Troubleshooting Tip: High CPU usage caused by writer error of siemdb process
Description | This article describes the procedure to troubleshoot high CPU usage caused by a writer error of the siemdb process. |
Scope | FortiAnalyzer. |
Solution | Currently, the FortiAnalyzer VM is in version 7.4.8, and it has a high CPU usage, but the log rate is low, which does not make sense of high CPU usage.  ![]()   ![]()  Validated the upgrade path to avoid errors in the procedure.  ![]()  During validation it was identified a process consuming 436.9 % CPU usage. 'Clickhouse', the processes related to it (siembd and siemagent). The SIEM/SOAR license is active in the device, and siem module is being used, so it is not possible to disable it.  ![]()   ![]()  It was verified that the status of the siemdb process to identify errors in the statistics, but it only shows that the writers had low io-utils percentage and there were no counters of errors. Discarded errors in the crash log and klog.  ![]()  Since there were no useful detail it was decided to monitor at debug level the siemdb process, and a record was identified that reported there was an error with a writer.  ![]()  In order to resolve the error, a restart of the process was executed, but after rebooting, the error was still appearing.  ![]()  ![]()  In order to push normal behavior, it was necessary to clean the siem database.  ![]()  After execute cleaning process, and FortiAnalyzer was rebooted, the CPU usage was normalized, and confirmed that the clickhouse process came back to normal CPU consumption.  ![]()   ![]()  The siemdb process was monitored again at debug level and confirmed that no errors appeared again.  ![]()   ![]()  Related documents: |














