I have a monitor that just returns a HostReachable = 1 if it successful. I have it running once a minute. I am trying to figure out how to create an incident where the evaluation would be for 5 min, and if the Host is unreachable 3 out of the 5 tries, then generate the alert.
I was thinking I could do this my selecting "Aggregation" = Min, but I don't understand the "Logic" column, I can't edit it.
Any help on this is much appreciated,
Thanks in advance,
The logic column only matters if you have multiple measures being considered; and for monitors it is pretty much irrelevant because by design you can't base an incident off of the measures from different monitors. Each measure will be treated individually.
Regardless, for your need though you don't work with individual runs of the monitor directly so you can't explicitly say "3 out of 5 runs" but what you can do is just use the average aggregation with a 5 minute timeframe. Since host reachable will be either 1 or 0 you would enter in a threshold of 2/5 = .4 .
Runs: 1(pass) + 1(pass)+ 0(fail)+ 0(fail)+ 0(fail)= 2 divided by 5 total runs = .4
This would essentially be the same as saying trigger if 3 out of 5 runs fail (i.e. return 0 for host reachable).