Applications Systems
WMI or agent polling causes high CPU utilization on monitored Windows nodes in the SolarWinds Platform
When polling a node via WMI, the WMI process on the target machine experiences high CPU utilization. This issue may be experienced with SolarWinds Agents when a job engine worker gets a spike in CPU utilization. Additionally, verify if your server has enough resources, especially for CPU.
First published date
Last published date
Overview
When polling a node via WMI, the WMI process on the target machine experiences high CPU utilization.
This issue may be experienced with SolarWinds agents when a job engine worker gets a spike in CPU utilization. When troubleshooting, you should take into consideration the resources of the affected server, in particular, the CPU.
Product section
Cause
This is caused by:
- A large amount of Windows Event Log monitors, Asset inventory, and AppInsight are applied to the server. For example, domain controllers with large event logs, or application servers with large application, security and event logs.
- Low allocation of CPU core(s) to the server, resulting in insufficient processing power available to compute and process the events logs.
Resolution
- Reduce the amount of event logs on the server.
- Review the AppInsight components and disable any if not required.
- Reduce polling intervals on the application monitor.
- Reduce the scope of the Windows Event Log monitors. For example, look for less Event IDs, and so on.
- Identify and change the template polling method from WMI to RPC. For a comparison of difference in protocol, refer to Services Monitor - WMI vs RPC vs SNMP.
- Verify if there is enough CPU allocated for the affected server. For more information on minimum recommended resources, see the SAM System Requirements .