CPU load on virtual machines due to ATP

Carolina Zamisnicu 316 Reputation points
2021-12-23T10:37:32.097+00:00

Hi,

I have a curiosity regarding one of the metrics I've came across. Recently, I noticed that my CPU load on my virtual machines is going pretty crazy and after some research I noticed that this is due to the mdatp_audisp_plugin, which is the ATP (currently Microsoft Defender). This service is not enabled for the entire subscription, I have the Microsoft Defender enabled only on several Log Analytics Workspaces (which includes servers resources-virtual machines only), which I divided to have a better visibility over the Defender service as I didn't want all the resources to be protected by this service.
First question is why is the load so big on my virtual machines? I understand that this is due to the plugin, what does the plugin has to do with the CPU load more exactly?
The second question is how can I optimize this load? For example, is there a possibility to minimize this load by implementing some policies at the Microsoft Defender level to segregate even more the service? Let's say I only want to use the Defender service from one Log Analytics Workspace for several folders only, let's say I do not want to use the service for one specific folder where my data is stored.
Can you help with a piece of advice?
Thank you!

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,158 questions
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
797 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,201 questions
0 comments No comments
{count} votes

1 additional answer

Sort by: Most helpful
  1. Carolina Zamisnicu 316 Reputation points
    2022-01-04T11:18:02.51+00:00

    Hello,

    For OS: CENTOS
    Version: 8

    Thanks