Without seeing the content of those alert mails it's hard to know what's going on. Do the alerts have identical labels? Do they have identical timestamps, down to the second?
Is it possible that [email protected] and [email protected] are being expanded as aliases and forward to the same destinations? Since you are relaying via your own smarthost ('mx2.so.com:25') it should be possible to look at logs on this host and check whether it's receiving one message from alertmanager or three separate copies. What's your rule evaluation interval? "for: 10s" is very short. For test purposes, I'd be inclined to add "send_resolved: true" to your receiver. This would let you see if the alert is triggering, resolving, and triggering again. Having said that, I think it's unlikely that this is happening with the SSL expiry rule you posted. Do you get any relevant logs in alertmanager? Try "journalctl -eu alertmanager". -- You received this message because you are subscribed to the Google Groups "Prometheus Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/prometheus-users/1d5bfb10-a0c0-4112-bc5e-f3ed3fba8164o%40googlegroups.com.

