Frequently reviewing and managing requests for the generated observations allows you to define the relevant rules for your setup. If you don't process observations in a timely manner, you continue to get similar and repeated observations from endpoints.
Also, if you place additional endpoints in Observe mode or perform multiple activities simultaneously on existing endpoints (in Observe mode), the absence of relevant rules might result in excessive generation of observations. If a high number of observations are received at the ePO - On-prem server from the endpoints, the ePO - On-prem interface might become sluggish.
Observation throttling helps you take care of the non-responsiveness of the ePO - On-prem interface. When the number of observations received at the ePO - On-prem server reaches the defined threshold, observation throttling is initiated. When observation throttling starts, Application Control performs these actions:
It stops further processing of observations at ePO - On-prem to prevent non-responsiveness of the ePO - On-prem interface.
It applies the Throttling Rules policy to the My Organization group to prevent the generation of observations on all endpoints after agent-server communication interval.
It generates the Observation Request Threshold Exceeded event. This event is displayed on the Threat Event Log page and can be used to create an automatic response.
It displays a warning message on the Policy Discovery page stating that observation generation has stopped.