Applications Systems

WMI or agent polling causes high CPU utilization on monitored Windows nodes in the SolarWinds Platform

When polling a node via WMI, the WMI process on the target machine experiences high CPU utilization. This issue may be experienced with SolarWinds Agents when a job engine worker gets a spike in CPU utilization. Additionally, verify if your server has enough resources, especially for CPU.

First published date

10/23/2018 8:46 PM

Last published date

7/11/2025 6:07 PM

Overview

When polling a node via WMI, the WMI process on the target machine experiences high CPU utilization.

This issue may be experienced with SolarWinds agents when a job engine worker gets a spike in CPU utilization. When troubleshooting, you should take into consideration the resources of the affected server, in particular, the CPU.

Product section

Server Application Monitor

Cause

This is caused by:

  1. A large amount of Windows Event Log monitors, Asset inventory, and AppInsight are applied to the server. For example, domain controllers with large event logs, or application servers with large application, security and event logs.
  2. Low allocation of CPU core(s) to the server, resulting in insufficient processing power available to compute and process the events logs.

Resolution

  • Reduce the amount of event logs on the server.
  • Review the AppInsight components and disable any if not required.
  • Reduce polling intervals on the application monitor.
  • Reduce the scope of the Windows Event Log monitors. For example, look for less Event IDs, and so on.
  • Identify and change the template polling method from WMI to RPC. For a comparison of difference in protocol, refer to Services Monitor - WMI vs RPC vs SNMP.
  • Verify if there is enough CPU allocated for the affected server. For more information on minimum recommended resources, see the SAM System Requirements .
Note: Investigate if there are other 3rd-party application that consumes the resources on the Orion server.