Spike rules
The spike rule list, bulk actions, and the chart and indicators on each rule's detail page.
The Regras de Pico (Spike rules) screen lists every rule in the tenant with its current state. Viewing the list requires spikes.rules.read; editing, duplicating, deleting and bulk actions require spikes.rules.write.
The list
Go to Detecção de Picos (Spike Detection) > Regras (Rules).
| Column | What it shows |
|---|---|
| Regra (Rule) | Rule name. A rule created for several zones shows up as a single row. |
| Zonas (Zones) | The zones being watched. |
| Estado (State) | Pausada (Paused), Observação (Observation), Alertando (Alerting) or Ativa (Active). |
| Incidentes abertos (Open incidents) | Number of the rule's incidents open at the moment. |
| Limiar (Threshold) | The configured % acima do normal (% above normal). |
| Avisos (Alerts) | Where alerts go. With no destination, the Não avisa ninguém (Alerts no one) badge shows up. |
| Resposta (Response) | The playbook that applies to the rule. |
Each row has the actions Editar (Edit), Duplicar (Duplicate) and Excluir (Delete). Refer to Create a spike rule.
States
| State | What it means |
|---|---|
| Pausada | The rule does not evaluate windows or open incidents. |
| Observação | Evaluates and records incidents, but sends no alerts. |
| Alertando | There is an open incident at the moment. |
| Ativa | The rule evaluates windows and there is no open incident. |
When more than one state applies, the precedence is: Pausada, then Observação, then Alertando.
Bulk actions
- Select the rules in the list.
- Choose the action in the bar that appears:
| Action | Effect |
|---|---|
| Pausar (Pause) | Stops evaluating the rules. |
| Ativar (Activate) | Resumes evaluation. |
| Ligar observação (Turn observation on) | Keeps recording incidents, without sending alerts. |
| Desligar observação (Turn observation off) | Starts sending alerts. |
| Destinatários… (Recipients…) | Sets the individual emails. |
| Locais… (Locations…) | Sets the notification locations. |
| Excluir (Delete) | Removes the rules. |
| Limpar seleção (Clear selection) | Clears the selection of all rules. |
Rule detail
Select a rule's name to open its detail page. The page has three tabs:
- Visão geral (Overview): indicators and chart.
- Incidentes (Incidents): this rule's incidents. Refer to Spike incidents.
- Resposta automática (Automatic response): the rule's playbook. Refer to Responses and playbooks.
Indicators
| Indicator | Values |
|---|---|
| Coleta (Collection) | Ligada (On), Atrasada (Delayed) or Desligada (Off). Atrasada means more than 20 minutes since the last window. |
| Avaliação (Evaluation) | Em incidente (In incident), Normal or Sem avaliação (Not evaluated). |
| Baseline | Aquecendo (Warming up) or Pronto (Ready), with collected over expected samples and the percentage. The rule only fires with 80% of the samples. |
| Calibração (Calibration) | The period in days, with incidents, false positives and median detection time. |
| Alerta (Alert) | Observação, Ligado (On) or Sem destino (No destination). |
Janelas × requisições chart (Windows × requests)
The chart shows each 5-minute window against what is normal for that time of day. Pick the range: 6 h, 24 h (default), 3 dias (3 days) or 7 dias (7 days).
| Legend | What it is |
|---|---|
| Requisições na janela (Requests in the window) | Each window's volume. |
| Limiar do alerta (mediana do horário + %) (Alert threshold, time-of-day median + %) | The value above which a window is anomalous. |
| Mediana do horário (normal) (Time-of-day median, normal) | The baseline. |
| Piso de volume (Volume floor) | The minimum volume to evaluate. |
| Janela anômala (Anomalous window) | A window above the threshold. |
| Incidente (Incident) | When an incident was opened. |
For IP rules, use the IP field to pick the subject shown in the chart.