Splunk AppDynamics

Health Rule - Affected Entities

Daniel_Nash
Engager

When setting Affected Entities for Health Rules there is an option to state:

"Business Transactions matching the following criteria"

I have used this to exclude certain business transactions and set it to "Business Transactions matching the following criteria" NOT contains "_CatchAll"

I would like to exclude business transactions that have _CatchAll or GetCSS.aspx in the BT name - is this possible?

Can I simply set it to "Business Transactions matching the following criteria" NOT contains "_CatchAll,GetCSS.aspx"?

Labels (3)
0 Karma
1 Solution

Morelz
Motivator

Hi

As the health rule does not have the option to use the "in list" condition, you will have to revert to regex

Just a simple test would look like this, that would match any BT name that does not have the following 2 words in the name

^(?!.*(_CatchAll|GetCSS.aspx)).*$

Not exactly sure how AppD would want the syntax and if it will work as above, however this piece works in normal regex

Ciao

View solution in original post

Morelz
Motivator

Hi

As the health rule does not have the option to use the "in list" condition, you will have to revert to regex

Just a simple test would look like this, that would match any BT name that does not have the following 2 words in the name

^(?!.*(_CatchAll|GetCSS.aspx)).*$

Not exactly sure how AppD would want the syntax and if it will work as above, however this piece works in normal regex

Ciao

Daniel_Nash
Engager

Thanks - this is helpful

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...