Disk volumes
Every fixed volume: free space, fill trend, protection state and whether the filesystem is readable.
Topic id: disk_volumes.
Full inventory every 15 minutes. Supported changes are reported when the agent observes them.
Fields
Capacity, growth, protection and filesystem readings for each fixed volume.
| Field | Type | Unit | Meaning |
|---|---|---|---|
sparklogs.data.disk_volumes.volume | string | The volume's stable identity (its GUID), lowercased. Episode continuity keys off this, never the drive letter. | |
sparklogs.data.disk_volumes.display_name | string | The drive letter, when the volume has one; otherwise its primary mount path. | |
sparklogs.data.disk_volumes.volume_label | string | The volume's OS-assigned name. | |
sparklogs.data.disk_volumes.aliases | string_array | Other names this volume is known by, such as its label: excludes its opaque id and its current display_name. | |
sparklogs.data.disk_volumes.drive_type | string | What kind of drive this volume sits on, from GetDriveTypeW. | |
sparklogs.data.disk_volumes.volume_role | string | os: Windows volume. fixed_data: other fixed data volume. removable: removable volume. Absent when unknown, which prevents conditions requiring a known role from firing. | |
sparklogs.data.disk_volumes.volume_role_code | integer | Numeric code for volume_role. | |
sparklogs.data.disk_volumes.free_bytes | integer | bytes | How many bytes are free on the volume. |
sparklogs.data.disk_volumes.free_pct | float | percent | Free space as a percentage of the volume's total. |
sparklogs.data.disk_volumes.used_pct | float | percent | Space used as a percentage of the volume's total (100 minus free_pct), carried on the row because the exhaustion floors are written against the used share. |
sparklogs.data.disk_volumes.writeable | bool | Whether the filesystem reports that writes are allowed. Absent when the filesystem did not answer. | |
sparklogs.data.disk_volumes.mount_state | string | Whether the volume is mounted, unmounted, raw, or unreadable. Absent when the volume's filesystem query did not answer this read. | |
sparklogs.data.disk_volumes.mount_state_code | integer | Numeric code for mount_state. | |
sparklogs.data.disk_volumes.filesystem | string | The volume's filesystem, lowercased. Absent when the volume's filesystem query did not answer this read. | |
sparklogs.data.disk_volumes.bitlocker_protection | string | The volume's BitLocker posture: on, off, suspended, or n_a when BitLocker is not in use on this volume. Absent when the provider could not answer. | |
sparklogs.data.disk_volumes.bitlocker_dropped | bool | Whether BitLocker protection is off or suspended. Absent when protection status could not be read. | |
sparklogs.data.disk_volumes.bitlocker_off_age_min | float | minutes | How long BitLocker protection has been off or suspended. |
sparklogs.data.disk_volumes.fill_rate_bytes_per_h | float | bytes_per_hour | How fast the volume's free space is shrinking: the sustained p25 of five-minute free-space intervals over the last hour, gated on the last ~10 min still filling. Absent until that hour exists. |
sparklogs.data.disk_volumes.fill_slope_sustained_h | float | hours | How long the current fill trend has held. |
sparklogs.data.disk_volumes.projected_full_eta_h | float | hours | The raw projected time until the volume fills, from the fill rate alone. |
sparklogs.data.disk_volumes.exhaustion_eta_h | float | hours | Projected hours until the volume fills. Zero when it has already reached its capacity ceiling, even if the fill rate has stalled. |
sparklogs.data.disk_volumes.backing_bus_permanent | bool | Whether every transport behind this volume is a permanent one (not USB). Absent while the backing transports are unknown. | |
sparklogs.data.disk_volumes.resource | object | What is measured (volume_space), its unit, and where it stands: used and capacity in bytes. | |
sparklogs.data.disk_volumes.projection | object | The forecast derived from resource and a lookback window: the signed change in used bytes over the window, the window's length, and the horizon that decided the reading's severity. | |
sparklogs.data.disk_volumes.departure_notice_eligible | bool | Whether this volume's clean departure would be worth reporting: its role is known, its presence baseline is complete, and its backing bus is permanent, gated by whether departure notices are enabled on this host. | |
sparklogs.data.disk_volumes.seen_count | integer | count | How many of the observations counted toward this volume's presence baseline actually saw it. |
sparklogs.data.disk_volumes.observed_count | integer | count | How many observations have counted toward this volume's presence baseline. |
sparklogs.data.disk_volumes.presence_ratio_pct | float | percent | seen_count over observed_count, as a percentage: the ratio the presence baseline is judged on. |
sparklogs.data.disk_volumes.presence_tracked_d | float | days | How long this volume has been tracked for its presence baseline. |
sparklogs.data.disk_volumes.observed_at | string | timestamp | When this row's reading was taken. |
sparklogs.data.disk_volumes.stale | bool | True when a failed probe left a previous reading in place. Changes between stale and fresh readings produce a delta. | |
sparklogs.data.disk_volumes.volume_space_low_age_basis | string | onset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time. | |
sparklogs.data.disk_volumes.volume_space_low_age_h | float | hours | How long this condition has been open, in hours. |
sparklogs.data.disk_volumes.volume_unreadable_age_basis | string | onset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time. | |
sparklogs.data.disk_volumes.volume_unreadable_age_h | float | hours | How long this condition has been open, in hours. |
Conditions
A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.
Example
Inventory (every 15 minutes)
2 volumes; "C" 96.0 GB free of 256.0 (38%), "D" 900.0 GB free of 2048.0 (44%).
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.bitlocker_protection: on
sparklogs.data.disk_volumes.filesystem: ntfs
sparklogs.data.disk_volumes.mount_state: mounted
sparklogs.data.disk_volumes.stale: false
sparklogs.data.disk_volumes.volume_role: os
sparklogs.data.disk_volumes.volume_role_code: 1
sparklogs.data.disk_volumes.writeable: true
sparklogs.data.disk_volumes.free_pct: 37.5
sparklogs.data.disk_volumes.free_bytes: 103079215104
sparklogs.data.disk_volumes.bitlocker_dropped: false
sparklogs.data.disk_volumes.mount_state_code: 1
SparkLogs: CONTEXT, Info, disk_volumes: INVENTORY: 2 volumes; "C" 96.0 GB free of 256.0 (38%), "D" 900.0 GB free of 2048.0 (44%).
Selected conditions
data_volume_space_exhausting
A data volume is projected to run out of space.
Also reported by: Disk volumes
Impact: Capacity may be exhausted before normal maintenance can intervene.
Example
started; volume "D" volume role 2
sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000002
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000002
SparkLogs: data_volume_space_exhausting, Error, disk_volumes: data_volume_space_exhausting: NOTABLE: started; volume "D" volume role 2
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | storage |
held | Trace to Fatal | storage |
recovered | Trace to Fatal | storage |
data_volume_space_low
A fixed data volume is low on free space.
Also reported by: Disk volumes
Impact: Applications or shares using that volume may fail writes if free space continues to fall.
Example
started; volume "D" free space 0.39% (threshold 10%)
sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000002
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000002
sparklogs.data.disk_volumes.volume_role_code: 2
sparklogs.data.disk_volumes.writeable: true
sparklogs.data.disk_volumes.free_pct: 0.39
sparklogs.data.disk_volumes.free_bytes: 8589934592
sparklogs.data.disk_volumes.volume_space_low_age_h: 0.0
SparkLogs: data_volume_space_low, Display, disk_volumes: data_volume_space_low: NOTABLE: started; volume "D" free space 0.39% (threshold 10%)
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | storage |
held | Trace to Fatal | storage |
recovered | Trace to Fatal | storage |
os_volume_space_exhausting
The OS volume is projected to run out of space.
Also reported by: Disk volumes
Impact: The host may fail updates, logging, paging, or normal service operation if the OS volume fills.
Example
started; volume "C" volume role 1
sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
SparkLogs: os_volume_space_exhausting, Severe, disk_volumes: os_volume_space_exhausting: NOTABLE: started; volume "C" volume role 1
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | storage |
held | Trace to Fatal | storage |
recovered | Trace to Fatal | storage |
os_volume_space_low
The OS volume is low on free space.
Also reported by: Disk volumes
Impact: Updates, logs, paging, or temporary files may be constrained if free space keeps falling.
Example
started; volume "C" free space 3.52% (threshold 15%)
sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.volume_role_code: 1
sparklogs.data.disk_volumes.free_pct: 3.52
sparklogs.data.disk_volumes.free_bytes: 9663676416
sparklogs.data.disk_volumes.volume_space_low_age_h: 0.0
SparkLogs: os_volume_space_low, Notice, disk_volumes: os_volume_space_low: NOTABLE: started; volume "C" free space 3.52% (threshold 15%)
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | storage |
held | Trace to Fatal | storage |
recovered | Trace to Fatal | storage |
volume_bitlocker_dropped
BitLocker protection is off or suspended on a fixed volume.
Also reported by: Disk volumes
Impact: Data-at-rest protection may be reduced while the state persists.
Example
started; volume "C" bitlocker off for 129min (threshold 120min)
sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.bitlocker_dropped: true
sparklogs.data.disk_volumes.bitlocker_off_age_min: 129.0
SparkLogs: volume_bitlocker_dropped, Notice, disk_volumes: volume_bitlocker_dropped: NOTABLE: started; volume "C" bitlocker off for 129min (threshold 120min)
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | storage |
held | Trace to Fatal | storage |
recovered | Trace to Fatal | storage |
volume_fill_rate_high
A volume has a high fill rate that current capacity is absorbing.
Also reported by: Disk volumes
Impact: Capacity trend is worth watching, but no near-term full-volume condition is claimed.
Example
started; volume "D" fill rate 40.0 GB (threshold 1.0 GB)
sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000002
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000002
SparkLogs: volume_fill_rate_high, Display, disk_volumes: volume_fill_rate_high: NOTABLE: started; volume "D" fill rate 40.0 GB (threshold 1.0 GB)