue here as well with 1903 Enterprise. It will continue to consume RAM to the point of crashing the machine. Only ways around are to reboot just about every other day (64GB of RAM), or if caught before it starts crashing other services, then restarting the Sophos services forcibly seems to work.
I've heard back from my team and can confirm that we haven't noticed many reports regarding this issue. I would request you all to raise a support investigation with Sophos technical support team.
Well you've noticed reports from us!
Anyway there are already support cases open and according to mine there are at least a dozen reports of this problem and the issue has been been passed to Global Escalations and Development who are working with Microsoft.
Anything else you need us to keep you up to date with just let us know.
We are having the same issue.
Is it only on 1903 computers?
Have you tried:1. Disable Tamper Protection on the EP if enabled and reboot does it continue?2. Disable EDR if enabled? Evidence of it being enabled | disabled is:HKLME\SOFTWARE\Sophos\EndpointDefense\PolicyConfiguration DWORD edr_enabled 1|0Note: In Central this policy setting is in the ThreatProtection policy and called:"Allow computers to send data on suspicious files, network events, and admin tool activity to Sophos Central".3. If you rename sohosed.sys under: \windows\system32\drivers\ (will need to disable Tamper protection) and reboot.Does it happen then?
Same problem here with Windows 10 Pro 1903....