---
title: Create a spike rule
description: The fields of the new spike rule form, their default values and why to start in observation mode.
updated: 2026-09-27
sidebarLabel: Create a rule
---

A spike rule defines which traffic to watch, how much deviation is abnormal and who receives the alert. Creating, editing and duplicating rules requires the `spikes.rules.write` permission, included in the **Tenant Admin** role.

## Before you start

- Connect your Cloudflare account. Refer to [Connect Cloudflare](/en/advisor/primeiros-passos/conectar-cloudflare/).
- To receive alerts, set up your [notification locations](/en/advisor/administracao/locais-de-notificacao/) before you create the rule.

:::tip
Start in **Modo observação** (Observation mode). In this mode, the rule evaluates and records incidents without sending alerts, so you can tune the threshold without false alerts. Collect data for at least 3 days, ideally 7, and observe for at least one week before turning on alerts.
:::

## Create the rule

1. Go to **Detecção de Picos** (Spike Detection) > **Regras** (Rules).
2. Select **Nova regra** (New rule). The **Nova regra de pico** (New spike rule) page opens.
3. Fill in the sections described below.
4. Select **Criar regra** (Create rule).

Advisor shows the message **Regra criada… Ela dispara depois que o baseline aquecer.** (Rule created… It fires once the baseline warms up.) On creation, Advisor pulls the last 7 days from Cloudflare so the rule starts with a baseline.

## Identificação (Identification)

| Field | Use |
|---|---|
| Nome da regra (Rule name) | Up to 120 characters. |
| Tipo (Type) | **Pico por IP** (Spike by IP), **Pico de status** (Status spike) or **Queda de status** (Status drop). |
| Zones | Multi-select. Choosing N zones creates N rules, shown as one row in the list. |

The types:

| Type | What it watches |
|---|---|
| Pico por IP | Request spikes. Opens one incident per anomalous IP. |
| Pico de status | Spikes in responses with a status from **Status inicial** (Start status) to **Status final** (End status). Default: 500 to 599. |
| Queda de status | Drops in responses with a status from **Status inicial** to **Status final**. Default: 200 to 399. |

:::note
Only **Queda de status** detects drops. For this type, **% acima do normal** (% above normal) must be under 100%.
:::

## Quando as requisições corresponderem a… (When requests match…)

This section filters the traffic the rule watches. With no conditions, the rule watches the whole zone.

1. Select **Adicionar condição** (Add condition).
2. Choose the field, the operator and the value.
3. Repeat for more conditions and choose **E** (AND) or **OU** (OR). The combiner applies to the whole expression.
4. Use **Prévia** (Preview) to check the expression.

Available fields: **Host**, **Caminho (path)** (Path), **Status da resposta** (Response status), **IP do cliente** (Client IP), **País** (Country), **ASN**, **Método HTTP** (HTTP method), **User agent** and **Ação de segurança** (Security action).

| Field type | Operators |
|---|---|
| Text | **é igual a** (equals), **é diferente de** (does not equal), **contém** (contains), **não contém** (does not contain), **começa com** (starts with), **está na lista** (is in list), **não está na lista** (is not in list) |
| Numeric | **é igual a**, **é diferente de**, **maior ou igual a** (greater than or equal to), **menor ou igual a** (less than or equal to), **entre** (between), **está na lista**, **não está na lista** |

### Agrupar por (Group by)

**Agrupar por** sets the incident's subject: one incident per value of the field, for example one per IP. The default is **Zona inteira (um alvo)** (Whole zone, one target). Any field from the list above can be used, except **User agent**.

## Quanto desvio é anormal (How much deviation is abnormal)

Empty fields use the default value.

| Field | Default | Use |
|---|---|---|
| % acima do normal (% above normal) | Required | How far above the time-of-day median the window must be. Example: 300. |
| Baseline (dias) (Baseline days) | 7 | Days used to compute normal. Minimum 3. |
| Piso de volume (Volume floor) | 200 requests | Minimum volume to evaluate. For drops, it applies to the baseline median. |
| Persistência (janelas) (Persistence, windows) | 2 | How many 5-minute windows above the threshold are required before firing. |
| Cooldown (janelas) (Cooldown, windows) | 6 (30 min) | Interval during which the same subject does not alert again. |
| Recuperação (janelas) (Recovery, windows) | 3 | Healthy windows needed to close the alert. |
| Ativa a partir de / Ativa até (Active from / Active until) | Always active | Time range when the rule evaluates. Outside it, evaluation pauses. |

## Então avise… (Then alert…)

| Field | Use |
|---|---|
| Locais de notificação (Notification locations) | Checklist of email lists and Slack channels. **Gerenciar locais** (Manage locations) opens the setup and **Recarregar lista** (Reload list) refreshes the options. |
| E-mails avulsos (Individual emails) | Addresses outside the locations. Use **Adicionar destinatário** (Add recipient), or **Receber eu também** (Send to me too) to include yourself. If your address is already included, the form shows **Você já recebe** (You already receive it). |

The option **Resolver o incidente automaticamente quando o tráfego normalizar (usa a janela de recuperação acima)** (Resolve the incident automatically when traffic returns to normal, using the recovery window above) is turned on by default. When it is turned off, the form states that closing is manual.

## Status

| Option | Use |
|---|---|
| Regra ativa (Rule active) | **Ativa** (Active) or **Pausada** (Paused). |
| Modo observação (Observation mode) | Evaluates and records incidents, but sends no alerts (no email, no Slack). |

:::caution
An active rule with no locations and no emails opens incidents in the dashboard but sends no alerts. The form shows this warning and the rule list tags the rule with **Não avisa ninguém** (Alerts no one).
:::

## Edit a rule

In the rule list, select **Editar** (Edit). The **Editar regra de pico** (Edit spike rule) page opens with the same fields. Select **Salvar** (Save) to store the changes.

:::caution
Changing the filter discards the collected series and starts a new collection. The form shows a warning before saving.
:::

## Duplicate a rule

In the rule list, select **Duplicar** (Duplicate). The **Duplicar regra de pico** (Duplicate spike rule) page opens with the fields filled in. Adjust the fields as needed and select **Criar cópia** (Create copy). The copy always starts in observation mode.

## Next steps

- [Spike rules](/en/advisor/deteccao-de-picos/regras/)
- [How Spike Detection works](/en/advisor/deteccao-de-picos/como-funciona/)

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/deteccao-de-picos/criar-regra/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
