Skip to main content

Health Topics

The SparkLogs Agent measures the endpoint itself on a schedule and reports each area as one topic. A topic raises a condition while a bad state holds, an occurrence when something happens once, and a change when an inventory differs from its last report.

TopicWhat it reportsReadingsStatus
Agent overheadWhat the SparkLogs agent stack itself costs the host: CPU, working set and handles.3Live
Agent pipelineThe agent spool and delivery pipeline: how much is queued and when it last drained.0Live
Collector healthPer-collector health for the shipper the agent runs.0Live
Crash dump configurationWhether this host can write a usable crash dump when Windows or an application crashes.1Live
CrashesWindows and application crashes with decoded error details and local dump analysis when available.3Live
Disk volumesEvery fixed volume: free space, fill trend, protection state and whether the filesystem is readable.7Live
Device driversThe device drivers installed on the host, and what changes about them between reports.3Live
Feed healthPer-feed health for the inputs the agent is shipping.0Live
Installed productsThe installed-product inventory the agent reads from the host.3Live
Installed product summaryA rolled-up view of installed products, including protection-category coverage.0Live
Host performanceWhole-host CPU and memory posture over a measured window.6Live
ProcessesPer-process cost: CPU, working set, handles and sustained growth.1Live
Windows servicesService configuration and run state, including automatic services that are not running.3Live
Storage device IOPer-device IO posture, including a device that is busy but moving almost nothing.1Live
Storage devicesThe physical and virtual storage devices attached to the host.0Live
Storage IOStorage throughput, queues and response time per volume.2Live
System informationMachine identity and posture, including whether a reboot is pending.5Live
Top processesProcesses selected by CPU, resident memory and read/write I/O, plus system CPU and an unlisted-process remainder.0Live
Volume mapHow volumes map onto devices and partitions.0Live
VSS shadow storageShadow-copy storage allocation and how close it is to its cap.2Live
VSS writersVSS writer state, the canonical evidence behind a failed backup.1Live
Windows Update agent stateWhether this host is scanning, paused, or falling behind on updates.2Live

A planned topic is one the fleet does not send yet. Everything else is arriving from endpoints running a current Agent.