To implement throttling, rules that filter and stop observations are added to the Stop Observation Requests rule group.
This rule group is read only and is assigned to the default read-only Throttling Rules policy. Initially, this policy isn't assigned to any system or group. When the number of observations reaches the defined threshold, this policy is applied to My Organization (all systems and groups in your organization).
On the ePO - On-prem console, select Menu → Policy → Policy Catalog.
Select Solidcore 8.x.x: Application Control for the product.
Click the Throttling Rules policy.
From the Rule Groups pane, select Stop Observation Requests.
Select the Filters tab.
Review the listed rules.