Integrations
Cloudflare
EvoHub receives Cloudflare notifications through a webhook destination. Any notification policy that uses the destination opens an EvoHub alert. Alerts with a start and an end, such as DDoS attacks, resolve when Cloudflare sends the end event.
Set it up
Create the integration
In EvoHub, go to On-Call → Integrations → + Add Integration, choose Cloudflare, pick an Escalation Policy and click Create Integration. Copy the Webhook URL.
Create the destination
In the Cloudflare dashboard, go to Notifications → Destinations → Webhooks → Create. Name it, set URL to your webhook URL and leave Secret empty — the key in the URL authenticates the call.
What EvoHub reads
| EvoHub alert | Taken from |
|---|---|
| Title | policy_name (or name). |
| Description | text, Cloudflare's description of the notification. |
| Labels | alert_type, account_id, policy_id, the alert's data fields (zone, hostname, attack type and so on), and url when the data carries a dashboard link. |
| Fingerprint | alert_correlation_id; for health checks the health check ID; otherwise the policy and alert type. |
Severity
| Alert type | EvoHub severity |
|---|---|
Contains ddos, origin or health_check |
high |
| Anything else | medium |
Resolve and deduplication
alert_event: ALERT_STATE_EVENT_ENDresolves the alert that the matching start event opened.- A health check notification whose new status is Healthy resolves the open alert for that health check.
- One-off notices, such as certificate expiry or usage notifications, have no end event and stay open until resolved in EvoHub.
PENDINGevents (Workers observability) are ignored.
Related
Was this page helpful?
