Splunk AppDynamics

Health Rule - Wait time after violation

Benjamin_Andres
New Member

Hello Everyone,

Looking for a little clarity on how to best use the "wait time after violation" option when constructing a health rule.

Our thought was that we did not want teams to receive alerts for the same issue, so we tried to set the value at 1440 (one day) so the team would only get one alert per day, until it resolution.

I think this may be causing an issue though, we had a brief violation of a rule yesterday evening at 5 pm cst, but then the value went back to being underneath the threshold (no longer violating). Even though it's been 22 hours since the violation, the health rule is still showing that its violating.

I believe having "wait time after violation" set to 24 hours, it is not allowing the health rule to re-evaluate its status. is that how it is working? I am just trying to gain confidence in how it is meant to operate.

Any input is greatly appreciated!

(Images attached for reference)image.pngLast violation - 22 hours agoimage.pnglast 1 hour - well under thresholdimage.pngwait time after violation

Labels (3)
0 Karma

Satbir_Singh
Path Finder

Hi,

HR are evaluated every minute, please read the info on the right side after entering the value. Seems like we are missing something here.image.png

Thanks,
Satbir Singh

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...