Splunk AppDynamics

How do I create health alert(s) about process state (running, or not) ?

pretzel2
Path Finder

We really love the AppD machine agent, which does a great job listing processes running on a virtual host.

How can we create health alerts that use the process running state?    We want to create an alert when a key process stops or goes down (unexpectedly). 

Labels (1)
0 Karma
1 Solution

Brian_Wheeldon
Contributor

Hi Walter,
There are a number of metrics available for every process, and depending on how you've configured the "Monitoring Mode", you'll see more as you enable "KPI", "Advanced", or "Diagnostic" detail.
 If you enable "Advanced" via configuration or interactively via the UI, you will see the process "Count" metric collected.
e.g. Application Infrastructure Performance|Root|Individual Nodes|cvpcclab|Hardware Resources|Process|tomcat9|Count

Your Health Rule should trigger when Count < 1, and "Evaluate true on no data" if you want to be alerted when the agent stops reporting to the Controller for any reason.

image.png
You will specify a Custom Metric Path for the metric, e.g. Hardware Resources|Process|tomcat9|Count

View solution in original post

Brian_Wheeldon
Contributor

Hi Walter,
There are a number of metrics available for every process, and depending on how you've configured the "Monitoring Mode", you'll see more as you enable "KPI", "Advanced", or "Diagnostic" detail.
 If you enable "Advanced" via configuration or interactively via the UI, you will see the process "Count" metric collected.
e.g. Application Infrastructure Performance|Root|Individual Nodes|cvpcclab|Hardware Resources|Process|tomcat9|Count

Your Health Rule should trigger when Count < 1, and "Evaluate true on no data" if you want to be alerted when the agent stops reporting to the Controller for any reason.

image.png
You will specify a Custom Metric Path for the metric, e.g. Hardware Resources|Process|tomcat9|Count

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...