A SAN with plenty of free space can still be the reason an application is slow. Latency, not capacity, is usually the first sign of a storage problem.
Not every vendor's SNMP MIB includes latency; some only report throughput and IOPS. If yours does, per-LUN read/write latency is usually the more actionable of the two.
A few milliseconds of latency is fine for bulk file storage and a real problem for a transactional database. Set thresholds per device group rather than one number for every SAN target.
Rising latency at flat or falling throughput often points to a controller or fabric problem rather than genuine load, and is worth flagging differently than latency that scales with a legitimate traffic increase.