Skip to main content

Disk volumes

7readings
7conditions
2themes fed
Livestatus

Every fixed volume: free space, fill trend, protection state and whether the filesystem is readable.

Topic id: disk_volumes.

Full inventory every 15 minutes. Supported changes are reported when the agent observes them.

Fields​

Capacity, growth, protection and filesystem readings for each fixed volume.

FieldTypeUnitMeaning
sparklogs.data.disk_volumes.volumestringThe volume's stable identity (its GUID), lowercased. Episode continuity keys off this, never the drive letter.
sparklogs.data.disk_volumes.display_namestringThe drive letter, when the volume has one; otherwise its primary mount path.
sparklogs.data.disk_volumes.volume_labelstringThe volume's OS-assigned name.
sparklogs.data.disk_volumes.aliasesstring_arrayOther names this volume is known by, such as its label: excludes its opaque id and its current display_name.
sparklogs.data.disk_volumes.drive_typestringWhat kind of drive this volume sits on, from GetDriveTypeW.
sparklogs.data.disk_volumes.volume_rolestringos: Windows volume. fixed_data: other fixed data volume. removable: removable volume. Absent when unknown, which prevents conditions requiring a known role from firing.
sparklogs.data.disk_volumes.volume_role_codeintegerNumeric code for volume_role.
sparklogs.data.disk_volumes.free_bytesintegerbytesHow many bytes are free on the volume.
sparklogs.data.disk_volumes.free_pctfloatpercentFree space as a percentage of the volume's total.
sparklogs.data.disk_volumes.used_pctfloatpercentSpace used as a percentage of the volume's total (100 minus free_pct), carried on the row because the exhaustion floors are written against the used share.
sparklogs.data.disk_volumes.writeableboolWhether the filesystem reports that writes are allowed. Absent when the filesystem did not answer.
sparklogs.data.disk_volumes.mount_statestringWhether the volume is mounted, unmounted, raw, or unreadable. Absent when the volume's filesystem query did not answer this read.
sparklogs.data.disk_volumes.mount_state_codeintegerNumeric code for mount_state.
sparklogs.data.disk_volumes.filesystemstringThe volume's filesystem, lowercased. Absent when the volume's filesystem query did not answer this read.
sparklogs.data.disk_volumes.bitlocker_protectionstringThe volume's BitLocker posture: on, off, suspended, or n_a when BitLocker is not in use on this volume. Absent when the provider could not answer.
sparklogs.data.disk_volumes.bitlocker_droppedboolWhether BitLocker protection is off or suspended. Absent when protection status could not be read.
sparklogs.data.disk_volumes.bitlocker_off_age_minfloatminutesHow long BitLocker protection has been off or suspended.
sparklogs.data.disk_volumes.fill_rate_bytes_per_hfloatbytes_per_hourHow fast the volume's free space is shrinking: the sustained p25 of five-minute free-space intervals over the last hour, gated on the last ~10 min still filling. Absent until that hour exists.
sparklogs.data.disk_volumes.fill_slope_sustained_hfloathoursHow long the current fill trend has held.
sparklogs.data.disk_volumes.projected_full_eta_hfloathoursThe raw projected time until the volume fills, from the fill rate alone.
sparklogs.data.disk_volumes.exhaustion_eta_hfloathoursProjected hours until the volume fills. Zero when it has already reached its capacity ceiling, even if the fill rate has stalled.
sparklogs.data.disk_volumes.backing_bus_permanentboolWhether every transport behind this volume is a permanent one (not USB). Absent while the backing transports are unknown.
sparklogs.data.disk_volumes.resourceobjectWhat is measured (volume_space), its unit, and where it stands: used and capacity in bytes.
sparklogs.data.disk_volumes.projectionobjectThe forecast derived from resource and a lookback window: the signed change in used bytes over the window, the window's length, and the horizon that decided the reading's severity.
sparklogs.data.disk_volumes.departure_notice_eligibleboolWhether this volume's clean departure would be worth reporting: its role is known, its presence baseline is complete, and its backing bus is permanent, gated by whether departure notices are enabled on this host.
sparklogs.data.disk_volumes.seen_countintegercountHow many of the observations counted toward this volume's presence baseline actually saw it.
sparklogs.data.disk_volumes.observed_countintegercountHow many observations have counted toward this volume's presence baseline.
sparklogs.data.disk_volumes.presence_ratio_pctfloatpercentseen_count over observed_count, as a percentage: the ratio the presence baseline is judged on.
sparklogs.data.disk_volumes.presence_tracked_dfloatdaysHow long this volume has been tracked for its presence baseline.
sparklogs.data.disk_volumes.observed_atstringtimestampWhen this row's reading was taken.
sparklogs.data.disk_volumes.staleboolTrue when a failed probe left a previous reading in place. Changes between stale and fresh readings produce a delta.
sparklogs.data.disk_volumes.volume_space_low_age_basisstringonset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time.
sparklogs.data.disk_volumes.volume_space_low_age_hfloathoursHow long this condition has been open, in hours.
sparklogs.data.disk_volumes.volume_unreadable_age_basisstringonset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time.
sparklogs.data.disk_volumes.volume_unreadable_age_hfloathoursHow long this condition has been open, in hours.

Conditions​

A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.

ConditionSeverityHow an episode ends
data volume running out of space (data_volume_space_exhausting)Warning to ErrorIt closes on a recovery rule written for this condition, which reads more than one measurement together.
data volume space low (data_volume_space_low)DisplayIt closes when any one of the several recovery conditions is met.
OS volume running out of space (os_volume_space_exhausting)Warning to CriticalIt closes on a recovery rule written for this condition, which reads more than one measurement together.
OS volume space low (os_volume_space_low)Notice to SeriousIt closes when any one of the several recovery conditions is met.
BitLocker protection dropped (volume_bitlocker_dropped)NoticeIt closes when the state it watches is no longer set.
volume filling fast (volume_fill_rate_high)DisplayIt closes on a recovery rule written for this condition, which reads more than one measurement together.
volume unreadable (volume_unreadable)Serious to SevereIt closes when the host reports one of the healthy states again.

Example​

Inventory (every 15 minutes)

2 volumes; "C" 96.0 GB free of 256.0 (38%), "D" 900.0 GB free of 2048.0 (44%).

sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.bitlocker_protection: on
sparklogs.data.disk_volumes.filesystem: ntfs
sparklogs.data.disk_volumes.mount_state: mounted
sparklogs.data.disk_volumes.stale: false
sparklogs.data.disk_volumes.volume_role: os
sparklogs.data.disk_volumes.volume_role_code: 1
sparklogs.data.disk_volumes.writeable: true
sparklogs.data.disk_volumes.free_pct: 37.5
sparklogs.data.disk_volumes.free_bytes: 103079215104
sparklogs.data.disk_volumes.bitlocker_dropped: false
sparklogs.data.disk_volumes.mount_state_code: 1

SparkLogs: CONTEXT, Info, disk_volumes: INVENTORY: 2 volumes; "C" 96.0 GB free of 256.0 (38%), "D" 900.0 GB free of 2048.0 (44%).

Selected conditions​

data_volume_space_exhausting​

A data volume is projected to run out of space.

Also reported by: Disk volumes

Impact: Capacity may be exhausted before normal maintenance can intervene.

Example

started; volume "D" volume role 2

sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000002
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000002

SparkLogs: data_volume_space_exhausting, Error, disk_volumes: data_volume_space_exhausting: NOTABLE: started; volume "D" volume role 2

CaseSeverityTicket class
onsetTrace to Fatalstorage
heldTrace to Fatalstorage
recoveredTrace to Fatalstorage

data_volume_space_low​

A fixed data volume is low on free space.

Also reported by: Disk volumes

Impact: Applications or shares using that volume may fail writes if free space continues to fall.

Example

started; volume "D" free space 0.39% (threshold 10%)

sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000002
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000002
sparklogs.data.disk_volumes.volume_role_code: 2
sparklogs.data.disk_volumes.writeable: true
sparklogs.data.disk_volumes.free_pct: 0.39
sparklogs.data.disk_volumes.free_bytes: 8589934592
sparklogs.data.disk_volumes.volume_space_low_age_h: 0.0

SparkLogs: data_volume_space_low, Display, disk_volumes: data_volume_space_low: NOTABLE: started; volume "D" free space 0.39% (threshold 10%)

CaseSeverityTicket class
onsetTrace to Fatalstorage
heldTrace to Fatalstorage
recoveredTrace to Fatalstorage

os_volume_space_exhausting​

The OS volume is projected to run out of space.

Also reported by: Disk volumes

Impact: The host may fail updates, logging, paging, or normal service operation if the OS volume fills.

Example

started; volume "C" volume role 1

sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000001

SparkLogs: os_volume_space_exhausting, Severe, disk_volumes: os_volume_space_exhausting: NOTABLE: started; volume "C" volume role 1

CaseSeverityTicket class
onsetTrace to Fatalstorage
heldTrace to Fatalstorage
recoveredTrace to Fatalstorage

os_volume_space_low​

The OS volume is low on free space.

Also reported by: Disk volumes

Impact: Updates, logs, paging, or temporary files may be constrained if free space keeps falling.

Example

started; volume "C" free space 3.52% (threshold 15%)

sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.volume_role_code: 1
sparklogs.data.disk_volumes.free_pct: 3.52
sparklogs.data.disk_volumes.free_bytes: 9663676416
sparklogs.data.disk_volumes.volume_space_low_age_h: 0.0

SparkLogs: os_volume_space_low, Notice, disk_volumes: os_volume_space_low: NOTABLE: started; volume "C" free space 3.52% (threshold 15%)

CaseSeverityTicket class
onsetTrace to Fatalstorage
heldTrace to Fatalstorage
recoveredTrace to Fatalstorage

volume_bitlocker_dropped​

BitLocker protection is off or suspended on a fixed volume.

Also reported by: Disk volumes

Impact: Data-at-rest protection may be reduced while the state persists.

Example

started; volume "C" bitlocker off for 129min (threshold 120min)

sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.disk_volumes.bitlocker_dropped: true
sparklogs.data.disk_volumes.bitlocker_off_age_min: 129.0

SparkLogs: volume_bitlocker_dropped, Notice, disk_volumes: volume_bitlocker_dropped: NOTABLE: started; volume "C" bitlocker off for 129min (threshold 120min)

CaseSeverityTicket class
onsetTrace to Fatalstorage
heldTrace to Fatalstorage
recoveredTrace to Fatalstorage

volume_fill_rate_high​

A volume has a high fill rate that current capacity is absorbing.

Also reported by: Disk volumes

Impact: Capacity trend is worth watching, but no near-term full-volume condition is claimed.

Example

started; volume "D" fill rate 40.0 GB (threshold 1.0 GB)

sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000002
sparklogs.data.disk_volumes.volume: volume:3b1a9c1e-0000-0000-0000-100000000002

SparkLogs: volume_fill_rate_high, Display, disk_volumes: volume_fill_rate_high: NOTABLE: started; volume "D" fill rate 40.0 GB (threshold 1.0 GB)