Skip to main content

Crash dump configuration

1readings
1conditions
1themes fed
Livestatus

Whether this host can write a usable crash dump when Windows or an application crashes.

Topic id: crash_dump_config.

Full inventory every 8 hours. Supported changes are reported when the agent observes them.

Fields​

Whether Windows can write a crash dump, and the dump files it wrote recently. The crashes themselves are in the crashes topic.

FieldTypeUnitMeaning
sparklogs.data.crash_dump_config.dump_typestringWhat this host is configured to write on a bugcheck: none, mini, kernel, full or automatic. Absent when the setting could not be read, which is not the same answer as none.
sparklogs.data.crash_dump_config.pagefile_sizingstringHow the page file is sized: off, system_managed, fixed, or unknown. One system-managed line among fixed lines makes the whole set unknown.
sparklogs.data.crash_dump_config.pagefile_max_bytesintegerbytesThe page file's configured maximum size, which is the room a dump has to be written into when no dedicated dump file is set. Present for off (zero) and fixed; absent for system_managed and unknown.
sparklogs.data.crash_dump_config.pagefile_required_bytesintegerbytesThe dump-backing room the configured dump type needs. Absent for none, mini, system_managed, unknown, a Windows-chosen dedicated dump file, or a complete dump when physical RAM could not be read.
sparklogs.data.crash_dump_config.pagefile_shortfall_pctfloatpercentPage-file shortfall as a percentage of the required size. Zero when no backing space is required. Absent when the dump type or size limit could not be read.
sparklogs.data.crash_dump_config.minidump_count_7dintegercountMinidump files written in the last seven days.
sparklogs.data.crash_dump_config.minidump_count_30dintegercountMinidump files written in the last thirty days.
sparklogs.data.crash_dump_config.newest_minidump_age_minfloatminutesHow long since the newest minidump file was written.
sparklogs.data.crash_dump_config.os_dump_pagefile_too_small_basisstringonset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time.

Conditions​

A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.

ConditionSeverityHow an episode ends
page file too small for the dump (os_dump_pagefile_too_small)NoticeIt closes when the measurement falls back past its recovery point.

Example​

Inventory (every 8 hours)

dump posture; type automatic, page file 16.0 GB for 0.2 GB required, dumps in 30d 0.

sparklogs.data.crash_dump_config.dump_type: automatic
sparklogs.data.crash_dump_config.pagefile_max_bytes: 17179869184
sparklogs.data.crash_dump_config.pagefile_sizing: fixed
sparklogs.data.crash_dump_config.pagefile_shortfall_pct: -6300.0

SparkLogs: CONTEXT, Info, crash_dump_config: INVENTORY: dump posture; type automatic, page file 16.0 GB for 0.2 GB required, dumps in 30d 0.

Selected conditions​

os_dump_pagefile_too_small​

The page file is too small for the configured crash dump.

Also reported by: Crash dump configuration

Impact: A future bugcheck may fail to write the expected dump.

Example

started; page file shortfall 50% (threshold 10%)

sparklogs.data.crash_dump_config.pagefile_shortfall_pct: 50.0

SparkLogs: os_dump_pagefile_too_small, Notice, crash_dump_config: os_dump_pagefile_too_small: NOTABLE: started; page file shortfall 50% (threshold 10%)

Example

cleared after 0h15m, peaked Notice, relapses 1; page file 16.0 GB, dump needs 0.2 GB (allowed shortfall 10%)

sparklogs.data.crash_dump_config.pagefile_shortfall_pct: -6300.0

SparkLogs: os_dump_pagefile_too_small, Info, crash_dump_config: os_dump_pagefile_too_small: RECOVERED: cleared after 0h15m, peaked Notice, relapses 1; page file 16.0 GB, dump needs 0.2 GB (allowed shortfall 10%)

CaseSeverityTicket class
onsetTrace to Fatalos_stability
heldTrace to Fatalos_stability
recoveredTrace to Fatalos_stability