Skip to main content
HernandezA
Staff
Staff
January 26, 2026

Troubleshooting Tip: High CPU usage caused by writer error of siemdb process

  • January 26, 2026
  • 0 replies
  • 731 views

Description

This article describes the procedure to troubleshoot high CPU usage caused by a writer error of the siemdb process.

Scope

FortiAnalyzer.

Solution

Currently, the FortiAnalyzer VM is in version 7.4.8, and it has a high CPU usage, but the log rate is low, which does not make sense of high CPU usage.

get system performance

 

CPU usageA.jpg

 

diagnose fortilogd lograte

 

lowlogratereceived.jpg

 

Validated the upgrade path to avoid errors in the procedure.

diagnose cdb upgrade summary

 

upgradesummary.jpg

 

During validation it was identified a process consuming 436.9 % CPU usage. 'Clickhouse', the processes related to it (siembd and siemagent). The SIEM/SOAR license is active in the device, and siem module is being used, so it is not possible to disable it.

execute top

 

highCPU.jpg

 

diagnose license list

 

sieminUse.jpg

 

It was verified that the status of the siemdb process to identify errors in the statistics, but it only shows that the writers had low io-utils percentage and there were no counters of errors. Discarded errors in the crash log and klog.

diagnose test application siemdb 4 

 

testappsiemdb4_writter_Stats.jpg

 

Since there were no useful detail it was decided to monitor at debug level the siemdb process, and a record was identified that reported there was an error with a writer.

diagnose debug application siemdb 8
diagnose debug enable

 

error writter commit.jpg

 

In order to resolve the error, a restart of the process was executed, but after rebooting, the error was still appearing.

diagnose test application siemdb 99

 

restarted siemdb process.jpg

 

error persisted.jpg

 

In order to push normal behavior, it was necessary to clean the siem database.

diagnose siem remove database ALL

Remove the entire SIEM database has been requested.

This operation will remove all data in the SIEM database and reset the database server.

This operation will reboot the device.

Do you want to continue? (y/n) y

 

removed siemDB.jpg

 

After execute cleaning process, and FortiAnalyzer was rebooted, the CPU usage was normalized, and confirmed that the clickhouse process came back to normal CPU consumption.

execute top

 

CPUusageforclockhouseproces OK.jpg

 

get system performance

 

AfterCPU.jpg

 

The siemdb process was monitored again at debug level and confirmed that no errors appeared again.

diagnose debug application siemdb 8
diagnose debug enable

 

Confirmed writter ok.jpg

 

diagnose test application siemdb 4

 

Aftercleared no errors in debug and iowritter increased.jpg

 

Related documents:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!