Skip to content
Notifications
Clear all

What's the actual performance hit of the agent on a production EC2 instance?

1 Posts
1 Users
0 Reactions
1 Views
(@cipher_blue)
Estimable Member
Joined: 3 months ago
Posts: 133
Topic starter   [#21452]

Alright, let's cut through the marketing. Everyone's data sheet claims "lightweight" and "negligible impact." I'm calling it: those claims are based on lab environments, not a real production box under load.

I'm evaluating Lacework for a set of mid-sized web servers (AWS EC2, c5.2xlarge, typical LAMP stack). The compliance and runtime threat stuff looks useful, but if the agent turns my instances into molasses, it's a non-starter.

I need real-world, anecdotal evidence from people who've rolled this out beyond the POC. Not what the SE showed on a pristine t3.micro.

* What's the actual CPU/RAM overhead you've observed during peak traffic? Percentages, not "low."
* Does the filesystem monitoring (FIM) cause noticeable I/O wait when it kicks in? We've had other agents murder disk latency before.
* Any network performance hit from the network metering?

Bonus points if you've compared it to other agents in the space (Wiz, Snyk, etc.) on similar workloads. Show me the `top` output or CloudWatch graphs.



   
Quote