Back to Skills

cx-alerts

This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts", "check which alerts are active", "find alerting rules", "set up an alert", "configure alerting", "mute an alert", "silence an alert", "see alert definitions", "check alert priority", or wants to manage Coralogix alert definitions using the cx CLI.

114stars10forksUpdated 8/13/2026

Security Assessment

Safe(92/100)
Security Score92/100

About cx-alerts

cx-alerts is a Coralogix-authored observability skill for managing alert definitions through the cx command-line interface. It solves the friction of hand-authoring the Coralogix alert API wire format by guiding an agent to list, inspect, create, delete, enable, disable, and mute alerts, plus manage suppression rules and inspect alert events and statistics. It maps natural-language requests such as create alert, investigate firing alerts, or silence an alert onto the correct cx subcommands and flags.

The skill documents the full cx alerts command surface, including list/get/create/delete/enable/disable, events and event-stats, and suppression-rules CRUD, with machine-readable output via -o json or -o agents and multi-profile targeting via -p. It enumerates the 12 Coralogix alert types (logs immediate/threshold/anomaly/ratio/new-value/unique-count/time-relative, metric threshold/anomaly, tracing immediate/threshold, and flow) and P1-P5 priority levels, and prescribes a create workflow that asks the user what to alert on and at what priority, builds the JSON payload in the API wire format, and verifies the result. Reference files cover DataPrime, PromQL, logs and spans querying, and alert schemas, including guidance on the span data model, field discovery, and duration units.

It is aimed at SREs, platform engineers, and developers who run Coralogix and want to manage alerting from an agent. Operations are performed through the official cx CLI against the user's own account and profiles, and the querying references are read-only investigative helpers.

FAQ

What can it do with alerts?

List, get, create, delete, enable, disable, and mute alert definitions, manage suppression rules, and inspect alert events and event statistics, all through the cx alerts CLI.

How are alerts created?

The workflow asks what to alert on (logs, metrics, or traces) and the priority (P1-P5), builds a JSON payload in the Coralogix API wire format, then creates it via stdin or --from-file and verifies with cx alerts list. A tip is to clone an existing alert with get -o json as a template.

What alert types are supported?

Twelve types: logs immediate, threshold, anomaly, ratio threshold, new value, unique count, and time relative; metric threshold and anomaly; tracing immediate and threshold; and flow.

Can I target multiple environments at once?

Yes. Use the repeatable -p <profile> flag to target multiple profiles simultaneously, and append -o json or -o agents for machine-readable output.

Does it require the cx CLI installed?

Yes. The skill drives the Coralogix cx CLI, which must be installed and configured with your account profiles; querying references cover DataPrime, PromQL, and logs/spans investigation.

All Files

6 files
references/spans-querying.md11.1 KB
View
references/promql-guidelines.md7.8 KB
View
references/alert-schemas.md19.8 KB
View
references/dataprime-reference.md10.7 KB
View
references/logs-querying.md9.0 KB
View
SKILL.md9.3 KB
View

Install cx-alerts

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill