What Sentinel does
- Receives your Cloudflare notifications: you point a notification policy at Sentinel’s webhook, and every alert is verified and checked for duplicates.
- Adds the data behind the alert: traffic, firewall events, bot scores, WAF attack scores and the rules already in place, for the zone and time window of the alert.
- Separates noise from incidents: a quick triage step filters false positives and background noise; real incidents get a full analysis.
- Tells you what to do: a Slack message with the verdict, severity, what the attack looks like and proposed WAF or rate limiting rules ready to review.
- Sends a daily digest: an optional daily security summary of the previous day’s alerts and the rules still pending review.
Who it is for
Teams running Cloudflare Enterprise or Business who receive more security alerts than they can investigate, and who want each one explained in plain language with a recommended action.
How it is delivered
We set up and operate Sentinel for each customer: the read-only API token, the notification policies, the Slack channels and their filters. Analyses for one customer never use another customer’s data.
Getting Sentinel
Talk to us about connecting Sentinel to your Cloudflare accounts.