Severity & cooldown
- Severity —
info,warning,error, orcritical. It labels the alert and drives styling, sound-alert thresholds, and triage. - Cooldown (minutes) — after a rule fires for a device, it won't fire again for that device until the cooldown elapses, even if the condition stays true. This prevents a flapping sensor from spamming you.
The cooldown is per device, not per rule. A rule that watches every device keeps a separate window for each one: two devices breaching the threshold are two alerts; the same device breaching again inside its window is still one. The one exception is a gateway outage — the devices marked offline because their gateway went down share the gateway's cooldown, so an offline rule sends one alert for the outage rather than one per device (see rules that fire on an event).
Choose a cooldown longer than the typical oscillation around your threshold. For a value that hovers near the limit, a 10–15 minute cooldown is usually right.