Device Health Conditions
A condition is a named state the agent scores on a schedule. An episode opens when the state turns bad, escalates or recovers while it holds, and closes when the host comes back out, so one item covers the whole stretch. An occurrence is recorded once, with no episode and no close.
Conditions
A condition opens as an episode, escalates or recovers while it holds, and closes when the host comes back out.
| Condition | Topic | What it means | What closes it | Severity |
|---|---|---|---|---|
cpu_busy | Host performance | cpu busy | It closes when the measurement falls back past its recovery point. | Display to Notice |
cpu_interrupt_storm | Host performance | cpu interrupt storm | It closes when the measurement falls back past its recovery point. | Warning to Error |
cpu_kernel_dominated | Host performance | cpu kernel dominated | It closes when any one of the several recovery conditions is met. | Notice |
cpu_throttled_under_load | Host performance | cpu throttled under load | It closes on a recovery rule written for this condition, which reads more than one measurement together. | Warning to Error |
data_volume_space_exhausting | Disk volumes | data volume running out of space | It closes on a recovery rule written for this condition, which reads more than one measurement together. | Warning to Error |
data_volume_space_low | Disk volumes | data volume space low | It closes when any one of the several recovery conditions is met. | Display |
disk_latency_degraded | Storage IO | disk latency degraded | It closes on a recovery rule written for this condition, which reads more than one measurement together. | Warning to Error |
disk_saturated | Storage IO | disk saturated | It closes when the measurement falls back past its recovery point. | Notice |
disk_unresponsive | Storage device IO | disk unresponsive | It closes when any one of the several recovery conditions is met. | Minor to Critical |
os_bsod_recurring | Crash dump configuration | recurring crash dumps | It closes on a recovery rule written for this condition, which reads more than one measurement together. | Minor to Critical |
os_dump_pagefile_too_small | Crash dump configuration | page file too small for the dump | It closes when the measurement falls back past its recovery point. | Notice |
os_volume_space_exhausting | Disk volumes | OS volume running out of space | It closes on a recovery rule written for this condition, which reads more than one measurement together. | Warning to Critical |
os_volume_space_low | Disk volumes | OS volume space low | It closes when any one of the several recovery conditions is met. | Notice to Serious |
patch_scan_stale | Windows Update agent state | update scan is stale | It closes when the measurement falls back past its recovery point. | Warning |
patch_updates_paused | Windows Update agent state | updates paused | It closes when any one of the several recovery conditions is met. | Notice to Error |
process_handle_count_high | Processes | process handle count high | It closes when the measurement falls back past its recovery point. | Display |
ram_commit_near_cap | Host performance | committed memory near its limit | It closes when the measurement falls back past its recovery point. | Display to Critical |
ram_hard_fault_storm | Host performance | hard fault storm | It closes when any one of the several recovery conditions is met. | Serious |
service_auto_not_running | Windows services | automatic service not running | It closes on a recovery rule written for this condition, which reads more than one measurement together. | Notice to Severe |
service_flapping | Windows services | service flapping | It closes when the measurement falls back past its recovery point. | Notice to Error |
service_stuck_pending | Windows services | service stuck pending | It closes on a recovery rule written for this condition, which reads more than one measurement together. | Warning to Error |
sparklogs_agent_cpu_over_budget | Agent overhead | sparklogs agent cpu over budget | It closes when the measurement falls back past its recovery point. | Notice |
sparklogs_agent_handle_over_budget | Agent overhead | sparklogs agent handle over budget | It closes when the measurement falls back past its recovery point. | Notice |
sparklogs_agent_memory_over_budget | Agent overhead | sparklogs agent memory over budget | It closes when the measurement falls back past its recovery point. | Notice |
volume_bitlocker_dropped | Disk volumes | BitLocker protection dropped | It closes when the state it watches is no longer set. | Notice |
volume_fill_rate_high | Disk volumes | volume filling fast | It closes on a recovery rule written for this condition, which reads more than one measurement together. | Display |
volume_unreadable | Disk volumes | volume unreadable | It closes when the host reports one of the healthy states again. | Serious to Severe |
vss_shadowstorage_near_cap | VSS shadow storage | shadow storage near cap | It closes when the measurement falls back past its recovery point. | Notice |
vss_snapshots_failing_for_space | VSS shadow storage | shadow copies failing for space | It closes when the measurement falls back past its recovery point. | Notice to Error |
vss_writer_failed | VSS writers | VSS writer failed | It closes when any one of the several recovery conditions is met. | Notice to Error |
Occurrences
An occurrence is recorded once, with no episode and no close.
| Occurrence | Topic | What it means | Severity |
|---|---|---|---|
os_crash_dump_created | Crash dump configuration | new crash dump | Not scored |