Skip to main content

Test Premium Value in Your Environment

๐Ÿงช Measure Premium Value During Your Trialโ€‹

Before exploring all Premium features, use this guide to measure and experience the value in your environment. These practical tests help you assess the concrete benefits of Premium during your trial period.


๐ŸŽฏ Test 1: Measure Improved Protectionโ€‹

What to Activateโ€‹

Premium protection features are automatically enabled when you upgrade:

  • Community Blocklist (Premium): Automatically sent to enrolled engines (50k IPs vs 3k)
  • Threat Forecast Blocklist: Generated automatically from your organization's shared signals
  • Premium Tier Blocklists: Subscribe to unlimited specialized blocklists
  • Remediation Sync: Propagate decisions across all Security Engines
  • Am I Under Attack: Get alerted on traffic surges

๐Ÿ“Š Metric 1: Remediation Ratioโ€‹

How to measure: Check your Console dashboard for proactive vs reactive blocking ratio.

Expected result: 2ร— more proactive blocking (blocklist hits vs real-time decisions)

๐Ÿ’ป Metric 2: Server Resourcesโ€‹

How to measure: Monitor CPU, memory, and bandwidth usage on your Security Engines before and after.

Expected result: 75-92% reduction in malicious traffic reaching your servers

๐Ÿ“ Metric 3: Log Volumeโ€‹

How to measure: Check your SIEM or log aggregator for alert volume changes.

Expected result: Cleaner logs, reduced alert fatigue, fewer false positives

Quick Test: Background Noise Filtering

Enable Background Noise Filtering (Low/Medium/High) and compare your alert dashboard before/after. You should see 75-92% fewer scanner and crawler alerts within 24 hours.

24h
to see results
75-92%
noise reduction
Learn more โ†’

๐Ÿ‘ฅ Test 2: Enable Team Collaborationโ€‹

What to Activateโ€‹

Enable team features to see collaboration improvements:

  • Multi-Seat Access: Invite team members (view/edit/admin roles)
  • Extended Alert Retention: 365 days of historical data (vs 60 days)
  • Increased CTI Quotas: 100 IP lookups/week (vs 30)
  • Push Notification Integrations: Slack, PagerDuty, webhooks

Expected Results:

  • โšก Faster incident investigations (direct CTI access in Console)
  • ๐Ÿ” Better threat attribution (1-year retention for pattern analysis)
  • ๐Ÿค Reduced tool sprawl (team works in one place)
  • ๐Ÿ“ข Proactive alerting (issues detected before users complain)

๐Ÿข Test 3: Scale for MSPs & Enterprisesโ€‹

What to Activateโ€‹

Test multi-tenant and automation capabilities:

  • Multi-Organization: Create separate organizations for each client/environment
  • Service API (SAPI): Automate console management
  • Blocklist Creation & Sharing: Distribute custom threat intel via API
  • Auto Enroll: Zero-touch engine enrollment

Test: Multi-Tenant Isolation

100% isolated

Create 2-3 test organizations for different clients. Verify complete data isolation: each org sees only its engines, alerts, and decisions. Test switching between orgs from a single account.

Test: Custom Blocklist via APIAPI

API-driven

Use SAPI to create a custom blocklist with 10-20 IPs from your SIEM. Subscribe multiple organizations to it. Verify the IPs are blocked across all client environments within minutes.

Learn more โ†’

Test: Automated Enrollment

Zero-touch

Enable Auto Enroll, then deploy a new Security Engine with your org's enrollment key. It should automatically join your organization without manual approval. Perfect for Terraform/Ansible/K8s deployments.

Test: Decision Management via APIAPI

Programmatic

Use SAPI to add/remove decisions from the Console. Test forcing a blocklist pull after subscription. Integrate this into your incident response playbooks or SOAR platform.

Learn more โ†’

Expected Results:

  • ๐Ÿ—๏ธ Clear tenant isolation (one org per client)
  • ๐Ÿค– Streamlined multi-customer operations (API automation)
  • ๐Ÿ“Š Custom visibility per client (each org has its own dashboard)
  • โš™๏ธ Infrastructure-as-code ready (zero-touch enrollment)

Week 1: Protectionโ€‹

  • Enable all blocklists
  • Activate Background Noise
  • Turn on Remediation Sync
  • Measure baseline metrics

Week 2: Teamโ€‹

  • Invite team members
  • Test CTI lookups
  • Configure push notifications
  • Analyze historical trends

Week 3: Scaleโ€‹

  • Create test organizations
  • Test SAPI endpoints
  • Try Auto Enroll
  • Custom blocklist sharing

Week 4: Reviewโ€‹

  • Compare metrics vs Week 1
  • Document value realized
  • Plan production rollout
  • Prepare upgrade decision

๐Ÿ’ก Need Help Testing?โ€‹

Questions about your trial?โ€‹

Our team can help you set up proper testing and measure the value in your specific environment.