Splunk AppDynamics

Health Rule - Wait time after violation

Benjamin_Andres
New Member

Hello Everyone,

Looking for a little clarity on how to best use the "wait time after violation" option when constructing a health rule.

Our thought was that we did not want teams to receive alerts for the same issue, so we tried to set the value at 1440 (one day) so the team would only get one alert per day, until it resolution.

I think this may be causing an issue though, we had a brief violation of a rule yesterday evening at 5 pm cst, but then the value went back to being underneath the threshold (no longer violating). Even though it's been 22 hours since the violation, the health rule is still showing that its violating.

I believe having "wait time after violation" set to 24 hours, it is not allowing the health rule to re-evaluate its status. is that how it is working? I am just trying to gain confidence in how it is meant to operate.

Any input is greatly appreciated!

(Images attached for reference)image.pngLast violation - 22 hours agoimage.pnglast 1 hour - well under thresholdimage.pngwait time after violation

Labels (3)
0 Karma

Satbir_Singh
Path Finder

Hi,

HR are evaluated every minute, please read the info on the right side after entering the value. Seems like we are missing something here.image.png

Thanks,
Satbir Singh

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...