Agent skill

Cx Alerts

by coralogix in coralogix/cx-cli

This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts"…

Apache-2.0Auto-check passedDevOps & Cloud

Install Cx Alerts

skills CLI
$ npx skills add coralogix/cx-cli --skill cx-alerts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coralogix/cx-cli cx-alerts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coralogix/cx-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cx-alerts .claude/skills/cx-alerts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cx-alerts
GitHub stars
121
Token cost
~2.5k tokens
SKILL.md length
814 words
Files
6 (incl. references)
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts"…

  • Works in 6 steps: Ask the user what they want to alert on… → Ask for priority (P1–P5) → Build the JSON payload with… → …
  • Asks to manage alerts
  • SKILL.md covers CLI Commands, Alert Types Reference, Priority Levels and Create Workflow, plus 4 more sections
  • Calls jq

What it does

Cx Alerts is an agent skill from coralogix/cx-cli. This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts", "check which alerts are active", "find alerting rules", "set up an alert", "configure alerting", "mute an alert", "silence an alert", "see alert definitions", "check alert priority", or wants to manage Coralogix alert definitions using the cx CLI.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/alert-schemas.md`, `references/dataprime-reference.md` and `references/logs-querying.md`).

It sits in DevOps & Cloud. The repository describes itself as: This is the Coralogix CLI. The licence is Apache-2.0.

When your agent uses it

  • Asks to manage alerts
  • Check alert status
  • Investigate firing alerts
  • Check which alerts are active

Example prompts

  • “manage alerts”
  • “create alert”
  • “list alerts”
  • “/cx-alerts”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Ask the user what they want to alert on (logs, metrics, traces)
  2. Ask for priority (P1–P5)
  3. Build the JSON payload with alertDefProperties - use the API wire format (see references/alert-schemas.md for all enum values)
  4. Tip: use cx alerts get -o json to get a working template, modify it, and pipe into create
  5. Create using: echo '' | cx alerts create or cx alerts create --from-file alert.json
  6. Verify with cx alerts list --name ""

What it can do on your machine

Read from SKILL.md and the folder at commit c071372. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cx Alerts loads about 2.5k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 814 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coralogix/cx-cli at commit c071372, republished under its Apache-2.0 licence (© coralogix). 814 words, ~2,477 tokens.

Download SKILL.mdSave it as .claude/skills/cx-alerts/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
cx-alerts
description
This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts", "check which alerts are active", "find alerting rules", "set up an alert", "configure alerting", "mute an alert", "silence an alert", "see alert definitions", "check alert priority", or wants to manage Coralogix alert definitions using the cx CLI.
metadata.version
0.1.0

Alert Management Skill

Use this skill to list, inspect, create, delete, enable, and disable Coralogix alert definitions using the cx alerts CLI commands.

CLI Commands

CommandPurposeKey flags
cx alerts listList all alert definitions--name <filter>
cx alerts get <id>Get a single alert definition by ID-
cx alerts createCreate an alert from a JSON definition--from-file <path> (default: stdin)
cx alerts delete <id>Delete an alert-
cx alerts enable <id>Enable an alert-
cx alerts disable <id>Disable an alert-
cx alerts eventsList events; use alert-version scoped endpoint when filtering--alert-version-id, --start, --end
cx alerts event-statsGet alert event statistics-
cx alerts suppression-rules listList suppression rules-
cx alerts suppression-rules get <id>Get a suppression rule-
cx alerts suppression-rules createCreate a suppression rule--from-file <path>
cx alerts suppression-rules updateUpdate a suppression rule--from-file <path>
cx alerts suppression-rules delete <id>Delete a suppression rule-

Output format: append -o json or -o toon to list, get, and create commands for machine-readable output.

Multi-profile: use -p <profile> (repeatable) to target multiple profiles simultaneously.

Alert Types Reference

Coralogix supports 12 alert types:

Type enumHuman nameDescription
ALERT_DEF_TYPE_LOGS_IMMEDIATELogs ImmediateTrigger on every matching log entry
ALERT_DEF_TYPE_LOGS_THRESHOLDLogs ThresholdTrigger when log count exceeds a threshold in a time window
ALERT_DEF_TYPE_LOGS_ANOMALYLogs AnomalyML-based anomaly detection on log volume
ALERT_DEF_TYPE_LOGS_RATIO_THRESHOLDLogs Ratio ThresholdTrigger on ratio between two log queries
ALERT_DEF_TYPE_LOGS_NEW_VALUELogs New ValueTrigger when a new value appears in a field
ALERT_DEF_TYPE_LOGS_UNIQUE_COUNTLogs Unique CountTrigger on unique value count threshold
ALERT_DEF_TYPE_LOGS_TIME_RELATIVE_THRESHOLDLogs Time RelativeCompare current vs past time window
ALERT_DEF_TYPE_METRIC_THRESHOLDMetric ThresholdTrigger when a PromQL expression crosses a threshold
ALERT_DEF_TYPE_METRIC_ANOMALYMetric AnomalyML-based anomaly detection on metrics
ALERT_DEF_TYPE_TRACING_IMMEDIATETracing ImmediateTrigger on every matching span
ALERT_DEF_TYPE_TRACING_THRESHOLDTracing ThresholdTrigger when span count exceeds a threshold
ALERT_DEF_TYPE_FLOWFlowSequence-based alert combining multiple conditions

Priority Levels

Always ask the user what priority to use when creating alerts:

PriorityUse case
P1Critical - pages on-call immediately
P2High - needs attention within the hour
P3Medium - investigate during business hours
P4Low - informational, check when convenient
P5Info - logging/tracking only

Create Workflow

  1. Ask the user what they want to alert on (logs, metrics, traces)
  2. Ask for priority (P1–P5)
  3. Build the JSON payload with alertDefProperties - use the API wire format (see references/alert-schemas.md for all enum values)
  4. Tip: use cx alerts get <existing-id> -o json to get a working template, modify it, and pipe into create
  5. Create using: echo '<json>' | cx alerts create or cx alerts create --from-file alert.json
  6. Verify with cx alerts list --name "<alert name>"

Important structural note: The type field is a string enum (e.g. "ALERT_DEF_TYPE_LOGS_THRESHOLD"), and the alert type config (e.g. "logsThreshold": {...}) is a sibling field at the same level - NOT nested inside type.

Example: Logs Threshold Alert
json
{
  "alertDefProperties": {
    "name": "High Error Rate",
    "description": "Alert when error logs exceed threshold",
    "priority": "ALERT_DEF_PRIORITY_P2",
    "type": "ALERT_DEF_TYPE_LOGS_THRESHOLD",
    "enabled": true,
    "logsThreshold": {
      "logsFilter": {
        "simpleFilter": {
          "luceneQuery": "severity:ERROR",
          "labelFilters": {
            "applicationName": [
              { "operation": "LOG_FILTER_OPERATION_TYPE_IS_OR_UNSPECIFIED", "value": "my-app" }
            ]
          }
        }
      },
      "rules": [{
        "condition": {
          "conditionType": "LOGS_THRESHOLD_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED",
          "threshold": 100,
          "timeWindow": {
            "logsTimeWindowSpecificValue": "LOGS_TIME_WINDOW_VALUE_MINUTES_5_OR_UNSPECIFIED"
          }
        }
      }]
    }
  }
}
Example: Metric Threshold Alert
json
{
  "alertDefProperties": {
    "name": "CPU Usage Critical",
    "priority": "ALERT_DEF_PRIORITY_P1",
    "type": "ALERT_DEF_TYPE_METRIC_THRESHOLD",
    "enabled": true,
    "metricThreshold": {
      "metricFilter": { "promql": "avg(cpu_usage_percent)" },
      "rules": [{
        "condition": {
          "conditionType": "METRIC_THRESHOLD_CONDITION_TYPE_MORE_THAN_OR_UNSPECIFIED",
          "threshold": 90,
          "ofTheLast": { "dynamicDuration": "5m" },
          "forOverPct": 100
        }
      }]
    }
  }
}
Example: Logs Immediate Alert
json
{
  "alertDefProperties": {
    "name": "OOM Killer Detected",
    "description": "Alert immediately when OOM killer runs",
    "priority": "ALERT_DEF_PRIORITY_P1",
    "type": "ALERT_DEF_TYPE_LOGS_IMMEDIATE_OR_UNSPECIFIED",
    "enabled": true,
    "logsImmediate": {
      "logsFilter": {
        "simpleFilter": {
          "luceneQuery": "\"Out of memory\" OR \"OOM\"",
          "labelFilters": {}
        }
      }
    }
  }
}

Investigation Workflow

Find firing alerts
bash
# List all alerts and look for ALERTING status
cx alerts list -o json | jq '.[] | select(.status == "ALERTING")'

# Filter by name
cx alerts list --name "error"
Inspect a specific alert
bash
cx alerts get <alert-id>
cx alerts get <alert-id> -o json
Show full SKILL.md (327 more words)Show less
Disable a noisy alert (temporary mute)
bash
cx alerts disable <alert-id>
# Later, re-enable:
cx alerts enable <alert-id>

Suppression Rules

Manage alert suppression rules that mute alerts during maintenance windows or known noisy periods.

CommandPurpose
cx alerts suppression-rules listList all suppression rules
cx alerts suppression-rules get <id>Get a suppression rule by ID
cx alerts suppression-rules create --from-fileCreate a suppression rule
cx alerts suppression-rules update --from-fileUpdate a suppression rule
cx alerts suppression-rules delete <id>Delete a suppression rule
bash
# List suppression rules
cx alerts suppression-rules list -o json

# Create from template
cx alerts suppression-rules get <existing-id> -o json > suppression-rule.json
# Edit suppression-rule.json
cx alerts suppression-rules create --from-file suppression-rule.json

Key Principles

  • Always ask for priority (P1–P5) when creating alerts - never assume
  • Use --name filter for large accounts with many alerts
  • Use -o json with jq for filtering and transformation
  • Use --from-file - to pipe JSON from stdin when constructing alerts programmatically
  • Verify after create - always list or get the alert after creation to confirm
  • Disable, don't delete - prefer disabling alerts over deletion for auditability
  • Link to a specific alert - cx alerts list prints only one "View in Coralogix" link, to the alerts overview page, not a per-alert link. To link a user to one specific alert, build <base>/alerts/<alert_id>, where <base> is the console URL already seen in a `View in Coralogix:
    <base>/...` line printed by any `cx alerts` command this session - never
    fabricate `<base>` yourself.

Additional Resources

Reference Files
  • references/alert-schemas.md - Complete JSON schema reference for all 12 alert types: field names, enum values (condition types, time windows, filter operations), common sub-objects (logs filter, tracing filter, notification groups, activity schedules), and important gotchas
  • references/dataprime-reference.md - DataPrime query language reference for log-based and span-based alert conditions (filter syntax, operators, severity values)
  • references/logs-querying.md - Log data model, field discovery, and query patterns for building log alert conditions
  • references/promql-guidelines.md - PromQL reference for metric-based alert conditions (counters, gauges, histograms, threshold patterns)
  • references/spans-querying.md - Span data model, duration units, and query patterns for building tracing alert conditions
  • cx-cases - triage the cases that group alert events into investigations
  • cx-slos - the SLO definitions whose error-budget burn raises alerts
  • cx-observability-setup - setting up notification routing and webhook integrations for alerts
  • cx-telemetry-querying - investigate the telemetry behind a firing alert

© coralogix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/cx-alerts of coralogix/cx-cli.

  • SKILL.md
  • references/alert-schemas.md
  • references/dataprime-reference.md
  • references/logs-querying.md
  • references/promql-guidelines.md
  • references/spans-querying.md

Open the folder on GitHubat commit c071372

Compare with similar skills

Cx Alerts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cx Alerts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cx Alerts this skillcoralogix/cx-cli121—~2.5kAutomated safety check: PassApache-2.0
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from coralogix/cx-cli

All 21 skills in this repo
  • Cx AI Center

    coralogix/cx-cli

    A skill your agent uses for any question or action about the user's AI/GenAI applications or agents — their behavior, prompts/responses, quality, hallucinations, guardrails, security, cost/tokens…

    121 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Coding Agents

    coralogix/cx-cli

    A skill your agent uses when the user asks about AI Center Coding Agents data, wants to reproduce or extend the Coding Agents dashboards, or asks questions about usage, cost, tokens, sessions…

    121 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Cost Optimization

    coralogix/cx-cli

    A skill your agent uses when the user asks to "check data usage", "list TCO policies", "reduce Coralogix costs", "optimize observability spend", "lower our logging bill", "data budget exceeded"…

    121 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Data Pipeline

    coralogix/cx-cli

    A skill your agent uses when the user asks to "set up parsing", "create parsing rule", "extract fields from logs", "regex extraction", "log parsing", "enrich logs", "add context to logs", "custom…

    121 GitHub stars~3k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Telemetry Querying

    coralogix/cx-cli

    A skill your agent uses for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior"…

    121 GitHub stars~2.6k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Dashboards

    coralogix/cx-cli

    Build and deploy a Coralogix dashboard for a given service from its logs, spans, metrics, and service specs.

    121 GitHub stars~4.7k tokensUpdated 4 days ago
    Auto-check: warnings

Categories

Questions about Cx Alerts

What does Cx Alerts do?

This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts"…. Cx Alerts is an agent skill from coralogix/cx-cli. This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts", "check which alerts are active", "find alerting rules", "set up an alert", "configure alerting", "mute an alert", "silence an alert", "see alert definitions", "check alert priority", or wants to manage Coralogix alert definitions using the cx CLI.

When should I use Cx Alerts?

Cx Alerts fits situations like: asks to manage alerts; check alert status; investigate firing alerts; check which alerts are active.

How do I install Cx Alerts in Claude Code?

Run `npx skills add coralogix/cx-cli --skill cx-alerts -a claude-code`. Or copy the skill folder (skills/cx-alerts in coralogix/cx-cli) into .claude/skills/cx-alerts in your project. Claude Code loads it when a task matches its description.

How do I install Cx Alerts in Codex?

Run `npx skills add coralogix/cx-cli --skill cx-alerts -a codex`. Or copy the skill folder (skills/cx-alerts in coralogix/cx-cli) into .agents/skills/cx-alerts in your project. Codex loads it when a task matches its description.

Can I use Cx Alerts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coralogix/cx-cli --skill cx-alerts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cx-alerts, .gemini/skills/cx-alerts, .github/skills/cx-alerts and .opencode/skills/cx-alerts in your project.

What does Cx Alerts need to run?

Going by SKILL.md and its folder, Cx Alerts needs the command-line tools its instructions call (jq).

Does Cx Alerts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cx Alerts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cx Alerts use?

Cx Alerts is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cx Alerts use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Cx Alerts?

Skills that share tags, products or a category with Cx Alerts: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cx Alerts?

coralogix (a GitHub organization) maintains it in coralogix/cx-cli, which has 121 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: coralogix/cx-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.