Splunk AppDynamics

Health rule Suppression

Sundarapandian_
Path Finder

Hello,

I have a healthrule suppression schedule enabled and it doesn't seem to be working as expected.

The requirement is to suppress or disable helathrule between 1 AM and 6 AM only on Sundays, and this the cron entry that i set up (see attached).

start time cron expression: * * 6 ? * 7

end time cron expression  : * * 1 ? * 7

If this is incorrect, please advise what needs to be modified. Thank you!

Labels (3)
0 Karma

Aniruddha_Salve
Engager

Hello,

Can you please mention the steps followed to achieve this.

Thank you.

0 Karma

millerep
Contributor

It's an old post, but essentially he's asking about how to do supress an action which is outlined in this document: https://docs.appdynamics.com/display/PRO45/Action+Suppression#ActionSuppression-ConfigureActionSuppr...

Once you're there, then follow his cron expression link above on what the syntax is.

You can also set this up when building your health rule as outlined in this document: https://docs.appdynamics.com/display/PRO45/Create+a+Health+Rule#CreateaHealthRule-Create_Manage_HRSc...

Which kind of has reverse logic. Usually you want the action to "start" when you want it to actually end supression, and then "end" when you want it to actually it to start, that way that "Health Rule" will only run everytime except the times you speecifically outlined to supress.

CommunityUser
Splunk Employee
Splunk Employee

I think you might have your start and end crossed so i switched them.  Also, for Sundays, shouldn't that be a '1' instead of a '7'?  Here's the result based on those adjustments.

start time cron expression: * * 1 ? * 1

end time cron expression  : * * 6 ? * 1

Here's a doc on cron format standards.

http://www.quartz-scheduler.org/documentation/quartz-2.1.x/tutorials/crontrigger

Sundarapandian_
Path Finder

Does anyone have an answer? 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...