Weekly Cloudflare WAF and traffic security digest in Slack

By General Input

Every Monday morning, get a plain English summary of what Cloudflare blocked last week, posted to Slack with a Linear ticket auto-filed when something looks unusual.

Integrations

  • Cloudflare
  • Slack
  • Linear

Type

Agentic Task

Categories

  • Engineering
  • Operations

Every Monday at 8am Eastern, build me a weekly Cloudflare attack and traffic security digest for my engineering and security team. Use a cron trigger on that weekly schedule.

Step 1: Use the Cloudflare Query GraphQL Analytics operation to pull last seven days of zone metrics across all my Cloudflare zones. I want total requests, cached vs uncached share, requests blocked or challenged by WAF custom rules and managed rules, top source countries and ASNs for blocked traffic, and top targeted hostnames and URI paths. Then pull the same numbers for the prior seven days so we can compute week over week deltas.

Step 2: Have the agent write a concise executive summary in plain English. Cover how much traffic we saw, what share was blocked, the biggest movers versus the previous week, the top three attack categories or rule IDs that fired, and the top three offending source ASNs or countries.

Step 3: Post the summary to a configured Slack channel using Slack Send a Message. Format it with section headings and inline week over week percentage deltas so it reads cleanly in the channel.

Step 4: Check anomaly thresholds. If any of these conditions hit, also file a Linear issue using Linear Create Issue in a configurable team, priority High, with a title naming the anomaly and a description that includes the relevant numbers plus a link back to the Slack post so the on call security engineer can pick it up:

1) Total blocked requests jumped more than 50 percent week over week. 2) A single source ASN accounts for more than 25 percent of blocked traffic. 3) A brand new attack category appears that did not fire at all the prior week.

The goal is to give the team a regular signal of what Cloudflare is actually catching at the edge without anyone having to log into the dashboard, and to auto-escalate when something looks unusual.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentWin back LiveChat visitors whose chats went unansweredChat quality review board for LiveChat support leadsWin back no-show and cancelled appointments every morningLive Loop returns analytics with product-level drill-downNewsletter pre-flight and approval board for Mailjet sendsTurn a prospect spreadsheet into personalized sequence enrollmentsMailjet email delivery lookup console for support teamsCatch feature flags that never got switched on in productionKajabi customer support console for member access fixes