Skip to main content

VSS shadow storage

2readings
2conditions
1themes fed
Livestatus

Shadow-copy storage allocation and how close it is to its cap.

Topic id: vss_shadowstorage.

Full inventory every 6 hours. Supported changes are reported when the agent observes them.

Fields​

Shadow-copy allocation, usage and configured limits.

FieldTypeUnitMeaning
sparklogs.data.vss_shadowstorage.display_namestringThe volume's drive letter or mount path, for display.
sparklogs.data.vss_shadowstorage.volumestringThe volume's stable identity, the same identity disk_volumes and volume_map use. Falls back to the raw lowercased vssadmin string when the volume could not be resolved to that identity.
sparklogs.data.vss_shadowstorage.volume_resolutionstringunresolved when the volume key is the raw vssadmin value and cannot be joined to the shared volume identity.
sparklogs.data.vss_shadowstorage.shadowstorage_used_pctfloatpercentHow much of the volume's shadow-storage allocation is used.
sparklogs.data.vss_shadowstorage.shadowstorage_at_capboolWhether shadow-storage usage is at or above its maximum allocation.
sparklogs.data.vss_shadowstorage.shadow_snapshots_deleted_deltaintegercountRestore points lost since the prior facts pass, when that could be derived. Normally absent: the underlying commands do not enumerate shadows, so this lights up only when a source happens to supply it.
sparklogs.data.vss_shadowstorage.snap_fail_count_7dintegercountHow many snapshot failures this volume has recorded in the last 7 days. Absent until the event-log failure scan has first run after a start, or while its reading is stale; zero when the scan ran and found none.
sparklogs.data.vss_shadowstorage.snap_fail_count_24hintegercountHow many snapshot failures this volume has recorded in the last 24 hours. Absent until the event-log failure scan has first run after a start, or while its reading is stale; zero when the scan ran and found none.
sparklogs.data.vss_shadowstorage.snap_fail_count_7d_by_idobjectThe 7-day snapshot failure count broken out by the Windows Event Log id that recorded each failure.
sparklogs.data.vss_shadowstorage.snap_fail_count_24h_by_idobjectThe 24-hour snapshot failure count broken out by the Windows Event Log id that recorded each failure.
sparklogs.data.vss_shadowstorage.snap_fail_first_seen_tsstringtimestampWhen the oldest snapshot failure counted in the current window was recorded.
sparklogs.data.vss_shadowstorage.snap_fail_last_seen_tsstringtimestampWhen the newest snapshot failure counted in the current window was recorded.
sparklogs.data.vss_shadowstorage.snap_fail_truncatedboolWhether the snapshot failure count hit its cap: more failures happened than the counter kept individually.
sparklogs.data.vss_shadowstorage.snap_fail_unresolved_countintegercountHow many snapshot failure records could not be attributed to a specific volume.
sparklogs.data.vss_shadowstorage.snap_fail_measured_atstringtimestampWhen this row's snapshot failure counts were measured.
sparklogs.data.vss_shadowstorage.vss_shadowstorage_age_basisstringonset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time.
sparklogs.data.vss_shadowstorage.vss_shadowstorage_age_hfloathoursHow long this condition has been open, in hours.

Conditions​

A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.

ConditionSeverityHow an episode ends
shadow storage near cap (vss_shadowstorage_near_cap)NoticeIt closes when the measurement falls back past its recovery point.
shadow copies failing for space (vss_snapshots_failing_for_space)Notice to ErrorIt closes when the measurement falls back past its recovery point.

Example​

Inventory (every 6 hours)

1 shadow store.

sparklogs.data.vss_shadowstorage.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.shadowstorage_at_cap: false
sparklogs.data.vss_shadowstorage.shadowstorage_used_pct: 17.58
sparklogs.data.vss_shadowstorage.snap_fail_count_24h: 0
sparklogs.data.vss_shadowstorage.snap_fail_count_7d: 0

SparkLogs: CONTEXT, Info, vss_shadowstorage: INVENTORY: 1 shadow store.

Selected conditions​

vss_shadowstorage_near_cap​

Shadow storage is near capacity.

Also reported by: VSS shadow storage

Impact: Restore points may start being deleted if usage continues to rise.

Example

started; volume "C" shadow storage used 92.19% (threshold 90%)

sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.shadowstorage_used_pct: 92.19
sparklogs.data.vss_shadowstorage.vss_shadowstorage_age_h: 0.0

SparkLogs: vss_shadowstorage_near_cap, Notice, vss_shadowstorage: vss_shadowstorage_near_cap: NOTABLE: started; volume "C" shadow storage used 92.19% (threshold 90%)

CaseSeverityTicket class
onsetTrace to Fatalbackup
heldTrace to Fatalbackup
recoveredTrace to Fatalbackup

vss_snapshots_failing_for_space​

Shadow copies are failing for want of space, so restore points are being lost.

Also reported by: Windows Application event log, Windows System event log, VSS shadow storage

Impact: Older restore points are being trimmed; backups themselves may still succeed, but restore history depth shrinks.

Example

started; volume "C" snapshot failures in a day 4 (threshold 3)

sparklogs.instance: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.volume: volume:3b1a9c1e-0000-0000-0000-100000000001
sparklogs.data.vss_shadowstorage.snap_fail_count_24h: 4
sparklogs.data.vss_shadowstorage.snap_fail_count_7d: 4
sparklogs.data.vss_shadowstorage.vss_shadowstorage_age_h: 0.0

SparkLogs: vss_snapshots_failing_for_space, Error, vss_shadowstorage: vss_snapshots_failing_for_space: NOTABLE: started; volume "C" snapshot failures in a day 4 (threshold 3)

CaseSeverityTicket class
onsetTrace to Fatalbackup
heldTrace to Fatalbackup
recoveredTrace to Fatalbackup