Sysmon High Memory Usage..Windows 2019 Server

azr 1 Reputation point

Noticed, even with latest sysmon there is a memory leak. Memory keeps on increasing. 100mb in 6 hours since restart. Busier servers seem to increase the memory quicker. Over a week or so goes up over 1gb. 1 server over 30 days went to 4gb memory usage on the sysmon process. Anyone else notice this on 2019 Windows Servers? Some of the servers run some application logging with constant log writing to various log directories. Should we be omitting these directories in sysmon? Running latest sysmon 12.3 version as well.

Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
999 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. mariora 371 Reputation points

    Also, can you take some screenshots using RamMap to show exactly what kind of memory is increasing??
    Let's say one screenshot every 3 hours for 4 times to show the increase on 12 hours..


  2. mariora 371 Reputation points

    I asked to capture some RamMap screenshots because if by any chance the leaked memory has been transferred to the standby list, then you can "mitigate" the problem releasing it using rammap itself



    But in this case it looks like a real memory leak.. so there is nothing else to do that report it as a bug and wait for a fix..


  3. azr 1 Reputation point

    It must have to do with the fileDelete or update. We ended up exempting the full program path's that are doing a lot of file operations. Once doing that we are steady around 11.4mb. Seems to be on servers that do heavy logging and file operations. Thanks for your detailed information. Quite helpful. I see you said they are working on a fix. We can test it out once that is released too. Thanks.

    0 comments No comments