Title
#windows
g

Gregory Storme

03/17/2022, 9:39 AM
when osquery 5.2.2 (installed using the fleet/orbit msi) runs on domain controllers, the LSASS process takes up 100% cpu and remains, until the osqueryd service is stopped couldn't find any known issues on this, has anyone else seen such behaviour?
defensivedepth

defensivedepth

03/17/2022, 11:35 AM
Do you have the Software Inventory enabled for FleetDM?
g

Gregory Storme

03/17/2022, 11:53 AM
yes
g

Gregory Storme

03/17/2022, 12:43 PM
great, thanks, disabling the software_inventory fixed it! i'll follow that thread
s

seph

03/17/2022, 6:56 PM
I would guess it’s going to be something crawling the users table
Mike Myers

Mike Myers

03/18/2022, 1:49 AM
Yea, Trail of Bits has been working on this problem. It's the number of users on the Domain Controller, that is the challenge. We have a PR here https://github.com/osquery/osquery/pull/7516
1:49 AM
Perhaps you can test, or we can get some reviews on it