Articles Rollup: how a state is worked out from what is beneath rules, updated 2026-09-28

Every object in the tree has a state, and each one is worked out from what sits directly beneath it. Rollup is where you say how. The same three settings appear at every level; only what is being counted changes:

On aRollup counts
SensorIts probe groups, each judging the sensor's readings on its own
DeviceIts sensors
GroupThe devices and groups in it
SiteIts groups

How the state is worked out

  1. Only those with an opinion are counted. Anything OK, WARN or CRIT is counted. Anything UNKNOWN, STALE or HELD, switched off, suspended, still a draft or outside its schedule is left out altogether: it is neither healthy nor failing, so it cannot drag the state either way. Where nothing is left to count and something beneath is HELD, cut off by something it depends on, the object is HELD too; see Dependencies. A sensor with Counts towards its parent's state cleared is left out of its device's count too.
  2. WARN and CRIT both count as failing.
  3. How many are failing puts the object in one of four buckets:
    • none failing: always OK
    • ANY: exactly one failing, and at least one other not
    • SOME: more than one failing, but not all
    • ALL: every one failing. With only one counted, one failing is all of them
  4. The bucket gives the state you chose for it, OK, WARN or CRIT.
  5. The state is never worse than the children. If the bucket says CRIT but none of the failing children is CRIT, the object is WARN. A device whose only problem is a warning never goes critical.

The settings

SettingWhat it does
ANY, SOME, ALLThe state for each bucket.
Minimum reportingBelow this many with an opinion, the state is UNKNOWN rather than a verdict reached from one straggler. On a sensor in three probe groups, 2 means one group on its own cannot decide.
Counts towards its parent's stateClear it to watch something without letting it condemn what it sits on. A certificate expiry warning is worth seeing, and is not the device being down.
Counts towards availability reportingClear it to keep the object out of availability figures, for something whose downtime is expected or not your concern.

The defaults

ObjectANYSOMEALL
Sensor, group, siteOKWARNCRIT
DeviceWARNCRITCRIT

A device with one failing sensor needs a look, and with more than one is in trouble, so a device defaults to WARN on ANY and CRIT on SOME and ALL. Keep each setting at least as bad as the one before it: a device set to CRIT on ANY but WARN on SOME would look better when a second sensor fails.

Sensors and probe groups

A sensor in one probe group is simple: when that group's readings fail, one of one is failing, which is ALL, so CRIT.

With more than one group, the defaults ask for agreement. In two groups, one failing is ANY, which is OK: the device is still reachable from the other, and the fault is most likely on the path from the first. Both failing is ALL and CRIT. Change the sensor's settings to suit what you are watching:

You want to knowANYSOMEALL
Is it down for everyone (the default)OKWARNCRIT
As soon as anyone loses itWARNCRITCRIT
Can every location reach it, such as a public web siteCRITCRITCRIT

SOME can only happen with three or more groups; with two, it is never reached.