Disk and CPU spikes
This is not an issue with constant high CPU usage, lets get that clear now. We are seeing disk and CPU spikes on a regular cycle that can be tracked back to the Symantec Service.
In our VM environment this is easy to see on both CPU and Disk due to ability to look at current stats for the past hour/day/month on a VM.
SAV 10 clients: (10.1.6.6000, 10.1.7.7000 and 10.1.8.8000, on 2003 and XP clients)
Every 3 mins and 20 seconds you'll see a CPU and disk spike. Disk usage will be 4-8 KB/s and then jump to between 3-12 MB/s usage for about 20-40 seconds. Upon investigating with filemon we see that SAV is going out and rereading in its definition files again.
SEPM 11 clients (latest for sure, know we saw it in earlier clients also, 2008, 2003, xp, etc)
Similiar to SAV 10, except every 5 mins and 40 seconds on the machine I was just looking at.
Simple fix is to go in and restart the Symantec service, if it is a SAV 10 box, this fixes it until the next AV update, once it has updated its definitions it starts this lovely cycle over again. A full restart of the system will normally take care of the problem for a few days to a week, but when they are servers this isn't normally an option. A complete removal of the client, deleting all old def files out there in common folders, etc, will sometimes fix it for a week to a month, but typically comes back again sooner or later.
SEPM clients if you restart the service, this normally fixes them for a week or more, does not normally appear to come back the next time the defs are updated.
Out of 100+ servers we normally see this happening on a few a month, this week I'm seeing it on about 8 machines. I've opened a ticket in the past on it and basically got told to send them to liveupdate instead of our local managed server, not really an option nor did it fix it, but after trying repeatedly to get them to understand the problem (over a few days) I gave up and just went back to the "simple fix" mentioned above.
The CPU spike is annonying, but not my biggest concern, with shared storage on 8 VMs misbehaving, we see our average MB/s go from about 6 MB/s for all our VMs to spikes in the 24 MB/s, just depends on how many are misbehaving at the same time!
Anyone else seeing any similiar issues? Any idea why it is constantly rereading in its def files like this on some systems, but not others and why restarting the service fixes it until the next definition update?