---
title: AI analysis
description: The analysis agent's verdict on a spike incident, the evidence it used, the trigger numbers and how to re-run it.
updated: 2026-09-27
sidebarLabel: AI analysis
---

When an incident opens, an analysis agent reviews the case using the traffic evidence and the tenant's context. It then records a verdict. The analysis shows up in the incident's **Análise** (Analysis) drawer for users with `responder.read`.

:::note
The analysis and the actions that come from it are internal Advisor governance. No setting in the customer's Cloudflare account changes.
:::

## Verdicts

| Verdict | What it means |
|---|---|
| Ataque (Attack) | The agent considers the spike an attack. Only this verdict can trigger a playbook. |
| Benigno (Benign) | The agent considers the spike legitimate traffic. |
| Inconclusivo (Inconclusive) | The evidence is not enough to decide. |

Each verdict comes with a confidence percentage.

## Analysis states

| State | What it means |
|---|---|
| Aguardando agente (Waiting for agent) | The analysis is queued or running. |
| Analisado (Analyzed) | The verdict is ready. |
| Falhou (Failed) | The analysis did not finish. |
| Sem análise (No analysis) | The incident has no analysis. |

### Shadow mode

The **Sombra** (Shadow) badge means the agent profile is in shadow mode: the verdict is recorded, but it does not trigger a playbook. Agent profiles and modes are managed by Guardnet.

## What the drawer shows

### Veredito (Verdict)

| Field | What it shows |
|---|---|
| Status | The analysis state. |
| Motivo (Reason) | The agent's explanation for the verdict. |
| Tipo de ataque (Attack type) | The attack classification, when there is one. |
| Severidade (Severity) | **Desprezível** (Negligible), **Baixa** (Low), **Alta** (High) or **Crítica** (Critical). |
| Perfil e modelo (Profile and model) | The agent profile that ran the analysis. |
| Analisado em (Analyzed at) | Date and time of the analysis. |

### Contexto usado pelo agente (Context used by the agent)

The items from the [knowledge base](/en/advisor/administracao/base-de-conhecimento/) the agent looked up to judge the case.

### Evidência de requests (Request evidence)

- **Requisições estimadas por minuto** (Estimated requests per minute).
- The most frequent values in **Caminhos** (Paths), **User agents**, **Países** (Countries), **ASNs**, **Status HTTP** (HTTP status) and **Métodos** (Methods).

IPs are deliberately left out of the evidence. When not all of the evidence could be collected, the drawer shows the **Coleta parcial da evidência** (Partial evidence collection) notice.

### Números do disparo (Trigger numbers)

| Field | What it shows |
|---|---|
| Valor na janela (Value in the window) | The volume of the window that fired. |
| Mediana (Median) | The normal volume for that time of day. |
| Desvio (Deviation) | How far the value was above or below the median. |
| Z robusto (Robust Z) | The statistical measure of the deviation. |
| Amostras (Samples) | How many samples made up the baseline. |

### Ações (Actions)

The actions available for the incident. Refer to [Responses and playbooks](/en/advisor/deteccao-de-picos/respostas-e-playbooks/).

The **Ver regra** (See rule) and **Incidentes desta regra** (This rule's incidents) links take you to the rule and to the filtered list.

## Re-run the analysis

Use **Reanalisar** (Re-analyze) to get a new judgment, for example after updating the knowledge base. It requires `responder.actions.execute`, included in the **Tenant Admin** role.

1. In the **Análise** drawer, select **Reanalisar**.
2. Read the warning in the **Reanalisar o incidente?** (Re-analyze the incident?) dialog.
3. Confirm the action.

:::caution
The on-screen warning says the agent judges the case again with the current profile, that this calls the model (which has a cost), and that an attack verdict can trigger the tenant's playbooks.
:::

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/deteccao-de-picos/analise-por-ia/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
