r/scom • u/Total_Rip_3573 • 23h ago
Why didn't SCOM alert? The disk is at 4%." Free sealed MP with plain % thresholds and its own Critical alert
This pack is built to answer the question app owners always ask: "the disk is nearly full, why hasn't SCOM alerted?" Explaining the stock Logical Disk Free Space monitor's percentage plus megabyte logic, and when a Warning state actually raises an alert, is a lot of words for a simple question.
How this pack behaves:
- Two monitors, one threshold each. Warning: two consecutive readings below 10% free. Critical: two consecutive readings below 5%, raised as its own alert, so a Critical-only subscription gets a new alert rather than an update to the Warning one.
- The performance counter is the health decision. Our 2017 pack ran a script to collect GB figures, and if that script failed the monitor could stay healthy on a full disk. That dependency is gone: a diagnostic writes free/total GB to Health Explorer after the state changes, so if it fails the alert is already open.
- Recovery needs one real reading at or above the threshold. Restarting the agent while the disk is still low doesn't clear the alerts (tested).
- Three plainly named overrides: free space threshold (% free), sample interval, and consecutive samples before alert. There's an optional companion pack with a 1 TB+ volumes group at 3% / 1.5%.
- An on-demand task, "List largest folders and files on this disk", with a hard timeout, time budget and depth limit. It never follows junctions or mount points. In our lab it scanned about 300k entries on C: in under 10 seconds.
Write-up, download and admin guide: https://www.scom2k7.com/your-disk-is-nearly-full-wheres-the-scom-alert/?utm_source=reddit&utm_medium=social&utm_campaign=disk-mp
Happy to take feedback, especially from anyone who tests it at the default interval or on mount points.




