AppD Archive

Custom Health rule not getting evaluated

Hariraj_J
Path Finder

Hi,

I have created a custom health rule "Overall Health" attached but for some reason it is not getting evaluated and not firing. Can you please let me know if i need to change anything in the configuration.

Thanks,

Hari

0 Karma
1 Solution

Hariraj_J
Path Finder

Thanks all found the issue i was using the incorrect metric hence it was not working.

View solution in original post

0 Karma

Saradhi_Pothara
Communicator
Could you check the underlying metric values and see if the HR is supposed to violate?
0 Karma

Hariraj_J
Path Finder

Yes I have verified that it should be evaulated and should have raised an alert, for example the memory utilization parameter is warning and the same rule added in my health rule along with other parameters is not triggering.

0 Karma

CommunityUser
Splunk Employee
Splunk Employee

instead of xml, can you please attach the screen shots of

1. Metric browser which shows that violation should occur

2. screen shot of the health check rule config page where you actually set the thresholds/conditions.

0 Karma

Hariraj_J
Path Finder

Thanks all found the issue i was using the incorrect metric hence it was not working.

0 Karma

CommunityUser
Splunk Employee
Splunk Employee

Which of the rules from your overall health rule is the one that you think should be evaluated?

The best way to check if the condition is even violated is to check for that same metrics in metric browser and checking if the values cross the threshold that you have set?

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...