Plans and limits
This page explains what your EyalSec plan sets: which products you have, how many machines you can add, how many events each list shows, and whether you can block actions with Raise. It also covers how to get more.
What a plan sets
Your plan is set for your account by EyalSec. Most of EyalSec works the same on every plan; a plan decides four things.
| Setting | What it controls |
|---|---|
| Products | Which products you can use. es-python is included by default; es-chromium is added per plan. |
| Machine limit | How many machines you can add, counted separately for each product. |
| Event quota | How many events each events list shows per calendar month. |
| Raise | Whether you can add rules that block actions, not only report them. |
There is no self-service upgrade button and no billing page in the dashboard. To change any of these, email sales@eyalsec.com; see How to get more.
A new account has no plan yet
An account you register yourself starts with no plan: it can sign in, but its machine limit and event quota are both zero. Every dashboard page shows a banner saying so, and adding a machine is refused with this message:
Your account has no active plan yet, so it cannot add machines.
Book a live demo or email sales@eyalsec.com to get set up.
Email sales@eyalsec.com to book a live demo and have your plan sized. An account created from an invitation usually arrives with its plan already set.
Products
Each product is switched on or off for your account separately. es-python is on by default; es-chromium is on when your plan includes it.
A product you have gets its own events list, its own machines and its own settings pages. A product you do not have is simply not shown. Both products, and what happens when one is switched off, are described on Products.
Machine limit
The machine limit is how many machines you can have for each product. It applies to each product separately: a limit of 5 means up to 5 es-python machines and up to 5 es-chromium machines, not 5 in total.
Every machine you have added counts, whether or not it is installed yet. The line above the list on the Machines page shows how many you are using, for example 3/5 machines, or one count per product when you have several.
When you try to add a machine past the limit, it is refused with:
Machine limit reached (5). Contact sales@eyalsec.com to upgrade your plan.
The number is your limit. Deleting a machine you no longer need frees its slot straight away; see Delete a machine. To raise the limit, contact sales.
Event quota
The event quota is how many events (rows in the list) each events list shows per calendar month. It is a display cap: it limits what you see in the list, not what EyalSec collects and not what you pay.
- Rows, not repeats. The quota counts event rows. A repeat of an event that is already shown only raises that row's count and uses no quota. How finely events are split into rows is your Unique event setting, so a finer setting fills the quota sooner.
- Per list. Each product's list has its own quota at the full value. A busy es-python fleet never uses up the room for your browser events, and adding a product adds a whole new quota.
- Per month. Each calendar month starts fresh, counted by when an event was first seen. The first events of a month are shown, up to the quota; events past that are kept but not shown. They stay hidden after the month ends, while the new month starts with fresh room.
- Nothing is deleted. Events past the quota are stored. If your quota is raised, they appear.
When you scroll to the end of a list, the footer reminds you of the quota, for example "Your plan shows the first 5,000 events in this view each month." A raise lifts the quota on every list at once.
What you pay for
Your bill is based on the machines you have and on detections. A detection is each time EyalSec reports untrusted data reaching a sink, including repeats that only raise an existing event's count. It is not based on how many rows your list shows.
So the event quota and how finely events are grouped (which you choose under Unique event) change what you see, never what you pay. Events a Don't send rule drops are never sent, so they are not detections. Raise, where enabled, is priced on top. The public pricing page explains how machines and detections are priced.
Raise
Raise lets a rule block a risky action instead of only reporting it: the program gets an error and the action does not run. It must be enabled on your account before you can add a Raise rule.
Until it is, adding a Raise rule is refused with:
Raise rules are not enabled for your account. Ask an administrator to enable them.
Email sales@eyalsec.com to have it enabled. Reporting works on every account either way. How Raise works is on Report and Raise, and Raise rules on Rules.
How to get more
To raise your machine limit or event quota, add a product, or enable Raise, email sales@eyalsec.com and say what you need. EyalSec changes it for you.
When changes take effect
Plan changes take effect on the dashboard at your next page load or request: a higher machine limit unlocks, a new product's list appears, Raise becomes available. You do not need to sign out or reinstall anything on your machines.
The agents on your machines are the one exception. When a product is switched off, its agents can keep sending events for up to a minute before they are refused. For any other question about your account, email support@eyalsec.com; see Getting help.