AppD Archive

Health Rule data was not available

CommunityUser
Splunk Employee
Splunk Employee

Hi,

I have some Health Rule without evaluation.

The following picture show my configuration and the result (I obfuscated names for security reason):

image.jpeg

image.jpeg

The metric is "Error per Minute".

image.jpeg

The resuling looks like this:

image.jpeg

One node is evaluated and the other is not because there are no data available.

So I checked the metric browser:

image.jpeg

So in metric browser are data available but the health rule has no data. This seems a bit weird.

I was waiting more then 1 hour and the health rule still has no data available.

Is there a mistake in configuration?

thx for help

Regards,

Thomas

0 Karma

Arun_Dasetty
Super Champion

Hi Thomas,

 

We do see such behavior at random times that UI shows health unknown/grey color and doing browser refresh /screen refresh should help get the updated status as green in your case as the EPM metric value is not greater > 0 and count metric represents the number of such EPM metric reported to UI for current applicaiton. Hope that clarifies.

 

Regards,

Arun

0 Karma

CommunityUser
Splunk Employee
Splunk Employee

Hi Arun,

so in my case the health rule should be green for both node.

Even after browser refresh / re-open browser / logout-login is the health rules on one node unknown/grey.

So this is just an UI error and the internal health rule is green? Or is it possible that the internal health rule is red and the UI shows grey?

What happen with actions based on this health rule? 

Regards,

Thomas

0 Karma

Arun_Dasetty
Super Champion

Hi Thomas,

 

Can you check the actual status under TroubleShoot -> Health rule violations and i expect there is no associated violation during the time for which screenshot provided from metric browser to us as EPM < 1

 

Regards,

Arun

0 Karma

CommunityUser
Splunk Employee
Splunk Employee

There is no violation. But the status is grey... I do not know if it is red and the action does not work correctly.

So please confirm that this is just an error in UI.

Regards,

Thomas

0 Karma

Arun_Dasetty
Super Champion

Hi Thomas,

 

We confirm it is UI level cache issue on status icon but user should see no issues in other screens like TroubleShoot -> health rule violations (this screen should reflect actual violations), Hope it answers your query.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...