# Interpret S2D drive history at the device measurement boundary

> Which parts of the I/O path are represented by Storage Spaces Direct drive-history counters?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-195-interpret-s2d-drive-history-at-the-device-measurement-boundary/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:56+00:00
- Modified: 2026-09-08T18:26:32+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which parts of the I/O path are represented by Storage Spaces Direct drive-history counters?

## Potentially affected

Administrators interpreting physical-drive performance history in Storage Spaces Direct.

## DSE recommendation

Record the drive identity and measurement boundary alongside each performance finding.

## Article

## Source facts

Microsoft provides drive history for devices in the cluster storage subsystem, excluding operating-system boot drives. The IOPS, throughput, and latency series come from the connected server’s Physical Disk counters, measured by partmgr.sys. They exclude much of the Windows software stack and network traversal. The values cover the whole interval: Microsoft’s example averages thirty operations in a ten-second interval as three operations per second. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/storage-spaces/performance-history-for-drives).

## Applicability

Identify the physical drive, connected server, metric, time interval, and application event. Distinguish the device-level observation from an end-to-end application response measurement before attributing a delay.

## DSE recommendation

Record the drive identity and measurement boundary alongside each performance finding. Correlate device observations with workload and network evidence from the same period. Ask the investigator to state whether a value is an interval average or another aggregation before comparing it with a threshold.

## Verification

Check the requested drive’s series and timestamps and compare them with the planned measurement interval. Investigate a high device latency alongside the remaining I/O path rather than assigning the whole application delay to that drive. Preserve missing history or an excluded boot device as a scope limitation.

## Official references

[Microsoft Learn: Performance history for drives](https://learn.microsoft.com/en-us/windows-server/storage/storage-spaces/performance-history-for-drives). Source reviewed September 8, 2026.

## Primary reference

- Name: Performance history for drives
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/storage-spaces/performance-history-for-drives
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Interpret S2D drive history at the device measurement boundary,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-195-interpret-s2d-drive-history-at-the-device-measurement-boundary/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
