---
title: Spike rules
description: The spike rule list, bulk actions, and the chart and indicators on each rule's detail page.
updated: 2026-09-27
sidebarLabel: Rules
---

The **Regras de Pico** (Spike rules) screen lists every rule in the tenant with its current state. Viewing the list requires `spikes.rules.read`; editing, duplicating, deleting and bulk actions require `spikes.rules.write`.

## The list

Go to **Detecção de Picos** (Spike Detection) > **Regras** (Rules).

| Column | What it shows |
|---|---|
| Regra (Rule) | Rule name. A rule created for several zones shows up as a single row. |
| Zonas (Zones) | The zones being watched. |
| Estado (State) | **Pausada** (Paused), **Observação** (Observation), **Alertando** (Alerting) or **Ativa** (Active). |
| Incidentes abertos (Open incidents) | Number of the rule's incidents open at the moment. |
| Limiar (Threshold) | The configured **% acima do normal** (% above normal). |
| Avisos (Alerts) | Where alerts go. With no destination, the **Não avisa ninguém** (Alerts no one) badge shows up. |
| Resposta (Response) | The playbook that applies to the rule. |

Each row has the actions **Editar** (Edit), **Duplicar** (Duplicate) and **Excluir** (Delete). Refer to [Create a spike rule](/en/advisor/deteccao-de-picos/criar-regra/).

## States

| State | What it means |
|---|---|
| Pausada | The rule does not evaluate windows or open incidents. |
| Observação | Evaluates and records incidents, but sends no alerts. |
| Alertando | There is an open incident at the moment. |
| Ativa | The rule evaluates windows and there is no open incident. |

When more than one state applies, the precedence is: **Pausada**, then **Observação**, then **Alertando**.

## Bulk actions

1. Select the rules in the list.
2. Choose the action in the bar that appears:

| Action | Effect |
|---|---|
| Pausar (Pause) | Stops evaluating the rules. |
| Ativar (Activate) | Resumes evaluation. |
| Ligar observação (Turn observation on) | Keeps recording incidents, without sending alerts. |
| Desligar observação (Turn observation off) | Starts sending alerts. |
| Destinatários… (Recipients…) | Sets the individual emails. |
| Locais… (Locations…) | Sets the notification locations. |
| Excluir (Delete) | Removes the rules. |
| Limpar seleção (Clear selection) | Clears the selection of all rules. |

:::caution
Rewriting a rule restarts the persistence count and the cooldown.
:::

## Rule detail

Select a rule's name to open its detail page. The page has three tabs:

- **Visão geral** (Overview): indicators and chart.
- **Incidentes** (Incidents): this rule's incidents. Refer to [Spike incidents](/en/advisor/deteccao-de-picos/incidentes/).
- **Resposta automática** (Automatic response): the rule's playbook. Refer to [Responses and playbooks](/en/advisor/deteccao-de-picos/respostas-e-playbooks/).

### Indicators

| Indicator | Values |
|---|---|
| Coleta (Collection) | **Ligada** (On), **Atrasada** (Delayed) or **Desligada** (Off). **Atrasada** means more than 20 minutes since the last window. |
| Avaliação (Evaluation) | **Em incidente** (In incident), **Normal** or **Sem avaliação** (Not evaluated). |
| Baseline | **Aquecendo** (Warming up) or **Pronto** (Ready), with collected over expected samples and the percentage. The rule only fires with 80% of the samples. |
| Calibração (Calibration) | The period in days, with incidents, false positives and median detection time. |
| Alerta (Alert) | **Observação**, **Ligado** (On) or **Sem destino** (No destination). |

:::tip
Use **Calibração** to tune the threshold. Every incident marked as a false positive counts toward it.
:::

### Janelas × requisições chart (Windows × requests)

The chart shows each 5-minute window against what is normal for that time of day. Pick the range: **6 h**, **24 h** (default), **3 dias** (3 days) or **7 dias** (7 days).

| Legend | What it is |
|---|---|
| Requisições na janela (Requests in the window) | Each window's volume. |
| Limiar do alerta (mediana do horário + %) (Alert threshold, time-of-day median + %) | The value above which a window is anomalous. |
| Mediana do horário (normal) (Time-of-day median, normal) | The baseline. |
| Piso de volume (Volume floor) | The minimum volume to evaluate. |
| Janela anômala (Anomalous window) | A window above the threshold. |
| Incidente (Incident) | When an incident was opened. |

For IP rules, use the **IP** field to pick the subject shown in the chart.

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/deteccao-de-picos/regras/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
