---
title: Spike incidents
description: 'Search, filters and handling for the incidents opened by spike rules: resolve, ignore, mark as false positive or reopen.'
updated: 2026-09-27
sidebarLabel: Incidents
---

Every time a rule fires, it opens an incident, one per subject, for example one per IP. The **Incidentes de Pico** (Spike incidents) screen gathers all incidents and refreshes automatically every 5 seconds.

Viewing incidents requires `spikes.incidents.read`. Acting on them requires `spikes.rules.write`, included in the **Tenant Admin** role.

## Open the list

Go to **Detecção de Picos** (Spike Detection) > **Incidentes** (Incidents). The list is split into four tabs:

| Tab | Status | What it holds |
|---|---|---|
| Abertos (Open) | Aberto (Open) | Ongoing incidents. |
| Resolvidos (Resolved) | Resolvido (Resolved) | Incidents closed manually or by automatic recovery. |
| Falsos positivos (False positives) | Falso positivo (False positive) | Incidents that were not a real anomaly. |
| Ignorados (Ignored) | Ignorado (Ignored) | Incidents set aside without resolution. |

## Columns

| Column | What it shows |
|---|---|
| Regra (Rule) | The rule that fired. |
| Escopo (Scope) | The incident's subject, such as the zone or the IP. |
| Início (Start) | When the incident opened. |
| Última detecção / Resolvido em (Last detection / Resolved at) | The most recent anomalous window or, for closed incidents, when it was resolved. |
| Volume | Requests in the triggering window. |
| Detecção (Detection) | The trigger's value and phrase. |
| Análise (Analysis) | The analysis agent's verdict. Shown to users with `responder.read`. |

Each incident has two shortcuts: **Abrir no painel da Cloudflare com o filtro do incidente** (Open in the Cloudflare dashboard with the incident's filter) and a link to ipinfo.io, to look up the IP.

### Orphan incident

The **Órfão** (Orphan) badge shows up when the rule was edited and the incident no longer has a current evaluation. In that case, the value and phrase shown are the ones from the trigger, not the current ones.

## Search and filter

- **Buscar IP ou regra…** (Search IP or rule…): text search.
- **Regra** (Rule): shows only one rule's incidents.
- **Volume**: **Até 500** (Up to 500), **500 a 1 mil** (500 to 1k), **1 mil a 2 mil** (1k to 2k), **2 mil a 3 mil** (2k to 3k), **3 mil a 5 mil** (3k to 5k) or **5 mil ou mais** (5k or more).
- **Análise** (Analysis): **Ataque** (Attack), **Benigno** (Benign), **Inconclusivo** (Inconclusive), **Aguardando agente** (Waiting for agent), **Falhou** (Failed) or **Sem análise** (No analysis). Only shown to users with `responder.read`.
- **Limpar filtros** (Clear filters): removes every filter.

## Handle an incident

Actions show up in the **Abertos** and **Ignorados** tabs.

| Action | Effect |
|---|---|
| Resolver (Resolve) | Closes the incident as resolved. |
| Ignorar (Ignore) | Moves the incident to **Ignorados**. |
| Marcar falso positivo (Mark false positive) | Moves the incident to **Falsos positivos** and counts toward the rule's **Calibração** (Calibration) metric. |

All three actions suppress new alerts for that subject for the rule's cooldown. Use **Reabrir** (Reopen) to bring an incident back to **Abertos**.

:::tip
Mark false positives with care. They feed **Calibração**, which indicates whether the rule's threshold is adequate. Refer to [Spike rules](/en/advisor/deteccao-de-picos/regras/).
:::

## See the analysis

From the **Análise** column, open the **Análise** drawer to review the agent's judgment, the evidence and the actions. Refer to [AI analysis](/en/advisor/deteccao-de-picos/analise-por-ia/).

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/deteccao-de-picos/incidentes/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
