Sysmon High Memory Usage..Windows 2019 Server

azr 1 Reputation point
2020-12-29T20:47:21.36+00:00

Noticed, even with latest sysmon there is a memory leak. Memory keeps on increasing. 100mb in 6 hours since restart. Busier servers seem to increase the memory quicker. Over a week or so goes up over 1gb. 1 server over 30 days went to 4gb memory usage on the sysmon process. Anyone else notice this on 2019 Windows Servers? Some of the servers run some application logging with constant log writing to various log directories. Should we be omitting these directories in sysmon? Running latest sysmon 12.3 version as well.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,163 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. mariora 376 Reputation points
    2021-01-01T08:51:25.143+00:00

    Also, can you take some screenshots using RamMap to show exactly what kind of memory is increasing??
    Let's say one screenshot every 3 hours for 4 times to show the increase on 12 hours..

    Thanks
    -mario


  2. mariora 376 Reputation points
    2021-01-02T09:34:53.72+00:00

    I asked to capture some RamMap screenshots because if by any chance the leaked memory has been transferred to the standby list, then you can "mitigate" the problem releasing it using rammap itself

    52836-capture.jpg

    52776-capture2.jpg

    But in this case it looks like a real memory leak.. so there is nothing else to do that report it as a bug and wait for a fix..

    Thanks
    -mario


  3. azr 1 Reputation point
    2021-01-06T15:29:25.033+00:00

    It must have to do with the fileDelete or update. We ended up exempting the full program path's that are doing a lot of file operations. Once doing that we are steady around 11.4mb. Seems to be on servers that do heavy logging and file operations. Thanks for your detailed information. Quite helpful. I see you said they are working on a fix. We can test it out once that is released too. Thanks.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.