Alert Management Skill
Use this skill to list, inspect, create, delete, enable, and disable Coralogix alert definitions using the cx alerts CLI commands.
CLI Commands
Output format: append -o json or -o toon to list, get, and create commands for machine-readable output.
Multi-profile: use -p <profile> (repeatable) to target multiple profiles simultaneously.
Alert Types Reference
Coralogix supports 12 alert types:
Priority Levels
Always ask the user what priority to use when creating alerts:
Create Workflow
- Ask the user what they want to alert on (logs, metrics, traces)
- Ask for priority (P1–P5)
- Build the JSON payload with
alertDefProperties- use the API wire format (seereferences/alert-schemas.mdfor all enum values) - Tip: use
cx alerts get <existing-id> -o jsonto get a working template, modify it, and pipe into create - Create using:
echo '<json>' | cx alerts createorcx alerts create --from-file alert.json - Verify with
cx alerts list --name "<alert name>"
Important structural note: The type field is a string enum (e.g. "ALERT_DEF_TYPE_LOGS_THRESHOLD"), and the alert type config (e.g. "logsThreshold": {...}) is a sibling field at the same level - NOT nested inside type.
Example: Logs Threshold Alert
Example: Metric Threshold Alert
Example: Logs Immediate Alert
Investigation Workflow
Find firing alerts
Inspect a specific alert
Disable a noisy alert (temporary mute)
Suppression Rules
Manage alert suppression rules that mute alerts during maintenance windows or known noisy periods.
Key Principles
- Always ask for priority (P1–P5) when creating alerts - never assume
- Use
--namefilter for large accounts with many alerts - Use
-o jsonwithjqfor filtering and transformation - Use
--from-file -to pipe JSON from stdin when constructing alerts programmatically - Verify after create - always list or get the alert after creation to confirm
- Disable, don't delete - prefer disabling alerts over deletion for auditability
- Link to a specific alert -
cx alerts listprints only one "View in Coralogix" link, to the alerts overview page, not a per-alert link. To link a user to one specific alert, build<base>/alerts/<alert_id>, where<base>is the console URL already seen in a `View in Coralogix: <base>/...` line printed by any `cx alerts` command this session - never fabricate `<base>` yourself.
Additional Resources
Reference Files
references/alert-schemas.md[blocked] - Complete JSON schema reference for all 12 alert types: field names, enum values (condition types, time windows, filter operations), common sub-objects (logs filter, tracing filter, notification groups, activity schedules), and important gotchasreferences/dataprime-reference.md[blocked] - DataPrime query language reference for log-based and span-based alert conditions (filter syntax, operators, severity values)references/logs-querying.md[blocked] - Log data model, field discovery, and query patterns for building log alert conditionsreferences/promql-guidelines.md[blocked] - PromQL reference for metric-based alert conditions (counters, gauges, histograms, threshold patterns)references/spans-querying.md[blocked] - Span data model, duration units, and query patterns for building tracing alert conditions
Related Skills
cx-cases- triage the cases that group alert events into investigationscx-slos- the SLO definitions whose error-budget burn raises alertscx-observability-setup- setting up notification routing and webhook integrations for alertscx-telemetry-querying- investigate the telemetry behind a firing alert


