Create operation and endpoint rules to group related requests

Learn what operation and endpoint rules are in Splunk APM and how to create them.

Use operation and endpoint rules to group and more efficiently monitor related requests.

Operation rules group operations that share a common prefix. You can use operation rules to simplify operation names, control cardinality costs in Splunk APM, and more efficiently monitor groups of related operations. Operation rules are applied before endpoint rules, and changes in operation rules will affect endpoints.

Endpoint rules group endpoints that start with, contain, or match a given string. You can use endpoint rules to modify and rename endpoints to align to your analytical needs and naming conventions. Endpoint rules support more targeted analysis with endpoint-specific metrics and business workflows.

Operation and endpoint rules are trace-level modifications that affect how operations and endpoints appear across Splunk APM, such as in the trace view, Tag Spotlight, and the Endpoints tab in the service view. They also affect the business workflows that are generated if your business workflow rules are based on endpoints.

Prerequisite

Learn about the prerequisite for creating operation and endpoint rules in Splunk APM.

You must have the admin role to configure operation and endpoint rules.

Create an operation rule

Learn how to create an operation rule in Splunk APM.

Complete the following steps to create a new operation rule in Splunk APM.
  1. From the Splunk Observability Cloud main menu, select Settings, then APM operation and endpoint configuration.
  2. The Operation configuration tab is selected by default. Select Create grouping rule(s).
  3. Follow the on-screen instructions to create the rule.
  4. Select Create to save your changes and apply the rule.

Create an endpoint rule

Learn how to create an endpoint rule in Splunk APM.

Complete the following steps to create a new endpoint rule in Splunk APM.
  1. From the Splunk Observability Cloud main menu, select Settings, then APM operation and endpoint configuration.
  2. Select the Endpoint configuration tab.
  3. Select Create endpoint rules for a service.
  4. Follow the on-screen instructions to create the rule.
  5. Select Add rule.
  6. If needed, adjust the priority of the new rule in the table. Rules are applied in the priority order defined in the table. By default, the newest rule has the highest priority.
  7. Select Create endpoint rules to create and apply the rule.

Next steps

Learn what you can do after you create operation and endpoint rules in Splunk APM.

After you create operation and endpoint rules, you can: