Hello @Balaji01 , threshold values usually depend on your observability goals. There are no values “fit them all” that we want to recommend. Usually practice is to observe these existing statistics and then to setup alert when you identify an unexpected grow or decrease beyond 10-15% which might indicate an unauthorized activity or malfunction (such as lost of connectivity) respectively. However, it is very much depend on your business case and volumes. You might also want to be notified about additional incidents.