Reliability

The 64 checks in the “Reliability” category of a SQL Server audit: what each one verifies, its severity and the versions covered.

Checks in this category
64
Weight in the score
18
Breakdown by severity
9 critical · 23 high · 15 medium · 1 low · 16 info

Checks in this category

  • AG001

    Availability group synchronization health

    Critical

    Verifies each Always On availability group reports HEALTHY synchronization via sys.dm_hadr_availability_group_states.

    Versions : 2012-2025

  • AG002

    Replica synchronization health

    Critical

    Detects replicas whose synchronization_health_desc is not HEALTHY in sys.dm_hadr_availability_replica_states.

    Versions : 2012-2025

  • AG003

    Per-database AG synchronization state

    Critical

    Verifies each AG database is SYNCHRONIZED or SYNCHRONIZING on every replica via sys.dm_hadr_database_replica_states.

    Versions : 2012-2025

  • AG004

    AG data movement suspended

    Critical

    Detects databases with is_suspended = 1, meaning data movement to a replica is halted.

    Versions : 2012-2025

  • AG021

    AG listener offline

    Critical

    Detects AG listener IPs whose state is not ONLINE in sys.dm_tcp_listener_states.

    Versions : 2012-2025

  • REL001

    Corruption Detected

    Critical

    No corruption should be present in msdb.dbo.suspect_pages

    Versions : 2012-2025

  • REL004

    AG Health

    Critical

    Verify Availability Groups health

    Versions : 2012-2025

  • WSFC001

    WSFC quorum state

    Critical

    Verifies quorum_state_desc is NORMAL_QUORUM in sys.dm_hadr_cluster.

    Versions : 2012-2025

  • WSFC004

    WSFC cluster nodes up

    Critical

    Detects cluster nodes whose state is not up via sys.dm_os_cluster_nodes.

    Versions : 2012-2025

  • AG005

    AG replica connection state

    High

    Detects replicas whose connected_state_desc is not CONNECTED.

    Versions : 2012-2025

  • AG006

    AG database failover-readiness

    High

    Checks is_failover_ready in sys.dm_hadr_database_replica_cluster_states for secondary replicas.

    Versions : 2012-2025

  • AG007

    AG estimated RPO (commit lag)

    High

    Estimates potential data loss via the last_commit_time delta between primary and each secondary.

    Versions : 2012-2025

  • AG008

    AG estimated RTO (redo backlog)

    High

    Estimates secondary catch-up time via redo_queue_size / redo_rate.

    Versions : 2012-2025

  • AG009

    AG log send queue backlog

    High

    Detects a persistent log_send_queue_size to a secondary (>1 MB), indicating RPO risk.

    Versions : 2012-2025

  • AG010

    AG automatic failover partner

    High

    Verifies a WSFC AG has at least two SYNCHRONOUS_COMMIT/AUTOMATIC replicas to allow automatic failover.

    Versions : 2012-2025

  • AG011

    AG automatic failover target not SYNCHRONIZED

    High

    Detects databases on an automatic-failover replica that are not SYNCHRONIZED, which would prevent lossless failover.

    Versions : 2012-2025

  • AG012

    REQUIRED_SYNCHRONIZED_SECONDARIES_TO_COMMIT misconfigured

    High

    Verifies required_synchronized_secondaries_to_commit does not exceed the number of available synchronous secondaries.

    Versions : 2017-2025

  • AG013

    AG automatic seeding failures

    High

    Detects failed automatic seeding operations in sys.dm_hadr_automatic_seeding.

    Versions : 2016-2025

  • AG020

    AG listener missing

    High

    Detects availability groups without a configured listener.

    Versions : 2012-2025

  • AG023

    HADR mirroring endpoint state/encryption

    High

    Verifies the mirroring endpoint (AG transport) is STARTED and AES-encrypted, not RC4 or disabled.

    Versions : 2012-2025

  • AG026

    AG automatic page repair

    High

    Detects corrupt pages not yet repaired (page_status <> 4) in sys.dm_hadr_auto_page_repair.

    Versions : 2012-2025

  • AG028

    Distributed availability group health

    High

    Verifies a distributed AG (is_distributed = 1) reports HEALTHY synchronization.

    Versions : 2016-2025

  • DR001

    DR replica (geographic separation)

    High

    Verifies at least one AG replica resides on a distinct site/subnet (best-effort from endpoints).

    Versions : 2012-2025

  • DR005

    User databases without HA/DR protection

    High

    Cross-references AG membership, mirroring, and log shipping to detect user databases protected only by backups.

    Versions : 2012-2025

  • LSHIP001

    Log shipping restore latency

    High

    Detects secondaries whose restore lag exceeds restore_threshold (alert 14421).

    Versions : 2012-2025

  • LSHIP002

    Log shipping backup latency

    High

    Detects primaries whose log backup lag exceeds backup_threshold (alert 14420).

    Versions : 2012-2025

  • REL002

    Memory Dumps

    High

    Memory dumps indicate stability issues

    Versions : 2012-2025

  • REPL001

    Replication latency (tracer token)

    High

    Measures end-to-end transactional latency via tracer token history in the distribution database.

    Versions : 2012-2025

  • REPL002

    Replication undistributed commands

    High

    Detects a large backlog of undistributed commands via replication monitor data.

    Versions : 2012-2025

  • REPL003

    Replication agent job status

    High

    Detects replication agent jobs (REPL-* category) whose last run failed.

    Versions : 2012-2025

  • WSFC002

    WSFC quorum witness present

    High

    Detects a missing witness while the vote count is even, risking split-brain.

    Versions : 2012-2025

  • WSFC003

    WSFC quorum witness online

    High

    Detects a witness whose member_state_desc is DOWN.

    Versions : 2012-2025

  • AG014

    AG databases not joined on a replica

    Medium

    Detects AG databases not joined (is_database_joined = 0) on a replica, hence unprotected there.

    Versions : 2012-2025

  • AG015

    AG session timeout below default

    Medium

    Detects replicas with session_timeout lower than the 10-second default.

    Versions : 2012-2025

  • AG018

    AG read-only routing URL missing

    Medium

    Detects readable replicas without a read_only_routing_url defined.

    Versions : 2012-2025

  • AG027

    Contained availability group system databases

    Medium

    For contained AGs (SQL 2022, is_contained = 1), verifies the contained system databases (master/msdb) are present.

    Versions : 2022-2025

  • DR003

    Database Mirroring health & deprecation

    Medium

    Detects mirrored databases, their synchronization state, and flags the feature's deprecation.

    Versions : 2012-2025

  • FCI005

    FCI shared storage resilience

    Medium

    Enumerates cluster shared drives via sys.dm_io_cluster_shared_drives to detect a storage SPOF.

    Versions : 2012-2025

  • LSHIP003

    Log shipping copy lag

    Medium

    Detects a log copy lag (last_copied_date_utc) greater than 30 minutes on a secondary.

    Versions : 2012-2025

  • LSHIP004

    Log shipping restore-threshold alert

    Medium

    Detects secondaries with threshold_alert_enabled = 0, hence no out-of-sync alerting.

    Versions : 2012-2025

  • REL007

    Last Critical Error

    Medium

    Check for recent critical errors in the log

    Versions : 2012-2025

  • REL008

    User objects in system databases

    Medium

    Finds application tables, views, procedures and functions created in master, msdb or model. These objects fall outside the application backups and are lost when the instance is rebuilt after a disaster.

    Versions : 2012-2025

  • REL009

    Third-party modules loaded in the SQL Server process

    Medium

    Lists the non-Microsoft libraries loaded inside the sqlservr process. A fault in any of them takes the whole instance down, and unsigned code inside the engine process is a supply-chain exposure.

    Versions : 2012-2025

  • REPL004

    Replication distribution retention

    Medium

    Verifies the max distribution retention (MSdistributiondbs) is sufficient relative to the backlog.

    Versions : 2012-2025

  • WSFC005

    WSFC quorum vote assignment

    Medium

    Detects vote-assignment anomalies (DOWN member holding a vote, node with multiple votes).

    Versions : 2012-2025

  • WSFC006

    WSFC fault-tolerance margin

    Medium

    Evaluates whether the cluster can still lose one vote without dropping below quorum.

    Versions : 2012-2025

  • WSFC007

    WSFC cluster networks health

    Medium

    Enumerates cluster networks via sys.dm_hadr_cluster_networks; up/down state requires the FailoverClusters module.

    Versions : 2012-2025

  • LSHIP005

    Log shipping dedicated monitor

    Low

    Detects the absence of a dedicated monitor server or a monitor hosted on the primary/secondary itself.

    Versions : 2012-2025

  • AG016

    AG health-check / failure-condition non-default

    Info

    Flags a health_check_timeout or failure_condition_level different from defaults (30000 ms / level 3).

    Versions : 2012-2025

  • AG017

    No readable AG secondary

    Info

    Indicates no replica allows read connections (secondary_role_allow_connections_desc).

    Versions : 2012-2025

  • AG019

    AG read-only routing list empty

    Info

    Detects replicas whose read-only routing list is empty in sys.availability_read_only_routing_lists.

    Versions : 2012-2025

  • AG022

    AG backup preference (this replica)

    Info

    Reports the automated_backup_preference and whether this replica is preferred for backup (fn_hadr_backup_is_preferred_replica).

    Versions : 2012-2025

  • AG024

    AG flow control waits

    Info

    Measures cumulative HADR flow-control waits (HADR_*_FLOW_CONTROL) since startup.

    Versions : 2012-2025

  • AG025

    AG replica build consistency

    Info

    Reports this instance's SQL build for cross-replica comparison (not remotely queryable in T-SQL).

    Versions : 2012-2025

  • DR002

    Recent failover / DR test

    Info

    Flags that no failover-test history is queryable in T-SQL (events live in the cluster log / AlwaysOn_health ring buffer).

    Versions : 2012-2025

  • FCI001

    FCI failure-condition / health-check level

    Info

    Flags that the FCI FailureConditionLevel and HealthCheckTimeout are not queryable in pure T-SQL.

    Versions : 2012-2025

  • FCI002

    FCI possible owners

    Info

    Flags that the FCI role's possible-owner node list is not accessible in T-SQL.

    Versions : 2012-2025

  • FCI003

    FCI lease timeout below default

    Info

    Flags that the FCI/AG LeaseTimeout is not queryable in T-SQL (cluster resource parameter).

    Versions : 2012-2025

  • FCI004

    FCI clustered MSDTC

    Info

    Flags that the presence of a clustered MSDTC is not verifiable in T-SQL.

    Versions : 2012-2025

  • OPS001

    Suspect pages recorded (inventory)

    Info

    Reports the rows in msdb.dbo.suspect_pages (event_type 1 to 3), which signal I/O or page-level corruption. Inventory without a verdict: that one is carried by REL001, which queries the same table — counting it twice would penalise a single corruption twice.

    Versions : 2012-2025

  • REL003

    Mirroring Status

    Info

    Check Database Mirroring status if configured

    Versions : 2012-2025

  • REL005

    Log Shipping Status

    Info

    Check Log Shipping status if configured

    Versions : 2012-2025

  • REL006

    Cluster Status

    Info

    Verify cluster health if FCI

    Versions : 2012-2025

  • REPL005

    Replication monitor thresholds

    Info

    Detects missing thresholds in MSpublicationthresholds, hence no alerting on latency/backlog.

    Versions : 2012-2025

Other categories

All checks