# My Macos elastic-endpoint process CPU is too high, up to 103%

**URL:** <https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640>\
**Category:** Endpoint Security\
**Created:** [July 26, 2022, 12:52pm UTC](https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640 "2022-07-26T12:52:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [July 26, 2022, 12:52pm UTC](https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640/1 "2022-07-26T12:52:16Z")

</div>

My Macos elastic-endpoint process CPU is too high, up to 103%，It causes the computer to heat up badly, how can I solve this problem：

 ![截屏2022-07-26 20.46.43](https://us1.discourse-cdn.com/elastic/original/3X/2/8/28aaf506f37665e0f1ddf7f8e6f86cfe79f9afa2.png)

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [July 27, 2022, 2:06am UTC](https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640/2 "2022-07-27T02:06:32Z")

</div>

Hi @xqaiviwjxzw . It's likely that Endpoint is monitoring some high load activity on your system. A common approach to lower Endpoint's CPU use is to determine what that activity is and then put in an alert exception or trusted app entry to prevent that known benign activity from being monitored.

The first step is to figure out what that activity is. Every time Endpoint applies policy, and every 24 hours as well, Endpoint reports the 20 top processes causing it to use CPU in a document that lives in the `metrics-endpoint.metrics-*` index. To grab fresh data for that can you first re-apply Endpoint's policy by going to Security App -\> Policies, then selecting the policy that is applied to the Endpoint and hitting Save without making any changes to it. All Endpoints using that policy should reapply their policy and regenerate the document that is stored in `metrics-endpoint.metrics-*`.

After doing that, go to Management -\> Dev Tools and run a query like below. Substitute YOUR\_HOST\_NAME with the host name of the affected host. Or use a different query to get the latest document from the affected host if you'd like to search a different way.

```auto
GET metrics-endpoint.metrics-*/_search?size=1
{
  "query": {
    "bool": {
      "must": [
        {"match": {"host.name": "YOUR_HOST_NAME"}}
      ]
    }
  },
  "sort": [
    {"@timestamp": {"order" : "desc"}}
  ]
}

```

Once you run that query, you should see the latest metrics document from the affected Endpoint. In it you'll see a `system_impact` array containing the top 20 system processes causing Endpoint to use CPU along with the total number of milliseconds spent per event type and/or malware scanning in the `week_ms` field. There's also some other information in there, like how busy different Endpoint threads are, that we can also use to figure out what is happening. Depending on what the data shows, we can figure out a next step of what can hopefully be done to lower Endpoints CPU.

You may feel the metrics document contains some personal information. Feel free to PM it to me directly if, redacting whatever you think is appropriate if you'd like.

---

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [July 27, 2022, 2:16am UTC](https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640/3 "2022-07-27T02:16:29Z")

</div>

Thanks ferullo, the metrics module is currently off, before it was on it would cause the server to lag more.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [July 27, 2022, 7:55am UTC](https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640/4 "2022-07-27T07:55:11Z")

</div>

Hi [xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)

> the metrics module is currently off

We are talking here about different thing, independent internal Endpoint Security metrics, documents consisting of detailed internal Endpoint Security statistics which Metric Beat cannot even collect because it's not aware of the functional blocks of Endpoint Security code. Metric Beat collects only generic "black box" metrics about processes on your system.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2022, 7:56am UTC](https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640/5 "2022-08-24T07:56:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
