Skip to main content

Crashes

3readings
1conditions
1themes fed
Livestatus

Windows and application crashes with decoded error details and local dump analysis when available.

Topic id: crashes.

Full inventory every 8 hours. Supported changes are reported when the agent observes them.

Fields​

One occurrence per crash, from the Windows event records that report it, with decoded codes and local dump analysis when a dump was available. The host row counts recent kernel crashes.

FieldTypeUnitMeaning
sparklogs.data.crashes.kernel_crash_count_1dintegercountKernel crashes in the last day, counted from the crash history: distinct crashes, not dump files.
sparklogs.data.crashes.kernel_crash_count_5dintegercountKernel crashes in the last five days.
sparklogs.data.crashes.kernel_crash_count_10dintegercountKernel crashes in the last ten days.
sparklogs.data.crashes.kernel_crash_days_since_lastfloatdaysHow long since the most recent kernel crash. Absent when the thirty-day history holds none.
sparklogs.data.crashes.kernel_crash_coverage_daysfloatdaysHow long the System log has been read without a gap (no record lost to a clear or a roll-over). Absent until it has been read once.
sparklogs.data.crashes.crash_idstringThe crash's stable identity, the same on every report of it. Opaque. Occurrence only.
sparklogs.data.crashes.time_basisstringWhere the event time comes from: dump_header (the analyzed kernel dump's own clock), report_event (the crash record), or estimated_bounds (no crash time; time_upper_ts is used). Occurrence only.
sparklogs.data.crashes.time_lower_tsstringtimestampFor estimated_bounds: the newest System record before the boot that followed the crash, when that read answered and is newer (the machine was running then); otherwise the latest crash evidence before that boot. An investigation bound, not the crash time. Occurrence only.
sparklogs.data.crashes.time_upper_tsstringtimestampThe earliest evidence known to follow the crash, for estimated_bounds. Occurrence only.
sparklogs.data.crashes.detected_tsstringtimestampWhen the agent first found the crash; not the crash time. Occurrence only.
sparklogs.data.crashes.wer_report_idsstring_arrayThe Windows Error Reporting report ids the crash's records carry, lowercase: a report GUID, or on Windows Server 2012 R2 the small dump's base name the System report uses as its id. Occurrence only.
sparklogs.data.crashes.evidenceobject_arrayThe event records the crash was built from, oldest first, at most 16: channel, provider, event_id, record_id (absent when unread) and event_ts. Occurrence only.
sparklogs.data.crashes.evidence_totalintegercountHow many records the crash was built from, including any past the list. Occurrence only.
sparklogs.data.crashes.analysisstringWhat the dump analysis did: complete, partial_timeout, partial_error, resource_limited, dump_unavailable, unsupported_format or budget_skipped. complete means the supported analysis finished, not that the cause is known. Occurrence only.
sparklogs.data.crashes.budget_reasonstringWhy the dump was not analyzed: with budget_skipped, per_key (three of this kind in a day), overall (64 in a day) or queue_full; with resource_limited, commit_pressure (the system's commit stayed too high to start the analysis). Occurrence only.
sparklogs.data.crashes.analysis_elapsed_msintegermillisecondsHow long the analysis ran. Absent when none ran. Occurrence only.
sparklogs.data.crashes.matching_dump_countintegercountHow many dump files matched the crash. Occurrence only.
sparklogs.data.crashes.dump_pathstringThe analyzed dump. Absent without one. Occurrence only.
sparklogs.data.crashes.dump_namestringThe analyzed dump's file name. Occurrence only.
sparklogs.data.crashes.dump_size_bytesintegerbytesThe analyzed dump's size. Occurrence only.
sparklogs.data.crashes.dump_formatstringThe analyzed dump's format: kernel_triage, kernel_full, kernel_bitmap or user_minidump. Occurrence only.
sparklogs.data.crashes.dump_type_rawstringThe dump header's raw type: the kernel DumpType, or the user dump's MINIDUMP_TYPE flags, as hex. Occurrence only.
sparklogs.data.crashes.dump_truncatedboolThe dump file is shorter than its header declares, so what was read from it is partial. Occurrence only.
sparklogs.data.crashes.architecturestringThe crashed system's or process's architecture: x64, x86, arm64 or other. Occurrence only.
sparklogs.data.crashes.os_buildintegerThe Windows build the dump was written on. Occurrence only.
sparklogs.data.crashes.context_ipstringThe crashing context's instruction pointer (rip or eip), as hex. Occurrence only.
sparklogs.data.crashes.context_spstringThe crashing context's stack pointer (rsp or esp), as hex. Occurrence only.
sparklogs.data.crashes.context_fpstringThe crashing context's frame pointer (rbp or ebp), as hex. Occurrence only.
sparklogs.data.crashes.modulesobject_arrayLoaded modules from the analyzed dump, at most 512; frames refer to them by position. Each has basename, and where read machine (hex), size_of_image, time_date_stamp (8 hex digits), identity_source, codeview_kind (rsds or nb10), pdb_name, pdb_guid (32 hex digits), pdb_signature (8 hex digits), pdb_age, debug_source, portable_pdb, pdb_checksum_algorithm, pdb_checksum, debug_directory_source, file_version and version_source. Sources are module_stream, triage_entry, dump_image or local_image. Occurrence only.
sparklogs.data.crashes.modules_totalintegercountHow many modules the dump lists, including any past the list. Occurrence only.
sparklogs.data.crashes.modules_truncatedboolModules were left out of the list. Occurrence only.
sparklogs.data.crashes.modules_walkstringHow the module list walk ended: complete, unavailable, cycle or iteration_cap. Occurrence only.
sparklogs.data.crashes.unloaded_modulesobject_arrayRecently unloaded modules from the analyzed dump, at most 128: basename, name_possibly_truncated, and where read size_of_image, time_date_stamp (8 hex digits) and unload_ts. Occurrence only.
sparklogs.data.crashes.unloaded_totalintegercountHow many unloaded modules the dump lists. Occurrence only.
sparklogs.data.crashes.unloaded_truncatedboolUnloaded modules were left out of the list. Occurrence only.
sparklogs.data.crashes.unloaded_walkstringHow the unloaded list walk ended: complete, unavailable, cycle or iteration_cap. Occurrence only.
sparklogs.data.crashes.unloaded_orderstringThe unloaded list's order: most_recent_first, or as_recorded when recency is not known. Occurrence only.
sparklogs.data.crashes.framesobject_arrayThe crashing thread's stack, at most 64 frames: module (position in modules) and offset (hex, module-relative), or unmapped for an address outside every module; address (instruction for frame 0, return_address after), method (context, unwind_table, leaf_assumed or frame_pointer), unwind_source (dump or local_image), and nearest_export with nearest_export_displacement (hex), which is the nearest export, never a resolved symbol. Occurrence only.
sparklogs.data.crashes.frames_truncatedboolThe stack went on past the frame cap. Occurrence only.
sparklogs.data.crashes.stack_stopstringWhy the stack walk stopped: end_of_stack, unmapped, no_image, image_unavailable, unwind_failed, stack_unavailable, frame_cap, unsupported_architecture or no_context. Occurrence only.
sparklogs.data.crashes.identity_basisstringWhat names a kernel crash: boot_start (the boot it was reported in), report_id or power_41. Kernel crash only.
sparklogs.data.crashes.boot_start_missingboolNo boot-start record placed the boot the kernel crash was reported in. Kernel crash only.
sparklogs.data.crashes.bugcheck_codestringThe bugcheck code, 0x and 8 hex digits. Absent only when no record or dump carried one. Kernel crash only.
sparklogs.data.crashes.bugcheck_namestringThe bugcheck's symbolic name, from the pack's bugcheck table. Absent when the table has no row for the code. Kernel crash only.
sparklogs.data.crashes.bugcheck_param1stringThe bugcheck's first parameter, as hex. Kernel crash only.
sparklogs.data.crashes.bugcheck_param2stringThe bugcheck's second parameter, as hex. Kernel crash only.
sparklogs.data.crashes.bugcheck_param3stringThe bugcheck's third parameter, as hex. Kernel crash only.
sparklogs.data.crashes.bugcheck_param4stringThe bugcheck's fourth parameter, as hex. Kernel crash only.
sparklogs.data.crashes.sleep_in_progressintegerKernel-Power 41's raw SleepInProgress value. Kernel crash only.
sparklogs.data.crashes.modern_standbyboolKernel-Power 41 says connected standby was in progress. Kernel crash only.
sparklogs.data.crashes.app_namestringThe crashed process's executable name. Process crash only.
sparklogs.data.crashes.app_versionstringThe executable's file version. Process crash only.
sparklogs.data.crashes.app_timestampstringThe executable's PE TimeDateStamp, 8 hex digits: a symbol-store key, not a date. Process crash only.
sparklogs.data.crashes.app_pathstringThe executable's path. Process crash only.
sparklogs.data.crashes.pidintegerThe crashed process's id. Process crash only.
sparklogs.data.crashes.process_start_tsstringtimestampWhen the crashed process started. Process crash only.
sparklogs.data.crashes.exception_codestringThe exception code, 0x and 8 hex digits. Process crash only.
sparklogs.data.crashes.exception_namestringThe exception code's NTSTATUS name, from the pack's status-code table. Absent when the table has no row for the code. Process crash only.
sparklogs.data.crashes.exception_addressstringThe faulting address the dump's exception record carries, as hex. Process crash only.
sparklogs.data.crashes.exception_thread_idintegerThe faulting thread's id, from the dump. Process crash only.
sparklogs.data.crashes.fault_modulestringThe module the crash record reports the fault in. Reported, not a cause. Process crash only.
sparklogs.data.crashes.fault_module_versionstringThe fault module's file version. Process crash only.
sparklogs.data.crashes.fault_module_timestampstringThe fault module's PE TimeDateStamp, 8 hex digits. Process crash only.
sparklogs.data.crashes.fault_module_pathstringThe fault module's path. Process crash only.
sparklogs.data.crashes.fault_offsetstringThe fault's offset in the fault module, as hex. Process crash only.
sparklogs.data.crashes.fault_module_indexintegerThe fault module's position in modules. Process crash only.
sparklogs.data.crashes.process_image_indexintegerThe executable's position in modules. Process crash only.
sparklogs.data.crashes.managed_exception_typestringThe .NET exception type the runtime reported for the crash. Process crash only.
sparklogs.data.crashes.managed_exception_messagestringThe .NET exception message the runtime reported, at most 512 bytes. Untrusted text; credential shapes are swept at ingest. Process crash only.
sparklogs.data.crashes.clr_versionstringThe .NET runtime version that reported the exception. Process crash only.
sparklogs.data.crashes.managed_framesstring_arrayThe .NET stack the runtime reported, at most 64 lines of 512 characters. Untrusted text, joined to the native stack by position only. Process crash only.
sparklogs.data.crashes.managed_frames_truncatedboolThe .NET stack went on past the list. Process crash only.
sparklogs.data.crashes.stitch_statusstringWhether the .NET stack continues the native one: stitched, or why not (no_managed_frames, not_single_exception, no_native_stack, no_junction). A stitch is by position, never an unwind. Process crash only.
sparklogs.data.crashes.scan_candidatesobject_arrayx86 only: stack values just past a call instruction in a module's code, at most 256, for a symbolizer to validate; never frames. Each has module, offset (hex) and stack_offset (bytes above the stack pointer). Process crash only.
sparklogs.data.crashes.scan_window_bytesintegerbytesStack bytes searched for scan candidates. Process crash only.
sparklogs.data.crashes.scan_candidates_truncatedboolScan candidates were left out of the list. Process crash only.

Conditions​

A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.

ConditionSeverityHow an episode ends
recurring kernel crashes (kernel_crash_recurring)Minor to CriticalIt closes on a recovery rule written for this condition, which reads more than one measurement together.

Occurrences​

An occurrence is a thing that happened and was discovered, rather than a state that holds. It is announced once and has no closing event.

OccurrenceWhat it means
kernel_crashkernel crash
process_crashprocess crash

Example​

Inventory (every 8 hours)

crash history; kernel crashes in 10d 0.

sparklogs.data.crashes.kernel_crash_count_1d: 0
sparklogs.data.crashes.kernel_crash_count_5d: 0
sparklogs.data.crashes.kernel_crash_count_10d: 0

SparkLogs: CONTEXT, Info, crashes: INVENTORY: crash history; kernel crashes in 10d 0.

Selected conditions​

kernel_crash_recurring​

The host is crashing with bug checks (blue screens) repeatedly.

Also reported by: Crashes

Impact: Repeated kernel crashes interrupt every user and service on the host. Compare the bug check codes of the individual crashes to see whether one cause repeats.

Example

started; kernel crashes 5d 5 (threshold 5)

sparklogs.data.crashes.kernel_crash_count_1d: 2
sparklogs.data.crashes.kernel_crash_count_5d: 5
sparklogs.data.crashes.kernel_crash_count_10d: 5

SparkLogs: kernel_crash_recurring, Severe, crashes: kernel_crash_recurring: NOTABLE: started; kernel crashes 5d 5 (threshold 5)

Example

cleared after 479h52m, peaked Minor, relapses 1; last kernel crash 679h55m ago (clears at 480h00m)

sparklogs.data.crashes.kernel_crash_count_1d: 0
sparklogs.data.crashes.kernel_crash_count_5d: 0
sparklogs.data.crashes.kernel_crash_count_10d: 0

SparkLogs: kernel_crash_recurring, Info, crashes: kernel_crash_recurring: RECOVERED: cleared after 479h52m, peaked Minor, relapses 1; last kernel crash 679h55m ago (clears at 480h00m)

Example

subsiding, not yet cleared; kernel crashes 10d 1 (below 2), last 237h07m ago, covered 0h57m (clears at 480h00m), open for 1h00m

sparklogs.data.crashes.kernel_crash_count_1d: 0
sparklogs.data.crashes.kernel_crash_count_5d: 0
sparklogs.data.crashes.kernel_crash_count_10d: 1

SparkLogs: kernel_crash_recurring, Notice, crashes: kernel_crash_recurring: ELEVATED: subsiding, not yet cleared; kernel crashes 10d 1 (below 2), last 237h07m ago, covered 0h57m (clears at 480h00m), open for 1h00m

Example

relapsed; kernel crashes 10d 2 (threshold 2), open for 1h30m, relapses 1

sparklogs.data.crashes.kernel_crash_count_1d: 1
sparklogs.data.crashes.kernel_crash_count_5d: 1
sparklogs.data.crashes.kernel_crash_count_10d: 2

SparkLogs: kernel_crash_recurring, Minor, crashes: kernel_crash_recurring: ELEVATED: relapsed; kernel crashes 10d 2 (threshold 2), open for 1h30m, relapses 1

CaseSeverityTicket class
onsetTrace to Fatalos_stability
heldTrace to Fatalos_stability
recoveredTrace to Fatalos_stability

kernel_crash​

Windows stopped with a bug check (blue screen).

Also reported by: Crashes

Impact: The host restarted unexpectedly, interrupting every user and service on it. The bug check code, its parameters and any analyzed dump are where the investigation starts.

Example

kernel crash 0x0000009F DRIVER_POWER_STATE_FAILURE | analysis=budget_skipped budget=per_key param1=0x3 param2=0xFFFFE0012A4B8060 param3=0xFFFFD000217A6960 param4=0xFFFFE0012C1E4010 time=estimated

SparkLogs: kernel_crash, Error, crashes: kernel_crash: NOTABLE: kernel crash 0x0000009F DRIVER_POWER_STATE_FAILURE | analysis=budget_skipped budget=per_key param1=0x3 param2=0xFFFFE0012A4B8060 param3=0xFFFFD000217A6960 param4=0xFFFFE0012C1E4010 time=estimated

Example

kernel crash 0x0000018B SECURE_KERNEL_ERROR | analysis=complete modern_standby=true param1=0x1 param2=0x0 param3=0x0 param4=0x0

SparkLogs: kernel_crash, Error, crashes: kernel_crash: NOTABLE: kernel crash 0x0000018B SECURE_KERNEL_ERROR | analysis=complete modern_standby=true param1=0x1 param2=0x0 param3=0x0 param4=0x0

process_crash​

An application process crashed.

Also reported by: Crashes

Impact: The process stopped on an unhandled exception, and users or services depending on it may have lost work or availability. The exception code, the faulting module and any analyzed dump narrow the cause.

Example

process crash in "Contoso.Worker.exe" | exception=0xE0434352 managed_exception="System.NullReferenceException" fault_module="KERNELBASE.dll" fault_module_version=10.0.20348.2849 fault_offset=0x3E2D2 app_version=3.1.0.0 analysis=complete managed_exception_message="Object reference not set to an instance of an object."

SparkLogs: process_crash, Warning, crashes: process_crash: NOTABLE: process crash in "Contoso.Worker.exe" | exception=0xE0434352 managed_exception="System.NullReferenceException" fault_module="KERNELBASE.dll" fault_module_version=10.0.20348.2849 fault_offset=0x3E2D2 app_version=3.1.0.0 analysis=complete managed_exception_message="Object reference not set to an instance of an object."

Example

process crash in "sqlservr.exe" | exception=0xC0000409 exception_name=STATUS_STACK_BUFFER_OVERRUN fault_module="ucrtbase.dll" fault_offset=0x7F4DE app_version=2022.160.4135.4 analysis=dump_unavailable

SparkLogs: process_crash, Warning, crashes: process_crash: NOTABLE: process crash in "sqlservr.exe" | exception=0xC0000409 exception_name=STATUS_STACK_BUFFER_OVERRUN fault_module="ucrtbase.dll" fault_offset=0x7F4DE app_version=2022.160.4135.4 analysis=dump_unavailable

Example

process crash in "example-app.exe" | exception=0xC0000005 exception_name=STATUS_ACCESS_VIOLATION fault_module="example.dll" fault_module_version=2.4.1.0 fault_offset=0x1234 app_version=5.0.2.17 analysis=complete

SparkLogs: process_crash, Warning, crashes: process_crash: NOTABLE: process crash in "example-app.exe" | exception=0xC0000005 exception_name=STATUS_ACCESS_VIOLATION fault_module="example.dll" fault_module_version=2.4.1.0 fault_offset=0x1234 app_version=5.0.2.17 analysis=complete

Example

process crash in "legacy-tool.exe" | exception=0xC0000005 exception_name=STATUS_ACCESS_VIOLATION fault_module="legacy.dll" fault_module_version=1.8.0.0 fault_offset=0x4A0C app_version=1.8.0.0 analysis=complete

SparkLogs: process_crash, Warning, crashes: process_crash: NOTABLE: process crash in "legacy-tool.exe" | exception=0xC0000005 exception_name=STATUS_ACCESS_VIOLATION fault_module="legacy.dll" fault_module_version=1.8.0.0 fault_offset=0x4A0C app_version=1.8.0.0 analysis=complete