Incoming alerts sharing an identical alarm_unique_id definition (e.g., $['host']%//%:%//%$['application']%//%-%//%$['alertid']) continuously create duplicate open alarms instead of updating the existing active alarm.
The issue recurs at regular intervals matching the configured alarm Time-To-Live (TTL).
DE678306: Setting alarm_ttl_mins to a short window (e.g., 30 minutes) causes the internal TTL tracking in RESTmon to expire after that duration. Once expired, any subsequent payload carrying the same alarm_id is evaluated as a brand-new alarm rather than a status update to the existing entry.
Increase the TTL value to 24 hours (1440 minutes) following procedure shown below: