High memory usage in combination with f-secure

ronald van den berg 241 Reputation points
2021-10-25T07:48:43.453+00:00

In some domains that we monitor the anti-virus client is replaced by f-secure. Since then the memory usage on a gateway is increasing till memory is full and the gateway restarts.

There is a well known document on which paths and processes of scom to exclude in your av client but that doesn't help. We now removed f-secure and all is back to normal.

Anyone using f-secure have any tips for us?

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,413 questions
0 comments No comments
{count} votes

Accepted answer
  1. SChalakov 10,261 Reputation points MVP
    2021-10-25T09:54:16.927+00:00

    Hi Ronald,

    I have used it once, but I can tell you what you need to do from the support perspective.
    This issue is most proably caused by the f-secure filter driver. AV filter drivers are know to cause such issues, that is the reason why Microsoft released this article:

    How to temporarily deactivate the kernel mode filter driver in Windows
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/performance/deactivate-kernel-mode-filter-driver

    When you are troubleshooting any one of these issues, frequently, you have to do more than just stop or disable the services that are associated with the software. Even if you disable the software component, the filter driver is still loaded when you restart the computer. You may be forced to remove a software component to find the cause of an issue.

    So my advice would be to contact F-Secure and ask about an update or a fix.

    I hope I could help you out with that!

    Best Regards,
    Stoyan

    ----------

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    1 person found this answer helpful.
    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. ronald van den berg 241 Reputation points
    2021-11-01T14:14:13.95+00:00

    All i know it's definitively related to F-secure, and scom was it's victim.

    But meanwhile i've heard that the f-secure admin did do some more exclusion configuration than before what i was aware of, so it seems the solution is still in the part of excluding the scom processess and the health state folder but apparently it needs to be done at more then 1 level.

    1 person found this answer helpful.
    0 comments No comments

  2. ronald van den berg 241 Reputation points
    2021-10-27T09:32:18.177+00:00

    Hi Stoyan,

    Thanks for your reply, unfortunately i cannot say it helps since this issue is suddenly resolved without anyone admitting to change anything so i'm waiting till it happens again.

    0 comments No comments

  3. SChalakov 10,261 Reputation points MVP
    2021-10-28T08:16:00.65+00:00

    Hey Ronald,

    do you suspect it can be indeed related to SCOM?

    Regards,
    Stoyan

    0 comments No comments