# Cloudflare

EvoHub receives Cloudflare notifications through a **webhook destination**. Any notification policy that uses the destination opens an EvoHub alert. Alerts with a start and an end, such as DDoS attacks, resolve when Cloudflare sends the end event.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **Cloudflare**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**.
### Create the destination
In the Cloudflare dashboard, go to **Notifications → Destinations → Webhooks → Create**. Name it, set **URL** to your webhook URL and leave **Secret** empty — the key in the URL authenticates the call.
### Test and save
Save and test the webhook. Cloudflare's "Hello World" test is answered with success and opens no alert.
### Use it in notifications
Go to **Notifications → All Notifications → Add**, pick the alert type and select the webhook destination.
:::

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | `policy_name` (or `name`). |
| Description | `text`, Cloudflare's description of the notification. |
| Labels | `alert_type`, `account_id`, `policy_id`, the alert's `data` fields (zone, hostname, attack type and so on), and `url` when the data carries a dashboard link. |
| Fingerprint | `alert_correlation_id`; for health checks the health check ID; otherwise the policy and alert type. |

### Severity

| Alert type | EvoHub severity |
| --- | --- |
| Contains `ddos`, `origin` or `health_check` | high |
| Anything else | medium |

## Resolve and deduplication

- `alert_event: ALERT_STATE_EVENT_END` resolves the alert that the matching start event opened.
- A health check notification whose new status is **Healthy** resolves the open alert for that health check.
- One-off notices, such as certificate expiry or usage notifications, have no end event and stay open until resolved in EvoHub.
- `PENDING` events (Workers observability) are ignored.

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [Escalation policies](https://docs-dev.evohub.io/escalation-policies.md)
