Processes
Per-process cost: CPU, working set, handles and sustained growth.
Topic id: processes.
Full inventory every hour. Supported changes are reported when the agent observes them.
Fields
Process identity, CPU, resident and private memory, and handle usage at the inventory observation.
| Field | Type | Unit | Meaning |
|---|---|---|---|
sparklogs.data.processes.pid | integer | Process ID. Combine with create_time_ts to distinguish processes when Windows reuses a PID. | |
sparklogs.data.processes.create_time_ts | string | timestamp | When the process started, as RFC3339 UTC with a Z suffix, converted from the Windows FILETIME. Together with pid it is this row's real identity. |
sparklogs.data.processes.image_name | string | The process's executable file name. | |
sparklogs.data.processes.image_path | string | Normalized executable path. Command-line arguments are not collected. | |
sparklogs.data.processes.resident_bytes | integer | bytes | Resident memory, including pages this process shares with others. Adding this field across processes counts shared pages more than once. |
sparklogs.data.processes.resident_pct_ram | float | percent | resident_bytes as a percentage of installed physical RAM from the same capture. Absent when that total was not read. Shared pages can make these percentages add up to more than 100. |
sparklogs.data.processes.private_resident_bytes | integer | bytes | Resident memory private to this process. Absent when the operating system did not report it. A total of these values is not the machine's used RAM. |
sparklogs.data.processes.private_commit_bytes | integer | bytes | Private committed memory, including memory that is not currently resident. This is not physical RAM usage. |
sparklogs.data.processes.handle_count | integer | count | How many handles the process holds. |
sparklogs.data.processes.age_s | integer | seconds | How long the process has been running. |
sparklogs.data.processes.services | string_array | The services this process hosts, sorted. Absent when it hosts none. | |
sparklogs.data.processes.cpu_busy_pct_avg | float | percent | CPU usage since the oldest retained baseline, as a percentage of all logical cores. One saturated core out of eight reads 12.5. Baselines are retained every five minutes for up to an hour. The elapsed-time denominator includes sleep. Requires the same PID and creation time at both observations. A process missing from the baseline has no CPU or I/O averages. Absent for the System Idle Process (PID 0). |
sparklogs.data.processes.read_mb_per_s_avg | float | megabytes_per_second | Read rate over the CPU average baseline interval, in MiB/s (1,048,576 bytes/s). Requires the same process at both observations. Includes file, pipe, device and network I/O. |
sparklogs.data.processes.write_mb_per_s_avg | float | megabytes_per_second | Write rate over the CPU average baseline interval, in MiB/s (1,048,576 bytes/s). Requires the same process at both observations. Includes file, pipe, device and network I/O. |
sparklogs.data.processes.process_handle_count_high_age_basis | string | onset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time. | |
sparklogs.data.processes.process_handle_count_high_age_h | float | hours | How long this condition has been open, in hours. |
Conditions
A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.
| Condition | Severity | How an episode ends |
|---|---|---|
process handle count high (process_handle_count_high) | Display | It closes when the measurement falls back past its recovery point. |
Example
Inventory (every hour)
3 processes; top ram "sqlservr.exe" 6.0 GB.
sparklogs.data.processes.pid: 4180
sparklogs.data.processes.create_time_ts: 2026-07-13T10:00:00Z
sparklogs.data.processes.handle_count: 2400
SparkLogs: CONTEXT, Info, processes: INVENTORY: 3 processes; top ram "sqlservr.exe" 6.0 GB.
Change set (every 5 minutes)
2 changed, 1 started, 1 exited; "+svchost.exe" "-backup.exe".
sparklogs.data.processes.delta_kind: added
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-17T09:58:00Z
SparkLogs: CONTEXT, Info, processes: DELTA: 2 changed, 1 started, 1 exited; "+svchost.exe" "-backup.exe".
Selected conditions
process_handle_count_high
A process has a very high handle count.
Also reported by: Processes
Impact: The process may be near resource limits even if growth trend is not yet visible.
Example
started; process "svchost.exe" handles 1130000 (threshold 1000000)
sparklogs.instance: process:1234|2026-07-16T10:00:00Z
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-16T10:00:00Z
sparklogs.data.processes.handle_count: 1130000
sparklogs.data.processes.process_handle_count_high_age_h: 0.0
SparkLogs: process_handle_count_high, Display, processes: process_handle_count_high: NOTABLE: started; process "svchost.exe" handles 1130000 (threshold 1000000)
Example
cleared after 0h24m, peaked Display, relapses 1; process "Vendor: Model.exe" handles 79000 (clears at 800000)
sparklogs.instance: process:1234|2026-07-16T10:00:00Z
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-16T10:00:00Z
sparklogs.data.processes.handle_count: 79000
SparkLogs: process_handle_count_high, Info, processes: process_handle_count_high: RECOVERED: cleared after 0h24m, peaked Display, relapses 1; process "Vendor: Model.exe" handles 79000 (clears at 800000)
Example
subsiding, not yet cleared; process "Vendor: Model.exe" handles 950000 (clears at 800000), open for 0h11m
sparklogs.instance: process:1234|2026-07-16T10:00:00Z
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-16T10:00:00Z
sparklogs.data.processes.handle_count: 950000
sparklogs.data.processes.process_handle_count_high_age_h: 0.18
SparkLogs: process_handle_count_high, Display, processes: process_handle_count_high: ELEVATED: subsiding, not yet cleared; process "Vendor: Model.exe" handles 950000 (clears at 800000), open for 0h11m
Example
relapsed; process "Vendor: Model.exe" handles 1130000 (threshold 1000000), open for 0h19m, relapses 1
sparklogs.instance: process:1234|2026-07-16T10:00:00Z
sparklogs.data.processes.pid: 1234
sparklogs.data.processes.create_time_ts: 2026-07-16T10:00:00Z
sparklogs.data.processes.handle_count: 1130000
sparklogs.data.processes.process_handle_count_high_age_h: 0.32
SparkLogs: process_handle_count_high, Display, processes: process_handle_count_high: ELEVATED: relapsed; process "Vendor: Model.exe" handles 1130000 (threshold 1000000), open for 0h19m, relapses 1
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | performance |
held | Trace to Fatal | performance |
recovered | Trace to Fatal | performance |