Could you post a chart of the measures being used in the incident during when you think they should be violating the threshold? Additionally any of the incident configuration (e.g. aggregations, measure details, and timeframe) would be required to look into this.
May be the reason is "smart alerting".
Are these hosts in one incident? Or you have 4 incidents for each host?
Similar problem was here: https://answers.dynatrace.com/questions/96058/smar...
Turn smart alerting off (in Incident Rule Properties) if you need to receive the letter for each starting of incident.