we have a correlation which selects some elements and after that this filtering is active:
For every new alarm which is critical/major we will receive an email everything is fine. But we would like also to receive an email when the alarm is gone and back to normal. Is there something we overlook? When we test the rule we never see a "green" alarm. Tested also just with serverity equal to normal for example.
Did you try to use the "execute on clear" option, you can find this at the bottom of your action section in the correlation rule.
Can you also verify if you have the trigger on single events checkbox enabled?