Spike incidents
Search, filters and handling for the incidents opened by spike rules: resolve, ignore, mark as false positive or reopen.
Every time a rule fires, it opens an incident, one per subject, for example one per IP. The Incidentes de Pico (Spike incidents) screen gathers all incidents and refreshes automatically every 5 seconds.
Viewing incidents requires spikes.incidents.read. Acting on them requires spikes.rules.write, included in the Tenant Admin role.
Open the list
Go to Detecção de Picos (Spike Detection) > Incidentes (Incidents). The list is split into four tabs:
| Tab | Status | What it holds |
|---|---|---|
| Abertos (Open) | Aberto (Open) | Ongoing incidents. |
| Resolvidos (Resolved) | Resolvido (Resolved) | Incidents closed manually or by automatic recovery. |
| Falsos positivos (False positives) | Falso positivo (False positive) | Incidents that were not a real anomaly. |
| Ignorados (Ignored) | Ignorado (Ignored) | Incidents set aside without resolution. |
Columns
| Column | What it shows |
|---|---|
| Regra (Rule) | The rule that fired. |
| Escopo (Scope) | The incident's subject, such as the zone or the IP. |
| Início (Start) | When the incident opened. |
| Última detecção / Resolvido em (Last detection / Resolved at) | The most recent anomalous window or, for closed incidents, when it was resolved. |
| Volume | Requests in the triggering window. |
| Detecção (Detection) | The trigger's value and phrase. |
| Análise (Analysis) | The analysis agent's verdict. Shown to users with responder.read. |
Each incident has two shortcuts: Abrir no painel da Cloudflare com o filtro do incidente (Open in the Cloudflare dashboard with the incident's filter) and a link to ipinfo.io, to look up the IP.
Orphan incident
The Órfão (Orphan) badge shows up when the rule was edited and the incident no longer has a current evaluation. In that case, the value and phrase shown are the ones from the trigger, not the current ones.
Search and filter
- Buscar IP ou regra… (Search IP or rule…): text search.
- Regra (Rule): shows only one rule's incidents.
- Volume: Até 500 (Up to 500), 500 a 1 mil (500 to 1k), 1 mil a 2 mil (1k to 2k), 2 mil a 3 mil (2k to 3k), 3 mil a 5 mil (3k to 5k) or 5 mil ou mais (5k or more).
- Análise (Analysis): Ataque (Attack), Benigno (Benign), Inconclusivo (Inconclusive), Aguardando agente (Waiting for agent), Falhou (Failed) or Sem análise (No analysis). Only shown to users with
responder.read. - Limpar filtros (Clear filters): removes every filter.
Handle an incident
Actions show up in the Abertos and Ignorados tabs.
| Action | Effect |
|---|---|
| Resolver (Resolve) | Closes the incident as resolved. |
| Ignorar (Ignore) | Moves the incident to Ignorados. |
| Marcar falso positivo (Mark false positive) | Moves the incident to Falsos positivos and counts toward the rule's Calibração (Calibration) metric. |
All three actions suppress new alerts for that subject for the rule's cooldown. Use Reabrir (Reopen) to bring an incident back to Abertos.
See the analysis
From the Análise column, open the Análise drawer to review the agent's judgment, the evidence and the actions. Refer to AI analysis.