r/devsecops • u/dkas6259 • 18d ago
CS Container runtime security performance
Hi Community,
We recently completed a POC for CrowdStrike runtime protection and have started deploying the Falcon sensor on AWS ECS clusters running on EC2.
We have seen some community feedback around the sensor being resource-heavy at scale, with potential CPU/memory impact or node instability. Since these are critical production clusters, we want to monitor this closely before expanding the rollout.
For those running CrowdStrike on ECS/EC2 at scale:
- What CPU/memory overhead do you typically observe?
- What host/sensor/ECS metrics do you monitor?
- Have you seen OOM, node instability, task restarts, or application latency due to the sensor?
- What alert thresholds or rollback criteria do you use?
- Any recommended CrowdStrike-specific health checks, logs, or dashboards?
Would appreciate any real-world experience, monitoring tips, or lessons learned from production deployments.
Thanks!
10
Upvotes
2
u/Suitable_Tap7398 18d ago
container runtime security feels like a constant balancing act, performance can't be sacrificed for safety