Splunk AppDynamics

Health Rule - Wait time after violation

Benjamin_Andres
New Member

Hello Everyone,

Looking for a little clarity on how to best use the "wait time after violation" option when constructing a health rule.

Our thought was that we did not want teams to receive alerts for the same issue, so we tried to set the value at 1440 (one day) so the team would only get one alert per day, until it resolution.

I think this may be causing an issue though, we had a brief violation of a rule yesterday evening at 5 pm cst, but then the value went back to being underneath the threshold (no longer violating). Even though it's been 22 hours since the violation, the health rule is still showing that its violating.

I believe having "wait time after violation" set to 24 hours, it is not allowing the health rule to re-evaluate its status. is that how it is working? I am just trying to gain confidence in how it is meant to operate.

Any input is greatly appreciated!

(Images attached for reference)image.pngLast violation - 22 hours agoimage.pnglast 1 hour - well under thresholdimage.pngwait time after violation

Labels (3)
0 Karma

Satbir_Singh
Path Finder

Hi,

HR are evaluated every minute, please read the info on the right side after entering the value. Seems like we are missing something here.image.png

Thanks,
Satbir Singh

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...