Skip to main content

Top processes

0readings
0conditions
0themes fed
Plannedstatus

The busiest processes by CPU, plus a remainder row for the rest.

Topic id: top_processes.

Emitted every 5 minutes on clock boundaries; each row covers the window ending at t; a partly watched window carries sparklogs.window_coverage_pct below 100; chart with buckets at least 5 minutes wide.

This topic is still rolling out. Endpoints on the general release do not send it yet.

Fields​

These fields rank the processes worth naming individually and fold everything else into one remainder row.

FieldTypeUnitMeaning
sparklogs.data.top_processes.pidintegerThe process id; with create_time_raw it is this row's identity, the same one the processes topic uses. 0 on the system and remainder rows.
sparklogs.data.top_processes.create_time_rawintegerThe process's creation time as the raw Windows FILETIME value. On the rows that are not a process it is a fixed instant in the first seconds of the Unix epoch, which no real process carries: the epoch itself for (other processes), one second after for (hardware interrupts), two for (deferred procedure calls).
sparklogs.data.top_processes.image_namestringThe process's executable file name; (hardware interrupts) or (deferred procedure calls) on a system row, (other processes) on the remainder row.
sparklogs.data.top_processes.servicesstring_arrayThe services this process hosts, sorted. Absent when it hosts none.
sparklogs.data.top_processes.entry_kindstringWhat the row is. process: one process the rankings named. system: CPU the kernel spent outside any process, one row for hardware interrupt service routines and one for deferred procedure calls; CPU fields only. remainder: (other processes), whose CPU is machine busy time minus every other row (the unlisted processes, and whatever a process that exited inside the window spent after its last enumeration), so the CPU of all rows adds up to the machine's busy time; its IO is the sum of the unlisted processes' own counters.
sparklogs.data.top_processes.top_bystring_arrayWhich rankings named this process: cpu, ram, io_read, io_write. Empty on the system and remainder rows.
sparklogs.data.top_processes.cpu_busy_pct_avgfloatpercentCPU this process used over the five-minute window that ends at the event's time, as a percent of the whole machine (every logical core). The idle process is never counted.
sparklogs.data.top_processes.cpu_busy_pct_max_1mfloatpercentThe highest one-minute CPU sample in that window, as a percent of the whole machine.
sparklogs.data.top_processes.working_set_bytesintegerbytesThe process's working set at the end of the window. Absent for a process that exited inside it.
sparklogs.data.top_processes.working_set_pct_ramfloatpercentThat working set as a percentage of installed RAM.
sparklogs.data.top_processes.read_bytes_5mintegerbytesBytes the process read in the window that ends at the event's time, as measured (never scaled up for a partly watched window). Counts every read IO it issued (files, pipes, devices, network), not disk alone.
sparklogs.data.top_processes.write_bytes_5mintegerbytesBytes the process wrote in the window that ends at the event's time, as measured (never scaled up for a partly watched window). Counts every write IO it issued (files, pipes, devices, network), not disk alone.
sparklogs.data.top_processes.read_mb_per_s_avgfloatmegabytes_per_secondAverage read rate over the watched part of the window, in 1024-based MB per second. Every read IO the process issued, not disk alone.
sparklogs.data.top_processes.write_mb_per_s_avgfloatmegabytes_per_secondAverage write rate over the watched part of the window, in 1024-based MB per second. Every write IO the process issued, not disk alone.

This topic reports what the host looks like rather than scoring a condition on it. The values it carries are queryable on their own.

Example​

Inventory (every 5 minutes)

cpu 3.2% busy; top ram "sqlservr.exe" 6.0 GB; top cpu "sqlservr.exe" 2.2%; top io "services.exe" 0.0 MB/s.

sparklogs.data.top_processes.pid: 4180
sparklogs.data.top_processes.create_time_raw: 134284101000000000

SparkLogs: CONTEXT, Info, top_processes: INVENTORY: cpu 3.2% busy; top ram "sqlservr.exe" 6.0 GB; top cpu "sqlservr.exe" 2.2%; top io "services.exe" 0.0 MB/s.