Troubleshoot high CPU usage

Prev Next

Determine the source of high CPU usage.

An analysis of customer reports of high CPU usage by the Trellix DLP Endpoint client (fcag.exe) has shown that many cases are due to one of two root causes:

  • Detection of the browser address bar URL.

  • Specific applications that are opening a large number of files for read purposes.

  1. In Policy Catalog, create a new Windows client configuration.

    Duplicate a policy that has a problem with CPU usage.

  2. In the Browsers section of the Operational Modes and Modules page, deselect web protection for the browser you want to test.

  3. Apply the policy to a small set of computers.

    If the issue is resolved, apply the client configuration to other systems.

Disabling browser address bar URL detection doesn't affect web protection, and doesn't affect web application awareness in web post protection rules, but it does affect web application awareness in the following rules:

  • Clipboard protection — You can't create rules that block copy/pasting text from a specific web application page.

  • Network share protection — You can't create rules that block saving a file or web page from a specific web application page to a network share.

  • Printing protection — You can't block printing from specific web applications.

  • Removable storage protection — You can't block saving files from a specific web application page.

  • Screen capture protection — You can't block screen shots when a specific web application page is visible on screen.

  • Web application content fingerprinting — You can't configure fingerprinting criteria to fingerprint files downloaded from a specific web application page.

In all of these cases, the browser address bar URL is required to identify the specific web-application.