Skip to main content

Device Health Conditions

A condition is a named state the agent scores on a schedule. An episode opens when the state turns bad, escalates or recovers while it holds, and closes when the host comes back out, so one item covers the whole stretch. An occurrence is recorded once, with no episode and no close.

Conditions​

A condition opens as an episode, escalates or recovers while it holds, and closes when the host comes back out.

ConditionTopicWhat it meansWhat closes itSeverity
cpu_busyHost performancecpu busyIt closes when the measurement falls back past its recovery point.Display to Notice
cpu_interrupt_stormHost performancecpu interrupt stormIt closes when the measurement falls back past its recovery point.Warning to Error
cpu_kernel_dominatedHost performancecpu kernel dominatedIt closes when any one of the several recovery conditions is met.Notice
cpu_throttled_under_loadHost performancecpu throttled under loadIt closes on a recovery rule written for this condition, which reads more than one measurement together.Warning to Error
data_volume_space_exhaustingDisk volumesdata volume running out of spaceIt closes on a recovery rule written for this condition, which reads more than one measurement together.Warning to Error
data_volume_space_lowDisk volumesdata volume space lowIt closes when any one of the several recovery conditions is met.Display
disk_latency_degradedStorage IOdisk latency degradedIt closes on a recovery rule written for this condition, which reads more than one measurement together.Warning to Error
disk_saturatedStorage IOdisk saturatedIt closes when the measurement falls back past its recovery point.Notice
disk_unresponsiveStorage device IOdisk unresponsiveIt closes when any one of the several recovery conditions is met.Minor to Critical
os_bsod_recurringCrash dump configurationrecurring crash dumpsIt closes on a recovery rule written for this condition, which reads more than one measurement together.Minor to Critical
os_dump_pagefile_too_smallCrash dump configurationpage file too small for the dumpIt closes when the measurement falls back past its recovery point.Notice
os_volume_space_exhaustingDisk volumesOS volume running out of spaceIt closes on a recovery rule written for this condition, which reads more than one measurement together.Warning to Critical
os_volume_space_lowDisk volumesOS volume space lowIt closes when any one of the several recovery conditions is met.Notice to Serious
patch_scan_staleWindows Update agent stateupdate scan is staleIt closes when the measurement falls back past its recovery point.Warning
patch_updates_pausedWindows Update agent stateupdates pausedIt closes when any one of the several recovery conditions is met.Notice to Error
process_handle_count_highProcessesprocess handle count highIt closes when the measurement falls back past its recovery point.Display
ram_commit_near_capHost performancecommitted memory near its limitIt closes when the measurement falls back past its recovery point.Display to Critical
ram_hard_fault_stormHost performancehard fault stormIt closes when any one of the several recovery conditions is met.Serious
service_auto_not_runningWindows servicesautomatic service not runningIt closes on a recovery rule written for this condition, which reads more than one measurement together.Notice to Severe
service_flappingWindows servicesservice flappingIt closes when the measurement falls back past its recovery point.Notice to Error
service_stuck_pendingWindows servicesservice stuck pendingIt closes on a recovery rule written for this condition, which reads more than one measurement together.Warning to Error
sparklogs_agent_cpu_over_budgetAgent overheadsparklogs agent cpu over budgetIt closes when the measurement falls back past its recovery point.Notice
sparklogs_agent_handle_over_budgetAgent overheadsparklogs agent handle over budgetIt closes when the measurement falls back past its recovery point.Notice
sparklogs_agent_memory_over_budgetAgent overheadsparklogs agent memory over budgetIt closes when the measurement falls back past its recovery point.Notice
volume_bitlocker_droppedDisk volumesBitLocker protection droppedIt closes when the state it watches is no longer set.Notice
volume_fill_rate_highDisk volumesvolume filling fastIt closes on a recovery rule written for this condition, which reads more than one measurement together.Display
volume_unreadableDisk volumesvolume unreadableIt closes when the host reports one of the healthy states again.Serious to Severe
vss_shadowstorage_near_capVSS shadow storageshadow storage near capIt closes when the measurement falls back past its recovery point.Notice
vss_snapshots_failing_for_spaceVSS shadow storageshadow copies failing for spaceIt closes when the measurement falls back past its recovery point.Notice to Error
vss_writer_failedVSS writersVSS writer failedIt closes when any one of the several recovery conditions is met.Notice to Error

Occurrences​

An occurrence is recorded once, with no episode and no close.

OccurrenceTopicWhat it meansSeverity
os_crash_dump_createdCrash dump configurationnew crash dumpNot scored