How Spike Detection works
The Spike Detection stages, from traffic collected every 5 minutes to the decision: baseline, rule, incident, alert, agent analysis and playbook.
Spike Detection compares the traffic in each 5-minute window with what is normal for that time of day and opens an incident when the deviation exceeds the limit set in the rule. An analysis agent reviews the incident. If there is a playbook, an action can be recorded or proposed for a decision.
Flow overview
- Collection: Advisor reads the zone's traffic from Cloudflare in 5-minute windows.
- Baseline: for each window, it computes normal as the median of the same time of day (±30 min) over the last few days.
- Rule: the rule fires when the value exceeds the threshold for the required number of windows.
- Incident: the trigger opens an incident in Incidentes de Pico (Spike incidents), one per subject (for example, one per IP).
- Alert: unless the rule is in observation mode, the configured notification locations and emails receive the alert.
- Analysis: the analysis agent reviews the incident and issues a verdict: Ataque (Attack), Benigno (Benign) or Inconclusivo (Inconclusive).
- Playbook: with an Ataque verdict above the minimum confidence, the playbook records the action (Só registrar, Record only) or proposes it and waits for approval (Propor e aguardar aprovação, Propose and wait for approval).
- Decision: in Respostas (Responses), approve or reject the proposal. In Incidentes (Incidents), resolve, ignore or mark as false positive.
Collection and baseline
- Windows are 5 minutes long.
- When you create a rule, Advisor pulls the last 7 days from Cloudflare, so the rule starts with a baseline.
- Normal is the median of the same time of day, ±30 minutes, over Baseline (dias) (Baseline days): 7 by default, 3 at minimum. The time zone is America/Sao_Paulo.
- In addition to the rule's percentage, a fixed statistical guard applies. It is not editable.
Warm-up
A rule only fires after its baseline warms up, which requires 80% of the samples for that time of day over the last N days. Before that, the rule does not fire. The rule's Baseline indicator shows Aquecendo (Warming up) or Pronto (Ready).
Rule states
| State | What it means |
|---|---|
| Pausada (Paused) | The rule does not evaluate windows or open incidents. |
| Observação (Observation) | Evaluates and records incidents, but sends no alerts. |
| Alertando (Alerting) | There is an open incident at the moment. |
| Ativa (Active) | The rule evaluates windows and there is no open incident. |
When more than one state applies, the precedence is: Pausada, then Observação, then Alertando.
Status indicators
Each rule shows five indicators on its detail page:
| Indicator | Values |
|---|---|
| Coleta (Collection) | Ligada (On), Atrasada (Delayed, more than 20 min since the last window) or Desligada (Off). |
| Avaliação (Evaluation) | Em incidente (In incident), Normal or Sem avaliação (Not evaluated). |
| Baseline | Aquecendo or Pronto, with collected over expected samples and the percentage. |
| Calibração (Calibration) | Incidents, false positives and median detection time over the period. |
| Alerta (Alert) | Observação, Ligado (On) or Sem destino (No destination). |
Refer to Spike rules.
Where it is in the menu
The Detecção de Picos (Spike Detection) menu has three items. Each item shows up for users with the matching permission:
| Item | Permission |
|---|---|
| Regras (Rules) | spikes.rules.read |
| Incidentes (Incidents) | spikes.incidents.read |
| Respostas (Responses) | responder.read |
Tenant Admin creates and edits rules, acts on incidents, re-runs analyses, approves actions and edits playbooks. Tenant User can only view rules, incidents and responses. The analysis agent's profiles and modes are managed by Guardnet. Refer to Roles and permissions.