Cloudflare application security

Sentinel, security alert analysis for Cloudflare

Sentinel is an alert analysis service for Cloudflare. It takes each security notification, adds the traffic and firewall data behind it, and sends your team a Slack message that says whether the alert matters, how severe it is and which WAF or rate limiting rules would stop it.

What Sentinel does

  • Receives your Cloudflare notifications: you point a notification policy at Sentinel’s webhook, and every alert is verified and checked for duplicates.
  • Adds the data behind the alert: traffic, firewall events, bot scores, WAF attack scores and the rules already in place, for the zone and time window of the alert.
  • Separates noise from incidents: a quick triage step filters false positives and background noise; real incidents get a full analysis.
  • Tells you what to do: a Slack message with the verdict, severity, what the attack looks like and proposed WAF or rate limiting rules ready to review.
  • Sends a daily digest: an optional daily security summary of the previous day’s alerts and the rules still pending review.

Who it is for

Teams running Cloudflare Enterprise or Business who receive more security alerts than they can investigate, and who want each one explained in plain language with a recommended action.

How it is delivered

We set up and operate Sentinel for each customer: the read-only API token, the notification policies, the Slack channels and their filters. Analyses for one customer never use another customer’s data.

Getting Sentinel

Talk to us about connecting Sentinel to your Cloudflare accounts.

Independent tools built by Noraina, a Cloudflare Authorized Service Delivery Partner. Not made or operated by Cloudflare. Cloudflare is a trademark of Cloudflare, Inc.

Frequently asked questions

Which Cloudflare alerts can Sentinel analyse?

HTTP DDoS and layer 3/4 DDoS attack alerts, security events alerts, traffic anomaly alerts, origin error rate alerts and bot detection alerts. Each one is analysed with the analytics of the zone and time window it refers to.

Does Sentinel change our Cloudflare configuration?

No. Sentinel uses a read-only API token. It proposes WAF and rate limiting rules in the Slack message, written against your existing rules, and your team decides whether to apply them.

How does Sentinel cut down alert noise?

A first model triages every alert as a false positive, harmless background noise or something that needs analysis, and only the last group gets a full analysis. Repeated alerts within a cooldown window are grouped, and each Slack channel can have its own severity threshold and alert categories.

Which AI models does Sentinel use?

Triage runs on Workers AI, and the full analysis uses Anthropic's Claude through Cloudflare AI Gateway. Each customer can set the language of the analysis and how cautious its recommendations should be.