Splunk AppDynamics

Health Rule - Wait time after violation

Benjamin_Andres
New Member

Hello Everyone,

Looking for a little clarity on how to best use the "wait time after violation" option when constructing a health rule.

Our thought was that we did not want teams to receive alerts for the same issue, so we tried to set the value at 1440 (one day) so the team would only get one alert per day, until it resolution.

I think this may be causing an issue though, we had a brief violation of a rule yesterday evening at 5 pm cst, but then the value went back to being underneath the threshold (no longer violating). Even though it's been 22 hours since the violation, the health rule is still showing that its violating.

I believe having "wait time after violation" set to 24 hours, it is not allowing the health rule to re-evaluate its status. is that how it is working? I am just trying to gain confidence in how it is meant to operate.

Any input is greatly appreciated!

(Images attached for reference)image.pngLast violation - 22 hours agoimage.pnglast 1 hour - well under thresholdimage.pngwait time after violation

Labels (3)
0 Karma

Satbir_Singh
Path Finder

Hi,

HR are evaluated every minute, please read the info on the right side after entering the value. Seems like we are missing something here.image.png

Thanks,
Satbir Singh

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...