What I want to do is to make it alert if I receive <1000 emails (WARNING) and <500 emails (CRITICAL) but I'm receiving more than the 1000 threshold so it shouldn't be sending alerts. Not sure why this is happening.
Windows Event Log Threshold Alerting came back with a CRITICAL state at
The alert was processed with the following thresholds:
• Lookback period: 60m
• Warning: 1000
• Critical: 500
Here is the full alert output:
CRITICAL: 14884 matching entries found |logs=14884;1000;500
See the last 60m in the Nagios Log Server dashboard.
Nagios Log Server
If you want to receive Alerts for less than the thresholds, you would have to edit the Alert and add a colon on the end of the thresholds line the example below.