Create a spike rule
The fields of the new spike rule form, their default values and why to start in observation mode.
A spike rule defines which traffic to watch, how much deviation is abnormal and who receives the alert. Creating, editing and duplicating rules requires the spikes.rules.write permission, included in the Tenant Admin role.
Before you start
- Connect your Cloudflare account. Refer to Connect Cloudflare.
- To receive alerts, set up your notification locations before you create the rule.
Create the rule
- Go to Detecção de Picos (Spike Detection) > Regras (Rules).
- Select Nova regra (New rule). The Nova regra de pico (New spike rule) page opens.
- Fill in the sections described below.
- Select Criar regra (Create rule).
Advisor shows the message Regra criada… Ela dispara depois que o baseline aquecer. (Rule created… It fires once the baseline warms up.) On creation, Advisor pulls the last 7 days from Cloudflare so the rule starts with a baseline.
Identificação (Identification)
| Field | Use |
|---|---|
| Nome da regra (Rule name) | Up to 120 characters. |
| Tipo (Type) | Pico por IP (Spike by IP), Pico de status (Status spike) or Queda de status (Status drop). |
| Zones | Multi-select. Choosing N zones creates N rules, shown as one row in the list. |
The types:
| Type | What it watches |
|---|---|
| Pico por IP | Request spikes. Opens one incident per anomalous IP. |
| Pico de status | Spikes in responses with a status from Status inicial (Start status) to Status final (End status). Default: 500 to 599. |
| Queda de status | Drops in responses with a status from Status inicial to Status final. Default: 200 to 399. |
Quando as requisições corresponderem a… (When requests match…)
This section filters the traffic the rule watches. With no conditions, the rule watches the whole zone.
- Select Adicionar condição (Add condition).
- Choose the field, the operator and the value.
- Repeat for more conditions and choose E (AND) or OU (OR). The combiner applies to the whole expression.
- Use Prévia (Preview) to check the expression.
Available fields: Host, Caminho (path) (Path), Status da resposta (Response status), IP do cliente (Client IP), País (Country), ASN, Método HTTP (HTTP method), User agent and Ação de segurança (Security action).
| Field type | Operators |
|---|---|
| Text | é igual a (equals), é diferente de (does not equal), contém (contains), não contém (does not contain), começa com (starts with), está na lista (is in list), não está na lista (is not in list) |
| Numeric | é igual a, é diferente de, maior ou igual a (greater than or equal to), menor ou igual a (less than or equal to), entre (between), está na lista, não está na lista |
Agrupar por (Group by)
Agrupar por sets the incident's subject: one incident per value of the field, for example one per IP. The default is Zona inteira (um alvo) (Whole zone, one target). Any field from the list above can be used, except User agent.
Quanto desvio é anormal (How much deviation is abnormal)
Empty fields use the default value.
| Field | Default | Use |
|---|---|---|
| % acima do normal (% above normal) | Required | How far above the time-of-day median the window must be. Example: 300. |
| Baseline (dias) (Baseline days) | 7 | Days used to compute normal. Minimum 3. |
| Piso de volume (Volume floor) | 200 requests | Minimum volume to evaluate. For drops, it applies to the baseline median. |
| Persistência (janelas) (Persistence, windows) | 2 | How many 5-minute windows above the threshold are required before firing. |
| Cooldown (janelas) (Cooldown, windows) | 6 (30 min) | Interval during which the same subject does not alert again. |
| Recuperação (janelas) (Recovery, windows) | 3 | Healthy windows needed to close the alert. |
| Ativa a partir de / Ativa até (Active from / Active until) | Always active | Time range when the rule evaluates. Outside it, evaluation pauses. |
Então avise… (Then alert…)
| Field | Use |
|---|---|
| Locais de notificação (Notification locations) | Checklist of email lists and Slack channels. Gerenciar locais (Manage locations) opens the setup and Recarregar lista (Reload list) refreshes the options. |
| E-mails avulsos (Individual emails) | Addresses outside the locations. Use Adicionar destinatário (Add recipient), or Receber eu também (Send to me too) to include yourself. If your address is already included, the form shows Você já recebe (You already receive it). |
The option Resolver o incidente automaticamente quando o tráfego normalizar (usa a janela de recuperação acima) (Resolve the incident automatically when traffic returns to normal, using the recovery window above) is turned on by default. When it is turned off, the form states that closing is manual.
Status
| Option | Use |
|---|---|
| Regra ativa (Rule active) | Ativa (Active) or Pausada (Paused). |
| Modo observação (Observation mode) | Evaluates and records incidents, but sends no alerts (no email, no Slack). |
Edit a rule
In the rule list, select Editar (Edit). The Editar regra de pico (Edit spike rule) page opens with the same fields. Select Salvar (Save) to store the changes.
Duplicate a rule
In the rule list, select Duplicar (Duplicate). The Duplicar regra de pico (Duplicate spike rule) page opens with the fields filled in. Adjust the fields as needed and select Criar cópia (Create copy). The copy always starts in observation mode.