Splunk AppDynamics

Healthrule against errors based on Baseline does not evaluate

CommunityUser
Splunk Employee
Splunk Employee

 Hi,

I havea health rule defined against a set of Business Transactions based on the 'Business Transaction name contains' pattern. This will look for around 30 Business transactions to evaluate the policy. 

Now my Critical / warning conditions are validated against standard deviation on Dynamic Baseline and for metric 'Errors per minute'. Please find snapshot for better insight. 

None of the business transactions are getting evaluated under this health rule. Any suggestions?

Labels (1)
0 Karma

Pratik_Maskey
Communicator

Might be the baseline condition is not evaluating, you are using baseline of last 30 days. Could you try with any simple condition except baseline.

Please refer following document regarding baseline calculations - 

https://docs.appdynamics.com/display/PRO44/Dynamic+Baselines

If you setup HR against baseline's standred deviation(stdDev) comparison, then it works as:
X(for that data point the value of metric as configured in HR) > (Baseline (selected baseline)+ by Y stdDev)

Please refer following screenshot.

image.png

0 Karma

CommunityUser
Splunk Employee
Splunk Employee

These baselines are working flawlessly for other metrics as I mentioned earlier, but just the Errors per min doesn't have it evaluated as expected. And to answer your point, yes I have tried it with using just a 'Specific Value' metric on the Critical condition and it worked just fine.

Also, even before evaluating, I would expect the baseline to show on the graphs from metric browser, but the baseline for Errors per min is always overlapped by current value, which as per my understanding, is that the baseline os not working for Errors per min. Please find attached graphs.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...