Check-aware normalization
RMON metadata becomes matcher-friendly labels for check ID, check type, target, agent, region and country. Existing labels, runbook URLs and source event links are preserved.
Alert lifecycle
Active failures are normalized to firing, while recovery values such as ok, recovered and resolved close the existing alert.
Recommended grouping
[
"rmon_check_id",
"rmon_check_type"
]
Reliable correlation
Use the same stable fingerprint for firing and recovery notifications. This prevents duplicate incidents and keeps the complete check history together.