Crash dump configuration
Whether this host can write a usable crash dump when Windows or an application crashes.
Topic id: crash_dump_config.
Full inventory every 8 hours. Supported changes are reported when the agent observes them.
Fields
Whether Windows can write a crash dump, and the dump files it wrote recently. The crashes themselves are in the crashes topic.
| Field | Type | Unit | Meaning |
|---|---|---|---|
sparklogs.data.crash_dump_config.dump_type | string | What this host is configured to write on a bugcheck: none, mini, kernel, full or automatic. Absent when the setting could not be read, which is not the same answer as none. | |
sparklogs.data.crash_dump_config.pagefile_sizing | string | How the page file is sized: off, system_managed, fixed, or unknown. One system-managed line among fixed lines makes the whole set unknown. | |
sparklogs.data.crash_dump_config.pagefile_max_bytes | integer | bytes | The page file's configured maximum size, which is the room a dump has to be written into when no dedicated dump file is set. Present for off (zero) and fixed; absent for system_managed and unknown. |
sparklogs.data.crash_dump_config.pagefile_required_bytes | integer | bytes | The dump-backing room the configured dump type needs. Absent for none, mini, system_managed, unknown, a Windows-chosen dedicated dump file, or a complete dump when physical RAM could not be read. |
sparklogs.data.crash_dump_config.pagefile_shortfall_pct | float | percent | Page-file shortfall as a percentage of the required size. Zero when no backing space is required. Absent when the dump type or size limit could not be read. |
sparklogs.data.crash_dump_config.minidump_count_7d | integer | count | Minidump files written in the last seven days. |
sparklogs.data.crash_dump_config.minidump_count_30d | integer | count | Minidump files written in the last thirty days. |
sparklogs.data.crash_dump_config.newest_minidump_age_min | float | minutes | How long since the newest minidump file was written. |
sparklogs.data.crash_dump_config.os_dump_pagefile_too_small_basis | string | onset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time. |
Conditions
A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.
| Condition | Severity | How an episode ends |
|---|---|---|
page file too small for the dump (os_dump_pagefile_too_small) | Notice | It closes when the measurement falls back past its recovery point. |
Example
Inventory (every 8 hours)
dump posture; type automatic, page file 16.0 GB for 0.2 GB required, dumps in 30d 0.
sparklogs.data.crash_dump_config.dump_type: automatic
sparklogs.data.crash_dump_config.pagefile_max_bytes: 17179869184
sparklogs.data.crash_dump_config.pagefile_sizing: fixed
sparklogs.data.crash_dump_config.pagefile_shortfall_pct: -6300.0
SparkLogs: CONTEXT, Info, crash_dump_config: INVENTORY: dump posture; type automatic, page file 16.0 GB for 0.2 GB required, dumps in 30d 0.
Selected conditions
os_dump_pagefile_too_small
The page file is too small for the configured crash dump.
Also reported by: Crash dump configuration
Impact: A future bugcheck may fail to write the expected dump.
Example
started; page file shortfall 50% (threshold 10%)
sparklogs.data.crash_dump_config.pagefile_shortfall_pct: 50.0
SparkLogs: os_dump_pagefile_too_small, Notice, crash_dump_config: os_dump_pagefile_too_small: NOTABLE: started; page file shortfall 50% (threshold 10%)
Example
cleared after 0h15m, peaked Notice, relapses 1; page file 16.0 GB, dump needs 0.2 GB (allowed shortfall 10%)
sparklogs.data.crash_dump_config.pagefile_shortfall_pct: -6300.0
SparkLogs: os_dump_pagefile_too_small, Info, crash_dump_config: os_dump_pagefile_too_small: RECOVERED: cleared after 0h15m, peaked Notice, relapses 1; page file 16.0 GB, dump needs 0.2 GB (allowed shortfall 10%)
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | os_stability |
held | Trace to Fatal | os_stability |
recovered | Trace to Fatal | os_stability |