Content Analysis (CA) is a crucial part of Blue Coat's Advanced Threat Protection (ATP) solutions suite. To take full advantage of its power, it's important to understand, enable, configure, and monitor various modules that can make an administrator's life much easier and save hours of digging through logs and analyzing data mined from those logs.
The purpose of ICTM is to warn the administrator when the CA systems under his/her care become too busy to be as effective as possible. ICTM is a tool to make administrators more proactive without having to constantly monitor every CA system in the environment.
To solve problems before they arise, the administrator should understand how ICTM is properly setup. That means to change the default values in 2 of the fields we see when navigating to Settings > ICTM.
The fields to change are explained in the following images.