How to detect network anomaly dynamically?
Almost all check plugins available in Nagios community use thresholds to classify levels of
network status. Users must define absolute threshold values for critical, warning, and ok levels for each
service check. This procedure is troublesome. For example, the check-ping service for two servers may
require different threshold levels because the servers are locate at different location. In this case, users
must define two different check-ping services, one for each set of thresholds. Moreover, it is
impractical to expect users to know before-hand all performance levels, such as round-trip delay, loss
rate, and load, for all servers.