How an outage is confirmed before you are alerted
The exact path from one failed check to an incident and a notification: confirmation runs, confidence labels, probe correlation, flap protection and what each one means for the alert you receive.
By the UptimeMonitor360 team · updated
One failure is an observation, not an incident
Every check result is written with its outcome (up, down, degraded or unknown), the error code and the evidence that justifies it. A single failing result changes the monitor's observed state but does not open an incident on its own: transient network blips from a single probe location are the most common source of false alerts.
Confirmation runs
When a primary check fails, the scheduler creates a confirmation run for the same monitor. The confirmation is executed as soon as a probe claims it, independently of the regular interval. Only when the confirmation fails too does the state machine open an incident. The incident records both results, so you can see the first failure and the confirmation side by side on the timeline.
Confidence labels
Each incident carries a confidence label. "Confirmed" means the failure was reproduced by a confirmation run. "Probe suspected" means that, inside a three-minute window, at least five monitors on the same probe failed while monitors on other probes stayed up, so the probe itself is the likelier cause; such incidents are opened at informational severity and are not escalated. "First observation" marks the first result of a brand-new monitor, which never pages anyone.
Flap protection
A monitor that alternates between up and down within a short window is flapping. Flap protection holds the monitor in its current incident instead of opening and closing a new one on every swing, and the incident timeline shows the swings as events. You keep one incident with a complete history instead of a flood of alerts.
Severity and escalation
Incidents inherit the severity configured on the monitor (critical, high, medium, low, informational). Notification rules decide who hears about an incident immediately; escalation policies decide who hears next, after how many minutes, and how often the reminder repeats until someone acknowledges. Quiet hours suppress the escalation steps you configure, never the incident itself.
What the notification contains
The message names the monitor, the error code and message, the observed latency, the confidence label and the probe region, and links to the incident. Acknowledging the incident stops repeats and escalations; resolving happens automatically when a check succeeds again and is recorded with the recovery evidence.
Maintenance windows
Checks continue during a maintenance window but their outcomes are recorded as maintenance and never open incidents or count against availability. A window that starts while an incident is open does not close it; it stops new incidents from opening.
Monitor the behaviour described here continuously: start free with 5 monitors or try the free tools.