I decided to head the ntopng route. OK, not quite what I was looking for but it's fancy and fast for my purposes as I found a solution and wanted to pass it along:
In ntopng, there is per host alerting. While it's not an email or sms, it does SLACK!! Woot. I just integrated a new workspace with my existing workspace in Slack and followed the instructions here:
https://github.com/ntop/ntopng/blob/dev/doc/README.slack
I set two threshold items - the Activity Time and Traffic, Layer 2 with the levels low to see what a baseline looked like. Sure enough, it is quite gated unless it gets stupid.
Hope this can help anyone else looking for this solution. The only way it could be better is to split send/rec in Traffic, but it works for now!