Comprehensive data protection for all workloads
Post Reply
karsten123
Service Provider
Posts: 569
Liked: 140 times
Joined: Apr 03, 2019 6:53 am
Full Name: Karsten Meja
Contact:

AV exclusion Sophos & postgresql

Post by karsten123 »

Hi,

we use Sophos AV and i think, the exclusion of the related path according kb1999 is not enough. Do you have experience, if it is necessary to additionally exclude the processes? And what are the vital processes of VBR?

The postgresql documentation says, that you must exclude data folder and the postgresql.exe process. So „c:\program files\postgresql\15\data“, right? And the process is „postgresql.exe“ on Windows?

Thanks in advance
Karsten
david.domask
Veeam Software
Posts: 2590
Liked: 606 times
Joined: Jun 28, 2016 12:12 pm
Contact:

Re: AV exclusion Sophos & postgresql

Post by david.domask »

Hi Karsten,

KB1999 is focused specifically on Veeam items and what paths to set for exclusions; from my experience, setting specific processes is not a requirement but this will vary from AV to AV, so it's difficult to tell -- are you seeing issues where you suspect Sophos is interrupting Veeam operations even with KB1999 implemented in full?

I've not seen that AV specifically interferes with PostgreSQL, but the postgres wiki has the suggestions I think you're referring to, and I would just follow their advice. But as noted, I just personally haven't seen many cases where AV + Postgres was the root cause, but it of course is reasonable to follow the postgres wiki advice.
David Domask | Product Management: Principal Analyst
amarsaudon
Novice
Posts: 3
Liked: never
Joined: Mar 10, 2020 5:05 pm
Full Name: Alex Marsaudon
Contact:

Re: AV exclusion Sophos & postgresql

Post by amarsaudon »

karsten123 wrote: Jul 16, 2024 9:31 am Hi,

we use Sophos AV and i think, the exclusion of the related path according kb1999 is not enough. Do you have experience, if it is necessary to additionally exclude the processes? And what are the vital processes of VBR?

The postgresql documentation says, that you must exclude data folder and the postgresql.exe process. So „c:\program files\postgresql\15\data“, right? And the process is „postgresql.exe“ on Windows?

Thanks in advance
Karsten
Did you ever figure this out? I am having the same experience. Implemented kb1999 in full, and added the exceptions described in the Postgres Wiki.
After an hour or so of runtime, performance will tank to an unusable state. Uninstalling Sophos immediately resolves the issue. Of course Sophos logging is more or less non-existent, so I don't have much to go on outside Google.
karsten123
Service Provider
Posts: 569
Liked: 140 times
Joined: Apr 03, 2019 6:53 am
Full Name: Karsten Meja
Contact:

Re: AV exclusion Sophos & postgresql

Post by karsten123 »

the customer raised a support ticket with Sophos with no outcome. Sophos said, that there are no known issues with Veeam.
in the end we did increase CPU and memory resources. done
dasfliege
Service Provider
Posts: 303
Liked: 65 times
Joined: Nov 17, 2014 1:48 pm
Full Name: Florin
Location: Switzerland
Contact:

Re: AV exclusion Sophos & postgresql

Post by dasfliege »

We're encountering the same issue now on our VBM365 servers. Sophos claims huge amount of memory and CPU ressources and the server becomes pretty unresponsive.
We've forgot to add exclusions for postgres after updating, so the behavior is explainable in our case. I have just created these exclusions some minutes ago and will check how it behaves now. If it's still an issue, we will track it down with sophos to the end. I don't think that just extending ressources is a good idea. Also our server is not exhausted in ressources yet, but still responds pretty laggy and i also think that backup performance is affected by this problem if postgres is scanned extensively.

@amarsaudon
Sophos does provide pretty extensive logging where you see exactly what is scanned at which time. You just have to enable it. You can refer to the following thread to get this done: https://community.sophos.com/intercept- ... paged-pool

Image
Post Reply

Who is online

Users browsing this forum: Bing [Bot] and 122 guests