Cx Alerts

coralogix/cx-cli/skills/cx-alerts

作者 coralogixc0713729787b無授權條款121 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫昨天更新

This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts", "check which alerts are active", "find alerting rules", "set up an alert", "configure alerting", "mute an alert", "silence an alert", "see alert definitions", "check alert priority", or wants to manage Coralogix alert definitions using the cx CLI.

僅含說明DevOps & Cloud
AI 產生的概覽

使用 cx CLI 管理 Coralogix 告警定義:列出、建立、刪除、啟用、停用並調查告警。

功能
此技能引導代理使用 cx alerts 命令列工具管理 Coralogix 告警定義。涵蓋告警的列出、檢視、建立、刪除、啟用與停用,以及抑制規則管理和告警事件檢視。它提供日誌、指標與追蹤告警類型的 JSON 承載範例、優先順序說明,以及告警結構描述、DataPrime、PromQL、日誌與跨度等參考檔案。
適用情境
適用於使用者想要建立、列出、刪除、啟用、停用或檢視 Coralogix 告警,或調查哪些告警正在觸發的情況。也適合設定抑制規則以及檢視告警優先順序或定義。
執行需求
需要已通過驗證的 Coralogix 設定檔的 cx CLI,並能存取 Coralogix 網路;建議使用 jq 篩選 JSON 輸出。此技能不隨附指令碼,僅包含指示與參考文件。

Alert Management Skill

Use this skill to list, inspect, create, delete, enable, and disable Coralogix alert definitions using the cx alerts CLI commands.

CLI Commands

CommandPurposeKey flags
cx alerts listList all alert definitions--name <filter>
cx alerts get <id>Get a single alert definition by ID-
cx alerts createCreate an alert from a JSON definition--from-file <path> (default: stdin)
cx alerts delete <id>Delete an alert-
cx alerts enable <id>Enable an alert-
cx alerts disable <id>Disable an alert-
cx alerts eventsList events; use alert-version scoped endpoint when filtering--alert-version-id, --start, --end
cx alerts event-statsGet alert event statistics-
cx alerts suppression-rules listList suppression rules-
cx alerts suppression-rules get <id>Get a suppression rule-
cx alerts suppression-rules createCreate a suppression rule--from-file <path>
cx alerts suppression-rules updateUpdate a suppression rule--from-file <path>
cx alerts suppression-rules delete <id>Delete a suppression rule-

Output format: append -o json or -o toon to list, get, and create commands for machine-readable output.

Multi-profile: use -p <profile> (repeatable) to target multiple profiles simultaneously.

Alert Types Reference

Coralogix supports 12 alert types:

Type enumHuman nameDescription
ALERT_DEF_TYPE_LOGS_IMMEDIATELogs ImmediateTrigger on every matching log entry
ALERT_DEF_TYPE_LOGS_THRESHOLDLogs ThresholdTrigger when log count exceeds a threshold in a time window
ALERT_DEF_TYPE_LOGS_ANOMALYLogs AnomalyML-based anomaly detection on log volume
ALERT_DEF_TYPE_LOGS_RATIO_THRESHOLDLogs Ratio ThresholdTrigger on ratio between two log queries
ALERT_DEF_TYPE_LOGS_NEW_VALUELogs New ValueTrigger when a new value appears in a field
ALERT_DEF_TYPE_LOGS_UNIQUE_COUNTLogs Unique CountTrigger on unique value count threshold
ALERT_DEF_TYPE_LOGS_TIME_RELATIVE_THRESHOLDLogs Time RelativeCompare current vs past time window
ALERT_DEF_TYPE_METRIC_THRESHOLDMetric ThresholdTrigger when a PromQL expression crosses a threshold
ALERT_DEF_TYPE_METRIC_ANOMALYMetric AnomalyML-based anomaly detection on metrics
ALERT_DEF_TYPE_TRACING_IMMEDIATETracing ImmediateTrigger on every matching span
ALERT_DEF_TYPE_TRACING_THRESHOLDTracing ThresholdTrigger when span count exceeds a threshold
ALERT_DEF_TYPE_FLOWFlowSequence-based alert combining multiple conditions

Priority Levels

Always ask the user what priority to use when creating alerts:

PriorityUse case
P1Critical - pages on-call immediately
P2High - needs attention within the hour
P3Medium - investigate during business hours
P4Low - informational, check when convenient
P5Info - logging/tracking only

Create Workflow

  1. Ask the user what they want to alert on (logs, metrics, traces)
  2. Ask for priority (P1–P5)
  3. Build the JSON payload with alertDefProperties - use the API wire format (see references/alert-schemas.md for all enum values)
  4. Tip: use cx alerts get <existing-id> -o json to get a working template, modify it, and pipe into create
  5. Create using: echo '<json>' | cx alerts create or cx alerts create --from-file alert.json
  6. Verify with cx alerts list --name "<alert name>"

Important structural note: The type field is a string enum (e.g. "ALERT_DEF_TYPE_LOGS_THRESHOLD"), and the alert type config (e.g. "logsThreshold": {...}) is a sibling field at the same level - NOT nested inside type.

Example: Logs Threshold Alert

json
{  "alertDefProperties": {    "name": "High Error Rate",    "description": "Alert when error logs exceed threshold",    "priority": "ALERT_DEF_PRIORITY_P2",    "type": "ALERT_DEF_TYPE_LOGS_THRESHOLD",    "enabled": true,    "logsThreshold": {      "logsFilter": {        "simpleFilter": {          "luceneQuery": "severity:ERROR",          "labelFilters": {            "applicationName": [              { "operation": "LOG_FILTER_OPERATION_TYPE_IS_OR_UNSPECIFIED", "value": "my-app" }            ]          }        }      },      "rules": [{        "condition": {          "conditionType": "LOGS_THRESHOLD_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED",          "threshold": 100,          "timeWindow": {            "logsTimeWindowSpecificValue": "LOGS_TIME_WINDOW_VALUE_MINUTES_5_OR_UNSPECIFIED"          }        }      }]    }  }}

Example: Metric Threshold Alert

json
{  "alertDefProperties": {    "name": "CPU Usage Critical",    "priority": "ALERT_DEF_PRIORITY_P1",    "type": "ALERT_DEF_TYPE_METRIC_THRESHOLD",    "enabled": true,    "metricThreshold": {      "metricFilter": { "promql": "avg(cpu_usage_percent)" },      "rules": [{        "condition": {          "conditionType": "METRIC_THRESHOLD_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED",          "threshold": 90,          "ofTheLast": { "dynamicDuration": "5m" },          "forOverPct": 100        }      }]    }  }}

Example: Logs Immediate Alert

json
{  "alertDefProperties": {    "name": "OOM Killer Detected",    "description": "Alert immediately when OOM killer runs",    "priority": "ALERT_DEF_PRIORITY_P1",    "type": "ALERT_DEF_TYPE_LOGS_IMMEDIATE_OR_UNSPECIFIED",    "enabled": true,    "logsImmediate": {      "logsFilter": {        "simpleFilter": {          "luceneQuery": "\"Out of memory\" OR \"OOM\"",          "labelFilters": {}        }      }    }  }}

Investigation Workflow

Find firing alerts

bash
# List all alerts and look for ALERTING statuscx alerts list -o json | jq '.[] | select(.status == "ALERTING")'
# Filter by namecx alerts list --name "error"

Inspect a specific alert

bash
cx alerts get <alert-id>cx alerts get <alert-id> -o json

Disable a noisy alert (temporary mute)

bash
cx alerts disable <alert-id># Later, re-enable:cx alerts enable <alert-id>

Suppression Rules

Manage alert suppression rules that mute alerts during maintenance windows or known noisy periods.

CommandPurpose
cx alerts suppression-rules listList all suppression rules
cx alerts suppression-rules get <id>Get a suppression rule by ID
cx alerts suppression-rules create --from-fileCreate a suppression rule
cx alerts suppression-rules update --from-fileUpdate a suppression rule
cx alerts suppression-rules delete <id>Delete a suppression rule
bash
# List suppression rulescx alerts suppression-rules list -o json
# Create from templatecx alerts suppression-rules get <existing-id> -o json > suppression-rule.json# Edit suppression-rule.jsoncx alerts suppression-rules create --from-file suppression-rule.json

Key Principles

  • Always ask for priority (P1–P5) when creating alerts - never assume
  • Use --name filter for large accounts with many alerts
  • Use -o json with jq for filtering and transformation
  • Use --from-file - to pipe JSON from stdin when constructing alerts programmatically
  • Verify after create - always list or get the alert after creation to confirm
  • Disable, don't delete - prefer disabling alerts over deletion for auditability
  • Link to a specific alert - cx alerts list prints only one "View in Coralogix" link, to the alerts overview page, not a per-alert link. To link a user to one specific alert, build <base>/alerts/<alert_id>, where <base> is the console URL already seen in a `View in Coralogix: <base>/...` line printed by any `cx alerts` command this session - never fabricate `<base>` yourself.

Additional Resources

Reference Files

  • references/alert-schemas.md [blocked] - Complete JSON schema reference for all 12 alert types: field names, enum values (condition types, time windows, filter operations), common sub-objects (logs filter, tracing filter, notification groups, activity schedules), and important gotchas
  • references/dataprime-reference.md [blocked] - DataPrime query language reference for log-based and span-based alert conditions (filter syntax, operators, severity values)
  • references/logs-querying.md [blocked] - Log data model, field discovery, and query patterns for building log alert conditions
  • references/promql-guidelines.md [blocked] - PromQL reference for metric-based alert conditions (counters, gauges, histograms, threshold patterns)
  • references/spans-querying.md [blocked] - Span data model, duration units, and query patterns for building tracing alert conditions

Related Skills

  • cx-cases - triage the cases that group alert events into investigations
  • cx-slos - the SLO definitions whose error-budget burn raises alerts
  • cx-observability-setup - setting up notification routing and webhook integrations for alerts
  • cx-telemetry-querying - investigate the telemetry behind a firing alert

來源與署名

來源:coralogix/cx-cli位於skills/cx-alerts提交c071372

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架