It's hard to guess what's the culprit without knowing your environment. The common issue causing high CPU and machine slowness is feedback loop between Elastic Endpoint and other security product. It's not recommended to run more than one security product but if that's your decision it's important to make appropriate exclusion on both ends, in Elastic Endpoint and in the other(s) product(s).
Apart from the above, this could be caused by a particular workflow. We have a built-in utilitytop to aid you with finding which feature/application is causing the biggest impact. When you spot some, you can try to add appropriate Trusted Application entry or turn off the feature.
Run:
"C:\Program Files\Elastic\Endpoint\elastic-endpoint.exe" top
or
sudo /Library/Elastic/Endpoint/elastic-endpoint top
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.