Protection from day one:
new hosts get built-in CPU and memory safeguards that alert immediately, no baseline-learning wait.
Threshold
detectors need no history and fire the moment a value crosses a fixed, known-bad line, like a disk at 95% full or a container at 95% of its memory limit. While a brand-new host or pod is still building the history an anomaly detector needs, these threshold nets are already watching, so genuine saturation on a fresh entity is caught immediately instead of waiting for a baseline to form.
Fewer false alarms:
tuned anomaly detection so alerts are the ones worth acting on.
Anomaly
detectors learn what normal looks like for each entity from its own recent history and fire only when a reading lands well outside that range, with a
Sensitivity
setting (High, Medium, or Low) to control how tightly that range is drawn. A breach also has to hold for about 30 minutes across several evaluations before it fires, so a brief spike settles on its own instead of paging anyone.
smart-alerts-detectors
Check out the Smart Alerts guide for the full breakdown.