VSS shadow storage
Shadow-copy storage allocation and how close it is to its cap.
Topic id: vss_shadowstorage.
Full inventory every 6 hours. Supported changes are reported when the agent observes them.
Fields
Shadow-copy allocation, usage and configured limits.
| Field | Type | Unit | Meaning |
|---|---|---|---|
sparklogs.data.vss_shadowstorage.display_name | string | The volume's drive letter or mount path, for display. | |
sparklogs.data.vss_shadowstorage.volume | string | The volume's stable identity, the same identity disk_volumes and volume_map use. Falls back to the raw lowercased vssadmin string when the volume could not be resolved to that identity. | |
sparklogs.data.vss_shadowstorage.volume_resolution | string | unresolved when the volume key is the raw vssadmin value and cannot be joined to the shared volume identity. | |
sparklogs.data.vss_shadowstorage.shadowstorage_used_pct | float | percent | How much of the volume's shadow-storage allocation is used. |
sparklogs.data.vss_shadowstorage.shadowstorage_at_cap | bool | Whether shadow-storage usage is at or above its maximum allocation. | |
sparklogs.data.vss_shadowstorage.shadow_snapshots_deleted_delta | integer | count | Restore points lost since the prior facts pass, when that could be derived. Normally absent: the underlying commands do not enumerate shadows, so this lights up only when a source happens to supply it. |
sparklogs.data.vss_shadowstorage.snap_fail_count_7d | integer | count | How many snapshot failures this volume has recorded in the last 7 days. Absent until the event-log failure scan has first run after a start, or while its reading is stale; zero when the scan ran and found none. |
sparklogs.data.vss_shadowstorage.snap_fail_count_24h | integer | count | How many snapshot failures this volume has recorded in the last 24 hours. Absent until the event-log failure scan has first run after a start, or while its reading is stale; zero when the scan ran and found none. |
sparklogs.data.vss_shadowstorage.snap_fail_count_7d_by_id | object | The 7-day snapshot failure count broken out by the Windows Event Log id that recorded each failure. | |
sparklogs.data.vss_shadowstorage.snap_fail_count_24h_by_id | object | The 24-hour snapshot failure count broken out by the Windows Event Log id that recorded each failure. | |
sparklogs.data.vss_shadowstorage.snap_fail_first_seen_ts | string | timestamp | When the oldest snapshot failure counted in the current window was recorded. |
sparklogs.data.vss_shadowstorage.snap_fail_last_seen_ts | string | timestamp | When the newest snapshot failure counted in the current window was recorded. |
sparklogs.data.vss_shadowstorage.snap_fail_truncated | bool | Whether the snapshot failure count hit its cap: more failures happened than the counter kept individually. | |
sparklogs.data.vss_shadowstorage.snap_fail_unresolved_count | integer | count | How many snapshot failure records could not be attributed to a specific volume. |
sparklogs.data.vss_shadowstorage.snap_fail_measured_at | string | timestamp | When this row's snapshot failure counts were measured. |
sparklogs.data.vss_shadowstorage.vss_shadowstorage_age_basis | string | onset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time. | |
sparklogs.data.vss_shadowstorage.vss_shadowstorage_age_h | float | hours | How long this condition has been open, in hours. |
Conditions
A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.
Example
Inventory (every 6 hours)
1 shadow store.
sparklogs.data.vss_shadowstorage.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.shadowstorage_at_cap: false
sparklogs.data.vss_shadowstorage.shadowstorage_used_pct: 17.58
sparklogs.data.vss_shadowstorage.snap_fail_count_24h: 0
sparklogs.data.vss_shadowstorage.snap_fail_count_7d: 0
SparkLogs: CONTEXT, Info, vss_shadowstorage: INVENTORY: 1 shadow store.
Selected conditions
vss_shadowstorage_near_cap
Shadow storage is near capacity.
Also reported by: VSS shadow storage
Impact: Restore points may start being deleted if usage continues to rise.
Example
started; volume "C" shadow storage used 92.19% (threshold 90%)
sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.shadowstorage_used_pct: 92.19
sparklogs.data.vss_shadowstorage.vss_shadowstorage_age_h: 0.0
SparkLogs: vss_shadowstorage_near_cap, Notice, vss_shadowstorage: vss_shadowstorage_near_cap: NOTABLE: started; volume "C" shadow storage used 92.19% (threshold 90%)
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | backup |
held | Trace to Fatal | backup |
recovered | Trace to Fatal | backup |
vss_snapshots_failing_for_space
Shadow copies are failing for want of space, so restore points are being lost.
Also reported by: Windows Application event log, Windows System event log, VSS shadow storage
Impact: Older restore points are being trimmed; backups themselves may still succeed, but restore history depth shrinks.
Example
started; volume "C" snapshot failures in a day 4 (threshold 3)
sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.snap_fail_count_24h: 4
sparklogs.data.vss_shadowstorage.snap_fail_count_7d: 4
sparklogs.data.vss_shadowstorage.vss_shadowstorage_age_h: 0.0
SparkLogs: vss_snapshots_failing_for_space, Error, vss_shadowstorage: vss_snapshots_failing_for_space: NOTABLE: started; volume "C" snapshot failures in a day 4 (threshold 3)
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | backup |
held | Trace to Fatal | backup |
recovered | Trace to Fatal | backup |