I would like to be alerted when an interface gets a much higher spike in traffic than we normally see so we can check for DoS attacks or some large copy of files headed outbound. I know the dashboard already has data for traffic averages or highest traffic IP device. The difficulty would be the logical comparision of traffic at any give time with the average traffic on that port at that approx time.