# Endpoint 7.12.x migration to 7.13 Lesson learned with Fleet "On-Prim"

**URL:** <https://discuss.elastic.co/t/endpoint-7-12-x-migration-to-7-13-lesson-learned-with-fleet-on-prim/274244>\
**Category:** Elastic Security\
**Tags:** fleet\
**Created:** [May 27, 2021, 5:28pm UTC](https://discuss.elastic.co/t/endpoint-7-12-x-migration-to-7-13-lesson-learned-with-fleet-on-prim/274244 "2021-05-27T17:28:45Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [June 10, 2021, 2:16pm UTC](https://discuss.elastic.co/t/endpoint-7-12-x-migration-to-7-13-lesson-learned-with-fleet-on-prim/274244/5 "2021-06-10T14:16:17Z")

</div>

Hi @PublicName

> [@PublicName](#):
>
> Would be really nice to see hard limits set for CPU/Memory and now disk utilization be set at a max percentage of free space lets say 50%/1025MB/2%. Options to override would be helpful as well. At no point should your endpoint security device be the thing that takes you offline that's rather ransomware like...

We are playing around with that type of feature, although I'm not sure when it will be ready for release.

In the meantime, is `elastic-endpoint.exe` using more CPU than you'd like? If so we'd be happy to dig into it a bit. One common cause of high CPU is two antivirus products monitoring each other in an endless loop, although other applications can do things as well that put more stress on Endpoint than you'd like. Adding a Trusted Application in Security -\> Administration often resolves that type of issue.

If the issue is with `elastic-endpoint.exe` there are two ways you can find what is causing it to use a lot of CPU. One is to look at the latest `data_stream.dataset : endpoint.metrics` document (found in a `metrics-*` data steam index) for the misbehaving Endpoint. In 7.13 we added `Endpoint.metrics.system_impact` details to this document, which is a list of programs on the computer that are causing Endpoint to do a lot of work. The `week_ms` value in each entry is the number of milliseconds spent over last week, the higher the value the more likely this is the cause of high CPU use for `elastic-endpoint.exe`.

Another option is to follow the guidance here ([Endpoint agent consistent 90+% CPU for some PCs - #13 by Matt\_Scherer](https://discuss.elastic.co/t/endpoint-agent-consistent-90-cpu-for-some-pcs/260693/13)) which outlines a way to create a Lens visualization to see what programs are causing Endpoint to produce the most data, which is likely to correspond with what is causing high Endpoint CPU.

Regardless of which route you take, its important to not create a Trusted Application for something like `svchost.exe,` which would create a large security blind spot in your network.

---

_[View the full topic](https://discuss.elastic.co/t/endpoint-7-12-x-migration-to-7-13-lesson-learned-with-fleet-on-prim/274244)._
