Skip to main content

Processes

1readings
1conditions
1themes fed
Livestatus

Per-process cost: CPU, working set, handles and sustained growth.

Topic id: processes.

Full inventory every hour. Supported changes are reported when the agent observes them.

Fields​

Process identity, CPU, resident and private memory, and handle usage at the inventory observation.

FieldTypeUnitMeaning
sparklogs.data.processes.pidintegerProcess ID. Combine with create_time_ts to distinguish processes when Windows reuses a PID.
sparklogs.data.processes.create_time_tsstringtimestampWhen the process started, as RFC3339 UTC with a Z suffix, converted from the Windows FILETIME. Together with pid it is this row's real identity.
sparklogs.data.processes.image_namestringThe process's executable file name.
sparklogs.data.processes.image_pathstringNormalized executable path. Command-line arguments are not collected.
sparklogs.data.processes.resident_bytesintegerbytesResident memory, including pages this process shares with others. Adding this field across processes counts shared pages more than once.
sparklogs.data.processes.resident_pct_ramfloatpercentresident_bytes as a percentage of installed physical RAM from the same capture. Absent when that total was not read. Shared pages can make these percentages add up to more than 100.
sparklogs.data.processes.private_resident_bytesintegerbytesResident memory private to this process. Absent when the operating system did not report it. A total of these values is not the machine's used RAM.
sparklogs.data.processes.private_commit_bytesintegerbytesPrivate committed memory, including memory that is not currently resident. This is not physical RAM usage.
sparklogs.data.processes.handle_countintegercountHow many handles the process holds.
sparklogs.data.processes.age_sintegersecondsHow long the process has been running.
sparklogs.data.processes.servicesstring_arrayThe services this process hosts, sorted. Absent when it hosts none.
sparklogs.data.processes.cpu_busy_pct_avgfloatpercentCPU usage since the oldest retained baseline, as a percentage of all logical cores. One saturated core out of eight reads 12.5. Baselines are retained every five minutes for up to an hour. The elapsed-time denominator includes sleep. Requires the same PID and creation time at both observations. A process missing from the baseline has no CPU or I/O averages. Absent for the System Idle Process (PID 0).
sparklogs.data.processes.read_mb_per_s_avgfloatmegabytes_per_secondRead rate over the CPU average baseline interval, in MiB/s (1,048,576 bytes/s). Requires the same process at both observations. Includes file, pipe, device and network I/O.
sparklogs.data.processes.write_mb_per_s_avgfloatmegabytes_per_secondWrite rate over the CPU average baseline interval, in MiB/s (1,048,576 bytes/s). Requires the same process at both observations. Includes file, pipe, device and network I/O.
sparklogs.data.processes.process_handle_count_high_age_basisstringonset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time.
sparklogs.data.processes.process_handle_count_high_age_hfloathoursHow long this condition has been open, in hours.

Conditions​

A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.

ConditionSeverityHow an episode ends
process handle count high (process_handle_count_high)DisplayIt closes when the measurement falls back past its recovery point.

Example​

Inventory (every hour)

3 processes; top ram "sqlservr.exe" 6.0 GB.

sparklogs.data.processes.pid: 4180
sparklogs.data.processes.create_time_ts: 2026-07-13T10:00:00Z
sparklogs.data.processes.handle_count: 2400

SparkLogs: CONTEXT, Info, processes: INVENTORY: 3 processes; top ram "sqlservr.exe" 6.0 GB.

Change set (every 5 minutes)

2 changed, 1 started, 1 exited; "+svchost.exe" "-backup.exe".

sparklogs.data.processes.delta_kind: added
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-17T09:58:00Z

SparkLogs: CONTEXT, Info, processes: DELTA: 2 changed, 1 started, 1 exited; "+svchost.exe" "-backup.exe".

Selected conditions​

process_handle_count_high​

A process has a very high handle count.

Also reported by: Processes

Impact: The process may be near resource limits even if growth trend is not yet visible.

Example

started; process "svchost.exe" handles 1130000 (threshold 1000000)

sparklogs.instance: process:1234|2026-07-16T10:00:00Z
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-16T10:00:00Z
sparklogs.data.processes.handle_count: 1130000
sparklogs.data.processes.process_handle_count_high_age_h: 0.0

SparkLogs: process_handle_count_high, Display, processes: process_handle_count_high: NOTABLE: started; process "svchost.exe" handles 1130000 (threshold 1000000)

Example

cleared after 0h24m, peaked Display, relapses 1; process "Vendor: Model.exe" handles 79000 (clears at 800000)

sparklogs.instance: process:1234|2026-07-16T10:00:00Z
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-16T10:00:00Z
sparklogs.data.processes.handle_count: 79000

SparkLogs: process_handle_count_high, Info, processes: process_handle_count_high: RECOVERED: cleared after 0h24m, peaked Display, relapses 1; process "Vendor: Model.exe" handles 79000 (clears at 800000)

Example

subsiding, not yet cleared; process "Vendor: Model.exe" handles 950000 (clears at 800000), open for 0h11m

sparklogs.instance: process:1234|2026-07-16T10:00:00Z
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-16T10:00:00Z
sparklogs.data.processes.handle_count: 950000
sparklogs.data.processes.process_handle_count_high_age_h: 0.18

SparkLogs: process_handle_count_high, Display, processes: process_handle_count_high: ELEVATED: subsiding, not yet cleared; process "Vendor: Model.exe" handles 950000 (clears at 800000), open for 0h11m

Example

relapsed; process "Vendor: Model.exe" handles 1130000 (threshold 1000000), open for 0h19m, relapses 1

sparklogs.instance: process:1234|2026-07-16T10:00:00Z
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-16T10:00:00Z
sparklogs.data.processes.handle_count: 1130000
sparklogs.data.processes.process_handle_count_high_age_h: 0.32

SparkLogs: process_handle_count_high, Display, processes: process_handle_count_high: ELEVATED: relapsed; process "Vendor: Model.exe" handles 1130000 (threshold 1000000), open for 0h19m, relapses 1

CaseSeverityTicket class
onsetTrace to Fatalperformance
heldTrace to Fatalperformance
recoveredTrace to Fatalperformance