Events Reference
This page lists these types of events generated in Splunk AppDynamics:
- Event types that are common to the platform, such as UI, configuration, and licensing-related events
- Events generated by the alert and response system
- Application monitoring events
Information on event types that are specific to a platform module, if available, appears with the module-specific documentation. For example, Database Agent events are listed on Database Agent Events Reference.
Event types listed here that are not visible in the UI can be retrieved using the Splunk AppDynamics REST API.
| Event | Description | Category | Visible in UI | More Info | 
|---|---|---|---|---|
| ACTIVITY_TRACE | The agent sent an internal event containing activity traces. Activity traces enable the tracing of a code path that passes through a specified class/method. The App Agent for Java uses them to provide object instance tracking (OIT) and automatic leak detection (ALD) | Splunk AppDynamics Data | No | Java Memory Leaks, Object Instance Tracking for Java | 
| ADJUDICATION_CANCELLED | A designated approver has canceled a thread dump or remediation action that was triggered by a policy. | No | Actions Requiring Approval, Policies | |
| AGENT_ADD_BLACKLIST_REG_LIMIT_REACHED | The agent Application Diagnostic Data (ADD) blocklist registration limit has been reached. | No | Customize System Notifications | |
| AGENT_ASYNC_ADD_REG_LIMIT_REACHED | The agent async Application Diagnostic Data (ADD) registration limit has been reached. | No | ||
| AGENT_CONFIGURATION_ERROR UI Display name: Agent Configuration Error | An agent configuration error has been detected. | Splunk AppDynamics Configuration Warnings | Yes | Troubleshoot .NET Agent Issues | 
| APPLICATION_CRASH UI Display name: Application Crash | A crash has been detected for a JVM. The crash log file is updated. | Application Changes | Yes | |
| AGENT_DIAGNOSTICS UI Display name: Agent Diagnostics | Diagnostic information concerning agent activity, such as business transaction overflow or HTTP error code diagnostics, has been sent. | Splunk AppDynamics Data | No | |
| AGENT_ERROR_ADD_REG_LIMIT_REACHED | The agent error Application Diagnostic Data (ADD) registration limit has been reached. | No | ||
| AGENT_EVENT UI Display name: Agent Event | Generic internal event. This event type is also used for all Database Agent events with a case-specific message attached. | Splunk AppDynamics Internal Diagnostics | No | Database Agent Events Reference | 
| AGENT_METRIC_BLACKLIST_REG_LIMIT_REACHED | The agent metric blocklist registration limit has been reached. | No | Metrics Limits | |
| AGENT_METRIC_REG_LIMIT_REACHED | The agent metric registration limit has been reached. | No | Metrics Limits | |
| AGENT_STATUS UI Display name: Agent Enabled / Disabled | The agent has been enabled or disabled. | Splunk AppDynamics Internal Diagnostics | No | Manage App Agents | 
| ALREADY_ADJUDICATED | A designated approver has previously approved or canceled a thread dump or remediation action that was triggered by a policy. | No | Actions Requiring Approval, Policies | |
| ANOMALY_CANCELLED_CRITICAL UI Display name:Anomaly Canceled - Critical | The critical anomaly event is cancelled because of the insufficient data. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_ CANCELLED_WARNING UI Display name:Anomaly Canceled - Warning | The warning anomaly event is cancelled because of the insufficient data. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_CLOSE_CRITICAL UI Display name:Anomaly Ended - Critical | The critical severity anomaly event is closed and the entity is back to normal. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_CLOSE_WARNING UI Display name:Anomaly Ended - Warning | The warning anomaly event is closed and the entity is back to normal. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_DOWNGRADED UI Display name:Anomaly Downgraded - Critical to Warning | The severity of the open anomaly event is downgraded from critical to warning. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_OPEN_CRITICAL UI Display name:Anomaly Started - Critical | The anomaly event began with a critical severity. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_OPEN_WARNING UI Display name:Anomaly Started - Warning | The anomaly event began with a warning severity. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_UPGRADED UI Display name:Anomaly Upgraded - Warning to Critical | The severity of the open anomaly event is upgraded from warning to critical. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_UPDATED_CRITICAL UI Display name:Anomaly Updated: Critical | The details of the critical anomaly event are updated. | Alerting event | Yes | Anomaly Detection | 
| ANOMALY_UPDATED_WARNING UI Display name:Anomaly Updated: Warning | The details of the warning anomaly event are updated. | Alerting event | Yes | Anomaly Detection | 
| APPDYNAMICS_DATA | Events used to send data from the agent to the Controller, then to the UI. Events such as BTOverflowDetails and MemoryLeakDiagnostics should be moved into this bucket. | Splunk AppDynamics Data | No | |
| APPDYNAMICS_INTERNAL_DIAGNOSTICS | Internal diagnostics events. | Splunk AppDynamics Internal Diagnostics | No | |
| APPLICATION_CONFIG_CHANGE UI Display name: Application Configuration Change | Application configuration has been changed interactively by the user or through the REST API. Note: This event type is automatically archived. | Application Changes | Yes | |
| APPLICATION_DEPLOYMENT UI Display name: Application Deployment | An application has been deployed. | Application Changes | Yes | |
| APPLICATION_DISCOVERED UI Display name: New Application Discovered | A new application has been added to the Controller. | Discovery | Yes | Policies | 
| APPLICATION_ERROR UI Display name: Application Server Exception | An application error has been detected. | Errors | Yes | |
| APP_SERVER_RESTART UI Display name: App Server Restart | An application server has been restarted. | Application Changes | Yes | |
| AZURE_AUTO_SCALING | An internal event that reports Azure auto-scaling progress to the UI. Seen at the bottom of the Azure auto-scaling screen. | Splunk AppDynamics Data | No | |
| BACKEND_DISCOVERED UI Display name: New Backend Discovered | A new backend has been added to the application. | Discovery | Yes | Policies | 
| BT_DISCOVERED UI Display name: New Business Transaction Discovered | A new business transaction has been added to the application. | Discovery | Yes | Policies | 
| BUSINESS_ERROR UI Display name: Business Error | A business error has been detected. | Errors | Yes | |
| CLR_CRASH UI Display name: CLR Crash | A CLR crash has occurred. | AD Infrastructure events | Yes | |
| CONTROLLER_AGENT_VERSION_INCOMPATIBILITY UI Display name: Agent Version is newer than Controller version | The agent version is newer than the Controller version. | Splunk AppDynamics Configuration Warnings | Yes | Agent and Controller Tenant CompatibilityAgent and Controller Tenant Compatibility | 
| CONTROLLER_ASYNC_ADD_REG_LIMIT_REACHED | The Controller limit for registering async Application Diagnostic Data (ADDs) for this account has been reached. | No | Customize System Notifications | |
| CONTROLLER_COLLECTIONS_ADD_REG_LIMIT_REACHED | The Controller COLLECTIONS ADD registration limit for the account has been reached. | No | Customize System Notifications | |
| CONTROLLER_ERROR_ADD_REG_LIMIT_REACHED | The limit for registering error Application Diagnostic Data (ADDs) for the account has been reached. | No | Customize System Notifications | |
| CONTROLLER_EVENT_UPLOAD_LIMIT_REACHED | The limit on the number of events per minute that can be uploaded to the controller for the account has been reached. | No | Customize System Notifications | |
| CONTROLLER_MEMORY_ADD_REG_LIMIT_REACHED | The Controller MEMORY ADD registration limit for the account has been reached. | No | Metrics Limits,Customize System Notifications | |
| CONTROLLER_METADATA_REGISTRATION_LIMIT_REACHED | The Controller metadata registration limit for the account has been reached. | No | Business Transactions,Organize Business Transactions,Customize System Notifications | |
| CONTROLLER_METRIC_DATA_BUFFER_OVERFLOW | The Controller metric data buffer has overflown. Now dropping metric data. | Metrics Limits,Customize System Notifications | ||
| CONTROLLER_METRIC_REG_LIMIT_REACHED | The limit for registering metrics for the account has been reached. | No | Metrics Limits,Customize System Notifications | |
| CONTROLLER_PSD_UPLOAD_LIMIT_REACHED | The PSD limit for the account has been reached. | No | Customize System Notifications | |
| CONTROLLER_RSD_UPLOAD_LIMIT_REACHED | The request segment data (RSD) limit for the account has been reached. | No | Customize System Notifications | |
| CONTROLLER_SEP_ADD_REG_LIMIT_REACHED | The limit for the Controller SERVICE_ENDPOINT ADD registration for the account has been reached. | No | Customize System Notifications | |
| CONTROLLER_STACKTRACE_ADD_REG_LIMIT_REACHED | The limit for registering StackTrace ADDs for the account has been reached. | No | Customize System Notifications | |
| CONTROLLER_TRACKED_OBJECT_ADD_REG_LIMIT_REACHED | The Controller TRACKED_OBJECT ADD registration limit for the account has been reached. | No | Customize System Notifications | |
| CUSTOM UI Display name: Depends on the event. | These are custom events thrown by REST API calls or Machine Agent API calls. | Custom Event | Depends on the event. | Create Events | 
| CUSTOM_ACTION_END | A custom action has ended. | No | Custom Actions,Policies | |
| CUSTOM_ACTION_FAILED | A custom action has failed. | No | Custom Actions,Policies | |
| CUSTOM_ACTION_STARTED | A custom action has started. | No | Custom Actions,Policies | |
| CUSTOM_EMAIL_ACTION_END | A custom email action ended. | No | Diagnostic Actions, Policies | |
| CUSTOM_EMAIL_ACTION_FAILED | A custom email action failed. | No | Diagnostic Actions, Policies | |
| CUSTOM_EMAIL_ACTION_STARTED | A custom email action started. | No | Diagnostic Actions,Policies | |
| DB_SERVER_PARAMETER_CHANGE | The DBMS server parameters have been changed. | DB Agent Event | ||
| DEADLOCK UI Display name: Code Deadlock | The agent has detected code deadlock. | Code Problems | Yes | Code Deadlocks for Java | 
| DEV_MODE_CONFIG_UPDATE | The Dev Mode Config has been updated. This is fired from the agent and the Controller. | |||
| DIAGNOSTIC_SESSION UI Display name: Diagnostic Session | A diagnostic session has started. | Splunk AppDynamics Internal Diagnostics | No | Diagnostic Sessions | 
| DISK_SPACE UI Display name: Controller Disk Space Low | The controller is running out of disk space. | Splunk AppDynamics Configuration Warnings | Yes | Controller System Requirements, Database Size and Data Retention | 
| EMAIL_ACTION_FAILED | Email action has failed. | Notification Actions | ||
| EMAIL_SENT | Email was sent to notify the recipient of an event. | No | Notification Actions | |
| EUM_CLOUD_BROWSER_EVENT | A browser snapshot was stored in the database. | No | End User Monitoring, Browser Snapshots | |
| EUM_CLOUD_SYNTHETIC_BROWSER_EVENT | A synthetic browser snapshot was stored in the database. | No | End User Monitoring, Browser Snapshots | |
| EUM_CLOUD_SYNTHETIC_ERROR_EVENT | A synthetic error event will occur on the first occurrence of an error session for a synthetic job. | End User Monitoring | ||
| EUM_CLOUD_SYNTHETIC_CONFIRMED_ERROR_EVENT | A synthetic error event is confirmed. When we see an error session again when we retry the job. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_ONGOING_ERROR_EVENT | A synthetic ongoing error event was detected when the error was confirmed. Sessions will be in error states. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_HEALTHY_EVENT | A synthetic event was reported healthy when a job is transited from any other state to a healthy state. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_WARNING_EVENT | When a synthetic job session status is WARNING, the detected warning is reported. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_CONFIRMED_WARNING_EVENT | A synthetic warning was confirmed. When we see a warning session again when we retry the job. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_ONGOING_WARNING_EVENT | A synthetic ongoing warning detection is reported when the warning is confirmed. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_PERF_WARNING_EVENT | A synthetic ongoing warning detection is reported when performance breaches/exceeds the threshold. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_PERF_CONFIRMED_WARNING_EVENT | A synthetic performance warning detection is reported when we see a warning session again and perform a retest or see consecutive failures of the job (This depends on the configurations). | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_PERF_ONGOING_WARNING_EVENT | A synthetic ongoing warning event is reported and confirmed. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_PERF_HEALTHY_EVENT | A synthetic healthy performance event was detected and is reported when a job is transited from any other state to a healthy state. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_PERF_CRITICAL_EVENT | A synthetic critical performance event was detected and is reported when performance for critical event breaches/exceeds the threshold. | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_PERF_CONFIRMED_CRITICAL_EVENT | A synthetic critical performance event was detected and is reported when we see a critical session again and retest or see consecutive failures of the job (This depends on the configurations). | No | End User Monitoring | |
| EUM_CLOUD_SYNTHETIC_PERF_ONGOING_CRITICAL_EVENT | A synthetic ongoing critical event was detected and the event is confirmed. | No | End User Monitoring | |
| EUM_INTERNAL_ERROR | An internal EUM error has occurred. | No | End User Monitoring | |
| HTTP_REQUEST_ACTION_END | An HTTP request action ended. | No | Diagnostic Actions,Policies | |
| HTTP_REQUEST_ACTION_FAILED | An HTTP request action failed. | No | Diagnostic Actions,Policies | |
| HTTP_REQUEST_ACTION_STARTED | An HTTP request action started. | No | Diagnostic Actions,Policies | |
| INFO_INSTRUMENTATION_VISIBILITY UI Display name: Bytecode Transformer Log | Information was written to the Bytecode Transformer Log. This log contains information associated with the Splunk AppDynamics bytecode instrumentation (BCI) engine. | Splunk AppDynamics Internal Diagnostics | No | Request Agent Log Files, App Agent Node Properties Reference | 
| INTERNAL_UI_EVENT UI Display name: Controller API Call Threw an Exception | These are the XResponder.handleGeneralServerFaultEvent events. | Splunk AppDynamics Internal Diagnostics | No | |
| KUBERNETES UI Display name: Cluster Event | The two Kubernetes event types, normal events and warning events, thrown by the Cluster Agent. | Kubernetes Events | Yes | Monitor Kubernetes Events | 
| LICENSE UI Display name: License Expired | The Splunk AppDynamics license has expired. | Splunk AppDynamics Configuration Warnings | Yes | License Information | 
| MACHINE_AGENT_LOG | The Machine Agent is now logging information. | Splunk AppDynamics Data | ||
| MACHINE_DISCOVERED UI Display name: New Machine Discovered | A new machine has been added to the application. | Discovery | Yes | Policies | 
| MEMORY UI Display name: AppDynamics Data | Events for automatic leak detection and custom memory structures. | Splunk AppDynamics Data | No | |
| MEMORY_LEAK_DIAGNOSTICS | The agent sends this internal event with memory leak data. The UI uses this on the memory monitoring screens in the node dashboards. | No | ||
| MOBILE_CRASH_IOS_EVENT | An iOS mobile application crash has arrived at the Controller. | No | Crashes | |
| MOBILE_CRASH_ANDROID_EVENT | An Android mobile application crash has arrived at the Controller. | No | Crashes | |
| MOBILE_NEW_CRASH_EVENT, SLOW, VERY_SLOW, STALL | An Android mobile application crash has arrived at the Controller with slow, very slow, or stalled status. | No | Crashes | |
| NETWORK UI Display name: Network | The log data provided by the NPM Agent has been logged by the NPM Dynamic service. | Yes | ||
| NODE_DISCOVERED UI Display name: New Node Discovered | A new node has been added to the application. | Discovery | Yes | Policies | 
| NORMAL | A business transaction is normal (not slow, very slow or stalled). | No | Transaction Thresholds, Dynamic Baselines | |
| OBJECT_CONTENT_SUMMARY | The agent sent an internal event with object content summary for collections, caches, etc. | Splunk AppDynamics Data | No | |
| POLICY_CANCELED_CRITICAL UI Display name: Health Rule Violation Canceled - Critical | A health rule violation, based on a status of critical, was canceled. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_CANCELED_WARNING UI Display name: Health Rule Violation Canceled - Warning | A health rule violation, based on a status of warning, was canceled. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_CLOSE_CRITICAL UI Display name: Health Rule Violation Ended - Critical | A health rule violation, based on a status of critical, ended. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_CLOSE_WARNING UI Display name: Health Rule Violation Ended - Warning | A health rule violation, based on a status of warning, ended. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_CONTINUES_CRITICAL UI Display name: Health Rule Violation Continues - Critical | After the initial POLICY_OPEN_CRITICAL event, an event generated to indicate the continuation of the health rule violation at the critical level. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_CONTINUES_WARNING UI Display name: Health Rule Violation Continues - Warning | After the initial POLICY_OPEN_WARNING event, an event generated to indicate the continuation of the health rule violation at the warning level. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_DOWNGRADED UI Display name: Health Rule Violation Downgraded - Critical to Warning | A health rule violation was downgraded from critical to warning. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_OPEN_CRITICAL UI Display name: Health Rule Violation Started - Critical | A critical health rule was violated. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_OPEN_WARNING UI Display name: Health Rule Violation Started - Warning | A warning health rule was violated. | Policy Violations | Yes | Health Rules, Policies | 
| POLICY_UPGRADED UI Display name: Health Rule Violation Upgraded - Warning to Critical | A health rule violation was upgraded from warning to critical. | Policy Violations | Yes | Health Rules, Policies | 
| RESOURCE_POOL_LIMIT UI Display name: Resource Pool Limit Reached | A resource pool limit, such as a thread pool or connection pool, has been reached. | Code Problems | Yes | Remediation Actions,Policies | 
| RUNBOOK_DIAGNOSTIC SESSION_END | A diagnostic session that was started by a diagnostic action triggered by a policy, has ended. | No | Diagnostic Sessions, Diagnostic Actions,Policies | |
| RUNBOOK_DIAGNOSTIC SESSION_FAILED | A diagnostic session that was started by a diagnostic action triggered by a policy failure. | No | Diagnostic Sessions,Diagnostic Actions,Policies | |
| RUNBOOK_DIAGNOSTIC SESSION_STARTED | A diagnostic session that was started by a diagnostic action triggered by a policy, session started. | No | Diagnostic Sessions,Diagnostic Actions,Policies | |
| RUN_LOCAL_SCRIPT_ACTION_END | A local script that was started by a remediation action triggered by a policy, has ended. | No | Remediation Actions,Policies | |
| RUN_LOCAL_SCRIPT_ACTION_FAILED | A local script that was started by a remediation action triggered by a policy, has failed. | No | Remediation Actions,Policies | |
| RUN_LOCAL_SCRIPT_ACTION_STARTED | A local script that was started by a remediation action triggered by a policy, has started. | No | Remediation Actions,Policies | |
| SERVICE_ENDPOINT_DISCOVERED UI Display name: New Service Endpoint Discovered | A new service endpoint has been added to the application. | Discovery | Yes | Policies | 
| SLOW UI Display name: Slow Transactions | A business transaction is now slow. | Slow Transactions | Yes | Troubleshoot Slow Response Times, Transaction Thresholds | 
| SMS_SENT | An SMS was sent to notify the recipient of an event. | No | Notification Actions | |
| STALL | A business transaction has stalled. | Slow Transactions | Yes | Troubleshoot Slow Response Times, Transaction Thresholds | 
| SYSTEM_LOG UI Display name: Automation Event | Thrown when events occur during workflow execution. | Splunk AppDynamics Data | Yes | |
| THREAD_DUMP_ACTION_END | A thread dump action ended. | No | Diagnostic Actions,Policies | |
| THREAD_DUMP_ACTION_FAILED | A thread dump action failed. | No | Diagnostic Actions,Policies | |
| THREAD_DUMP_ACTION_STARTED | A thread dump action started. | No | Diagnostic Actions,Policies | |
| TIER_DISCOVERED UI Display name: New Tier Discovered | A new tier has been added to the application. | Discovery | Yes | Policies | 
| VERY_SLOW UI Display name: Very Slow Transactions | A business transaction is now very slow. | Slow Transactions | Yes | Troubleshoot Slow Response Times, Transaction Thresholds | 
| WARROOM_NOTE | A War Room Note has been added. | Virtual War Rooms |