Channels
  • g

    George

    7 months ago
    Hi, I'm running osquery on linux with process auditing via eBPF enabled. I've been using https://github.com/hillu/edr-loadgen/blob/master/edr-loadgen.go to check performance stats and I'm getting the same ~20% cpu usage results regardless of how many execs/s I run. I'm unsure if I'm missing something but I can't find any documentation that suggests CPU usage is limited to max 20%? I'm not very knowledgeable on Linux performance testing so it's quite possible I may have something configured wrong.
  • zwass

    zwass

    7 months ago
    cc @alessandrogario
  • s

    seph

    7 months ago
    There’s a pretty large performance bug around ebpf in 5.0. Checkout https://github.com/osquery/osquery/issues/7310