Dependent Alert Mapping - defining the originating alert
In the current Dependent Alert Mapping feature, alert suppression will only take place if an upstream device has an alert for the Ping or Host Status datasources for overall reachability.
There are many cases where the upstream device will not be completely down, and instead will have an alert for an interface or BGP peer going down. This will still impact downstream devices, but Dependent Alert Mapping does not work correctly in these cases because the upstream device was not technically "down".
I would like to request that the Dependent Alert Mapping feature give us the option to allow other types of alerts be considered when it determines what alert is "Originating" vs "Dependent".
Ideally we would be able to define this when we are defining entry points. We could have the option of only using Ping or Host Status like the feature does today, or we could choose to select our own datasources for determining what the "Originating" alert is.
This would allow us to get a lot more granular and make the feature a lot more flexible/powerful than it is today.