Understanding Monocle Application Health Status
Each Monocle application shows a health status badge indicating whether it's actively sending traffic. Learn what each color means and what to check if an application goes quiet.
Difficulty
Beginner
No prior Spur experience needed
Time estimate
2 minutes
Typical time to complete
Prerequisites
- A Monocle application set up in your Spur account
What you'll achieve
- Understand what each health status badge means
- Know what to check when an application shows an amber or red status
Steps
- 1
Check the status badge
Each application in your Monocle dashboard shows a colored status badge next to its name:
- Gray — the application has never reported data yet; setup is still in progress
- Green — traffic was observed within the last 24 hours (healthy)
- Amber — no traffic for between 24 and 72 hours; often a temporary quiet stretch rather than a real problem
- Red — no traffic for more than 72 hours (3 days), suggesting Monocle may no longer be installed correctly
- 2
Look for the traffic warning banner
When an application is in amber or red status, a warning banner appears next to the application selector, showing how long it's been quiet. Hover over the banner for the full message.
- 3
Investigate a quiet application
An amber or red status usually means the Monocle snippet is no longer running on the site or app it was installed on — for example after a site redesign or a change to your content security policy. Re-check your installation using your integration's setup guide to confirm the snippet is still present and loading correctly.
Related FAQs & guides
Do you have a confidence score or last seen date?
Spur operates on a "high confidence" only model to reduce the likelihood of false positives ever making it into our data. Our mentality is that our customers should trust us to decide if something is true rather than providing an arbitrary score to constantly adjust higher or lower. Every API request or Monocle session provides the latest true information for that moment in time. On-prem solutions are updated at their purchased cadence (daily or real-time). We actively purge any result that is no longer true and maintain smart age-offs to maintain the most accurate snapshot of data each day.
If Spur identifies a provider such as NetNut, does that mean the traffic originated directly from that provider's customer?
Not necessarily. Proxy ecosystems often involve resellers, downstream providers, SDK operators, and shared infrastructure. A provider label identifies infrastructure associated with the traffic but should not be treated as attribution of a specific end user without additional evidence and investigation.
How is Spur different from traditional IP reputation feeds?
Traditional reputation feeds focus primarily on known malicious activity. Spur focuses on understanding the infrastructure, routing, anonymization technologies, and contextual characteristics behind an IP address, enabling organizations to make more informed decisions even when no prior abuse history exists.
Which delivery option is best for my organization?
The best option depends on:
Does Spur offer downloadable feeds, local deployments, or MMDB-style delivery?
Available delivery methods may vary by product and customer requirements. Organizations with low-latency or high-volume enrichment needs should contact Spur to discuss available deployment and data-delivery options.
What is the difference between online subscriptions and enterprise tiers?
Our enterprise tiers are specifically designed to provide other businesses with package offerings, robust SLAs, custom volumes, support, commercial licensing, and onboarding. Online subscriptions are designed for smaller teams with lower volume and support needs.