I have a 3448 that is running a high cpu utilization:
System load: 1sec:99.40% 1min:100.00% 5min:99.26% Min: 0.00% Max: 100.00%
Context switch load: 0.68%
Invoked Exec Time Runtime Load %%
Task Id Task Name PRI STA (count) (usec) (usec) (1sec)
1 Idle 0 W 147427119 486 0 0.00
3 PC Config 7 S 63001176 520 74241 7.42
4 PacketRouting 44 W 2755530024 10 441509 44.15
5 Timer 46 W 1175549823 13 16243 1.62
6 Thread Pool 4 R 756721 143 1321 0.13
7 Timer-00 10 W 185727222 2 468 0.05
8 Nm01 5 W 0 535588 0 0.00
9 Clock 9 W 2754307 18 0 0.00
10 FrontPanel 43 W 24652721 115 2236 0.22
11 con0 46 W 253366 11 0 0.00
12 Flash Maintena~ 4 W 123721 426 0 0.00
13 CF Manager 9 W 1536594 5 5 0.00
14 ICP Session 8 W 114217 10 0 0.00
15 RSTP 43 W 12030582 107 1057 0.11
16 RSTP-BG 42 W 28 532 0 0.00
17 MLD Thread 6 W 4 8 0 0.00
18 RouteTableTick 6 W 1135063 90 90 0.01
19 RouteTableTick 6 W 1103853 10 10 0.00
20 IGMPTick 6 W 794737 40 40 0.00
21 IGMP-Receiver 6 W 0 4059757 0 0.00
22 IP Events 27 W 1491115 34 72 0.01
23 tcptimer 25 W 272549 7 97 0.01
24 tcpinp 25 W 721696 111 783 0.08
25 tcpout 25 W 1131114 63 873 0.09
26 DnsClient 19 W 855535 30 0 0.00
27 DnsProxy 19 W 2216031396 80 251189 25.12
28 DnsTable 19 W 223970 28 0 0.00
29 Port Manager 9 W 7715017 47 244 0.02
30 eth01 46 W 1582827099 4 73447 7.34
31 eth02 46 W 19781916 69 7759 0.78
32 SnmpThread 6 W 11339105 9 30 0.00
33 WWW 22 W 1454963 57 0 0.00
34 SEC 46 W 116244 25 0 0.00
35 IKE 6 W 68769 9 0 0.00
36 IPSecKeyGen 4 W 0 324320 0 0.00
37 SCEP 6 W 0 322274 0 0.00
38 MediaConnectio~ 39 W 2437229 2 920 0.09
39 FTPServer List~ 5 W 1 37 0 0.00
40 SMTP Client 19 W 0 72 0 0.00
41 SNTP Client 22 W 13 22 0 0.00
42 Switch Managem~ 43 W 0 75 0 0.00
43 Switch Mainten~ 4 R 11026501 5 49350 4.94
44 Stacking 9 W 973859 52 0 0.00
45 FCC2 46 W 11990717 8 35 0.00
46 CLIInjectQ 6 W 0 59395 0 0.00
49 RipOut 6 W 758577 7 7 0.00
50 RipIn 6 W 51 41 0 0.00
51 poe0 46 W 7658708 12 54 0.01
52 PwrOvrEth 9 W 28021881 4 199 0.02
53 UDP Relay 22 W 1 105 0 0.00
54 DHCP Server 34 W 838 38 0 0.00
55 CFM Maint 44 W 1122159 37 37 0.00
56 AUTOLINKQ 4 W 427584 323 0 0.00
57 HttpClientQ 6 W 2695 84 0 0.00
58 SIP_Stack 38 W 341702 74 128 0.01
59 ntpd 22 W 2385208 86 86 0.01
60 RvSipProc0 39 W 123158 117 0 0.00
62 DHCPv6 34 W 0 433 0 0.00
63 PacketCapture 4 R 1183956 27 53 0.01
64 Flow Meter Log~ 20 W 1496705 38 38 0.00
65 OSPF 6 W 0 154730 0 0.00
66 OSPFv3 6 W 0 45481 0 0.00
67 TWAMP-Control 6 W 0 28707 0 0.00
68 TWAMP-Test 19 W 1 13 0 0.00
69 UDP In 42 W 718556243 75 71356 7.14
Your top CPU hogs are packet routing, DNS proxy and UDP in. Look for a host on the inside acting as part of a botnet involved in a DDoS attack, or configured as a resolver and open to the public.
"show ip policy-sessions" will possibly give a clue. Look for dozens or hundreds of UDP connections that aren't serving a business purpose.
Your top CPU hogs are packet routing, DNS proxy and UDP in. Look for a host on the inside acting as part of a botnet involved in a DDoS attack, or configured as a resolver and open to the public.
"show ip policy-sessions" will possibly give a clue. Look for dozens or hundreds of UDP connections that aren't serving a business purpose.