Issue ID: AV-08
Applies to: Datto AV
Environment: Windows Server (primary pattern); macOS server use not confirmed
KB type: Troubleshooting
Symptoms
- Elevated memory (RAM) usage attributed to the Datto AV process.
- General slowdown or lag on a server running Datto AV, especially after an update.
- Performance issue may be intermittent or sustained, potentially tied to scan or update windows.
Cause
High memory or CPU usage by Datto AV on servers is most often associated with:
- Real-time scanning of high I/O workloads (such as databases or file servers).
- Insufficient or missing exclusions for resource-intensive directories or processes.
- Scan schedule conflicts or overlapping with other resource-heavy operations.
- Third-party antivirus conflicts.
- Less commonly, a resource-usage regression introduced by a recent update.
There is no universal or official Datto AV exclusion list for servers. Exclusions must be tailored to the environment and workload.
Resolution steps
Follow these steps to troubleshoot and resolve high memory or CPU usage by Datto AV on servers:
-
Identify the process and usage pattern
- Use Task Manager or Resource Monitor to record the exact Datto AV process consuming resources.
- Note the measured memory and CPU usage, and when the spike started.
- Correlate the timing with any recent Datto AV updates or configuration changes.
-
Determine server role and workload
- Identify the server’s primary role (e.g., database, file server, application server).
- Check if high I/O activity or scheduled tasks coincide with the resource spike.
-
Review and apply exclusions
- Review current Datto AV exclusions for the server.
- Add targeted exclusions for trusted, high-churn directories and critical business applications as needed. Avoid broad exclusions that could reduce security.
- Refer to Working with exclusions in your Datto AV policy for official exclusion configuration guidance.
- Use Best practices for creating Datto AV policies to guide exclusion tuning.
-
Check scan schedules and update timing
- Confirm whether the resource spike aligns with scheduled scans or signature updates.
- Adjust scan schedules to avoid overlap with peak workload periods if necessary.
-
Compare with general hardware requirements
- Datto AV requires a minimum of 4 GB RAM and a quad-core CPU for server environments.
- If Datto AV consistently uses over 1 GB of memory for extended periods, this may indicate abnormal behavior.
-
Check for third-party security product conflicts
- Ensure no other antivirus or endpoint protection products are running concurrently, as this can cause performance issues.
-
Escalate if unresolved
- If high resource usage persists after applying exclusions and adjusting schedules:
- Gather all available logs with verbose or debug logging enabled.
- Collect diagnostic information, such as Process Monitor (ProcMon) captures and Task Manager screenshots showing the increased usage.
- Document when the increase occurs and any patterns (e.g., during scans, backups, or heavy application use).
- Escalate to Datto Support with the collected data for further analysis.
- If high resource usage persists after applying exclusions and adjusting schedules:
Notes
- Exclusions should be as specific as possible and only applied to trusted paths or processes.
- Avoid broad or blanket exclusions unless officially recommended.
- Use Alert Only mode during initial deployment to identify false positives and performance impacts before enforcing exclusions (Best practices for creating Datto AV policies).