VSS writers
VSS writer state, the canonical evidence behind a failed backup.
Topic id: vss_writers.
Full inventory every 6 hours. Supported changes are reported when the agent observes them.
Fields
Writer status and errors relevant to backup readiness.
| Field | Type | Unit | Meaning |
|---|---|---|---|
sparklogs.data.vss_writers.writer | string | The VSS writer's name, lowercased so it joins with the string a failure message names it by. | |
sparklogs.data.vss_writers.display_name | string | The writer name as vssadmin prints it, case preserved, for display. | |
sparklogs.data.vss_writers.writer_state | string | The writer's state as vssadmin reports it. | |
sparklogs.data.vss_writers.writer_present | bool | Always true: this row exists only for a writer vssadmin actually listed. | |
sparklogs.data.vss_writers.writer_state_failed | bool | Whether writer_state starts with failed. | |
sparklogs.data.vss_writers.writer_class_code | integer | Numeric writer classification: ignored, notice-only, or error on failure. | |
sparklogs.data.vss_writers.writer_last_error | string | What the writer itself reported as its last error, so a failure names its cause instead of only its state. | |
sparklogs.data.vss_writers.writer_expected | bool | Whether the enrichment store expects this writer to be present on this host (for example, a SQL Server host expecting sqlserverwriter). Absent when that inventory has not run. | |
sparklogs.data.vss_writers.vss_writer_failed_age_basis | string | onset: witnessed start. observed: already present when first seen, making age a lower bound. unknown_ongoing: no meaningful onset time. | |
sparklogs.data.vss_writers.vss_writer_failed_age_h | float | hours | How long this condition has been open, in hours. |
Conditions
A condition is a state that holds for a while. The agent opens it when the host enters it, keeps it open while it lasts, and closes it when the host comes back out, so one episode answers for the whole stretch instead of one alert per sample.
| Condition | Severity | How an episode ends |
|---|---|---|
VSS writer failed (vss_writer_failed) | Notice to Error | It closes when any one of the several recovery conditions is met. |
Example
Inventory (every 6 hours)
4 writers.
sparklogs.data.vss_writers.writer: sqlserverwriter
sparklogs.data.vss_writers.writer_state: stable
sparklogs.data.vss_writers.writer_state_failed: false
sparklogs.data.vss_writers.writer_class_code: 4
SparkLogs: CONTEXT, Info, vss_writers: INVENTORY: 4 writers.
Selected conditions
vss_writer_failed
A VSS writer is failed or unstable.
Also reported by: Windows Application event log, VSS writers
Impact: Backups depending on that writer may fail, exclude data, or fall back to crash-consistent behavior.
Example
started; writer "system writer" state failed
sparklogs.instance: writer:system writer
sparklogs.data.vss_writers.writer: system writer
sparklogs.data.vss_writers.writer_state_failed: true
sparklogs.data.vss_writers.writer_class_code: 2
sparklogs.data.vss_writers.vss_writer_failed_age_h: 0.0
SparkLogs: vss_writer_failed, Notice, vss_writers: vss_writer_failed: NOTABLE: started; writer "system writer" state failed
| Case | Severity | Ticket class |
|---|---|---|
onset | Trace to Fatal | backup |
held | Trace to Fatal | backup |
recovered | Trace to Fatal | backup |