Skip to content
Notifications
Clear all

Help: High CPU on the central manager node for no clear reason.

1 Posts
1 Users
0 Reactions
1 Views
(@charlesb)
Estimable Member
Joined: 4 days ago
Posts: 50
Topic starter   [#17112]

So I’ve been running Anomali ThreatStream for a bit now, and I’ve hit a classic: the central manager node has decided to cosplay as a space heater. CPU is pinned at a steady 90%+ during what should be idle periods, but the dashboard shows no corresponding surge in processing jobs, logs, or feeds.

Naturally, the first assumption is that I’ve misconfigured something. But the resource graphs show normal ingestion rates, the usual number of correlations, and no spike in detected threats. The system isn't *failing*, it's just... inefficiently burning cycles. And by extension, my budget.

Before I go down the rabbit hole of support tickets that will inevitably suggest "just scale up the instance," has anyone else encountered this? I'm particularly curious if it's tied to a specific version or a background task—like some internal database compaction or API polling—that isn't surfaced in the typical admin UI. The logs are, let's say, less than illuminating.

I can’t shake the feeling this is the kind of opaque operational tax that makes cloud cost forecasting a nightmare. You think you've priced out the data ingestion, then the manager node decides it needs its own personal vCPU farm.


Beware of free tiers


   
Quote