Thanks, I await the PM. elastic-agent.exe
may occasionally launch an instance of elastic-endpoint.exe
to do some internal bookkeeping. Perhaps that's what you're seeing. If you could make sure to include PID, PPID, and command line as well as the user in the screenshot, and make sure all elastic-agent.exe
and elastic-endpoint.exe
are visible that would be great. I understand if there are bits you want to black out in the screenshot.
Which executable are you referring to here? elastic-endpoint.exe
or filebeat.exe
? Am I right to presume you're referring to the same memory use/CPU use concern you described in this other post (Endpoint 7.12.x migration to 7.13 Lesson learned with Fleet "On-Prim")?