---
title: How Spike Detection works
description: 'The Spike Detection stages, from traffic collected every 5 minutes to the decision: baseline, rule, incident, alert, agent analysis and playbook.'
updated: 2026-09-27
sidebarLabel: How it works
---

Spike Detection compares the traffic in each 5-minute window with what is normal for that time of day and opens an incident when the deviation exceeds the limit set in the rule. An analysis agent reviews the incident. If there is a playbook, an action can be recorded or proposed for a decision.

:::note
The analysis agent and the playbooks do not change your Cloudflare account. Actions are internal Advisor governance: closing, archiving or escalating an incident.
:::

## Flow overview

1. **Collection**: Advisor reads the zone's traffic from Cloudflare in 5-minute windows.
2. **Baseline**: for each window, it computes normal as the median of the same time of day (±30 min) over the last few days.
3. **Rule**: the rule fires when the value exceeds the threshold for the required number of windows.
4. **Incident**: the trigger opens an incident in **Incidentes de Pico** (Spike incidents), one per subject (for example, one per IP).
5. **Alert**: unless the rule is in observation mode, the configured notification locations and emails receive the alert.
6. **Analysis**: the analysis agent reviews the incident and issues a verdict: **Ataque** (Attack), **Benigno** (Benign) or **Inconclusivo** (Inconclusive).
7. **Playbook**: with an **Ataque** verdict above the minimum confidence, the playbook records the action (**Só registrar**, Record only) or proposes it and waits for approval (**Propor e aguardar aprovação**, Propose and wait for approval).
8. **Decision**: in **Respostas** (Responses), approve or reject the proposal. In **Incidentes** (Incidents), resolve, ignore or mark as false positive.

## Collection and baseline

- Windows are 5 minutes long.
- When you create a rule, Advisor pulls the last 7 days from Cloudflare, so the rule starts with a baseline.
- Normal is the median of the same time of day, ±30 minutes, over **Baseline (dias)** (Baseline days): 7 by default, 3 at minimum. The time zone is America/Sao_Paulo.
- In addition to the rule's percentage, a fixed statistical guard applies. It is not editable.

### Warm-up

A rule only fires after its baseline warms up, which requires 80% of the samples for that time of day over the last N days. Before that, the rule does not fire. The rule's **Baseline** indicator shows **Aquecendo** (Warming up) or **Pronto** (Ready).

:::tip
To calibrate the rule, collect data for at least 3 days, ideally 7. Then keep the rule in **Modo observação** (Observation mode) for at least one week before turning on alerts.
:::

## Rule states

| State | What it means |
|---|---|
| Pausada (Paused) | The rule does not evaluate windows or open incidents. |
| Observação (Observation) | Evaluates and records incidents, but sends no alerts. |
| Alertando (Alerting) | There is an open incident at the moment. |
| Ativa (Active) | The rule evaluates windows and there is no open incident. |

When more than one state applies, the precedence is: **Pausada**, then **Observação**, then **Alertando**.

## Status indicators

Each rule shows five indicators on its detail page:

| Indicator | Values |
|---|---|
| Coleta (Collection) | **Ligada** (On), **Atrasada** (Delayed, more than 20 min since the last window) or **Desligada** (Off). |
| Avaliação (Evaluation) | **Em incidente** (In incident), **Normal** or **Sem avaliação** (Not evaluated). |
| Baseline | **Aquecendo** or **Pronto**, with collected over expected samples and the percentage. |
| Calibração (Calibration) | Incidents, false positives and median detection time over the period. |
| Alerta (Alert) | **Observação**, **Ligado** (On) or **Sem destino** (No destination). |

Refer to [Spike rules](/en/advisor/deteccao-de-picos/regras/).

## Where it is in the menu

The **Detecção de Picos** (Spike Detection) menu has three items. Each item shows up for users with the matching permission:

| Item | Permission |
|---|---|
| Regras (Rules) | `spikes.rules.read` |
| Incidentes (Incidents) | `spikes.incidents.read` |
| Respostas (Responses) | `responder.read` |

**Tenant Admin** creates and edits rules, acts on incidents, re-runs analyses, approves actions and edits playbooks. **Tenant User** can only view rules, incidents and responses. The analysis agent's profiles and modes are managed by Guardnet. Refer to [Roles and permissions](/en/advisor/referencia/papeis-e-permissoes/).

## Next steps

- [Create a rule](/en/advisor/deteccao-de-picos/criar-regra/)
- [Incidents](/en/advisor/deteccao-de-picos/incidentes/)
- [AI analysis](/en/advisor/deteccao-de-picos/analise-por-ia/)
- [Responses and playbooks](/en/advisor/deteccao-de-picos/respostas-e-playbooks/)

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/deteccao-de-picos/como-funciona/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
