Cloudflare Alert Triage Agent with Claude Code

Cost follows alert volume, which is the one number nobody here controls: a quiet month is a handful of runs and a bad afternoon is dozens inside an hour. Each individual run stays small, a payload read plus health checks and two analytics windows. Claude Code sits at the thorough end of the range, and Cloudflare's own notification policies remain your first filter on how often it wakes.

Loading preview…
Free to start · guided setup

Watch it work before it's live

Run a staged conversation — no account needed. The agent handles it for real while a simulated world answers its tool calls; nothing touches real accounts, and nothing is actually sent.

HTTP DDoS attack detected and mitigated

tienda.bellavia.mxBellavia Retail, account a91c4

Managed rule 6a2f began mitigating at 03:14 UTC. Peak 412,000 requests per second against /checkout/session, 94 percent from three autonomous systems. Mitigation is still active. Nothing in the payload about origin status.

Set up in minutes

Using this template drops you into a guided setup. It asks exactly this, nothing else:

  1. Connect Cloudflare

    One sign-in. The agent acts through your account, scoped to what this template uses.

  2. Connect Slack

    One sign-in. The agent acts through your account, scoped to what this template uses.

  3. Alert rules

    Which Cloudflare alerts deserve a channel post and what each kind means for you - your zones and who owns them, how seriously you take an attack alert next to a health check flip, and where somebody should look first when your origin throws errors or a certificate stops renewing.

  4. Runs on Claude Code

    Preselected for this page — connect your Claude Code account during setup, or switch to NoClick's built-in models with one click.

  5. Watch it handle a test run

    A staged conversation against a simulated world — then it’s live.

Why Claude Code for this agent

Cloudflare filters before we do

Whatever your notification policies already suppress never becomes a run. The routing you spent time tuning keeps working exactly as it does now, one layer above this.

Small runs, unpredictable count

Two analytics windows and a health check list is a modest read. What varies is how many times a week your edge has something to say, which is worth watching for a fortnight before widening.

Before you fork

A sustained attack fires forty notifications in an hour. What does that do?

Forty runs, each a payload read plus analytics for two windows. Bounding it belongs upstream in Cloudflare's notification policy, since collapsing repeated alerts is what that layer is for. Teams usually route attack notifications through a coarser policy and keep health check and certificate alerts at one note each.

Run it with a different agent

Put Cloudflare Alert Triage Agent to work on Claude Code

Free to start. Guided setup, a test run against staged conversations, and it's live.