We have configured an URL monitor to run every 10 minutes and created an incident rule and email action for the monitor. Evaluation timeframe is 10 s. When aggregation is 'first', no incident is triggered but it we change aggregation to 'last', an incident is triggered and email is sent. Can you please explain why aggregation must be 'last'? Thresholds for the three measures are configured.
The "last" aggregation consider the last PurePath from the transactions, so when evaluation timeframe see the last PurePath is violating the configured thresholds then it shoot an email immediately.
To add to the correct answer from Babar. I have a YouTube Tutorial where I explain how Incident Conditions are evaluated. I even use the same URL Monitor example for a live demo. feel free to check it out: https://www.youtube.com/watch?v=Ysh_HL8HDoA&list=P...