I ended up whitelisting the component to stop the triggers. I know this isn't an Admin Tools issue, but I ould like some help trying to understand what Admin Tools may be seeing as a threat. In the other ticket the issue was XSSSHIELD being triggered. Now, on a different site, it's CSRF Shield being triggered. Again, I've whitelisted the component and, hopefully, that'll be the end of it. Though I'm bothered about why the analytics component would be triggering something which I read is related to form submission.
EDIT: Just had an idea where the form comes in. The site in question - www.lincolnchamber.com - has another component jBusinessDirectory (not the same author) which has a search form that may be used when looking for a member (rather than clicking through everyone). The office manager mentioned the blocking occurred while looking through the directory - possibly by submitting the search form. Yet the target URL listed in Admin Tools was https://www.lincolnchamber.com/index.php?option=com_jrealtimeanalytics&format=json.
I've written to the analytics component developer too though, last time, I kind of got the brush off - or it felt like it. That's why I'm also trying to gain some insight if I get another such reply!
Appreciate your help.