Copy as Markdown[Open in ChatGPT](https://chatgpt.com/?q=Read%20https%3A%2F%2Fcoralogix.com%2Fdocs%2Fuser-guides%2Fai%2Fcode-agents%2Falerts.md%20and%20help%20me%20with%20my%20question%20about%20this%20Coralogix%20documentation%20page.)[Open in Claude](https://claude.ai/new?q=Read%20https%3A%2F%2Fcoralogix.com%2Fdocs%2Fuser-guides%2Fai%2Fcode-agents%2Falerts.md%20and%20help%20me%20with%20my%20question%20about%20this%20Coralogix%20documentation%20page.)

# Code Agents alerts

Deploy a prebuilt set of alerts for Claude Code and GitHub Copilot activity. The **Code Agents Alerts** extension installs 12 ready-to-use metric threshold alerts that catch cost spikes, runaway sessions, unused licenses, adoption drops, and unapproved models before they become expensive or risky.

Use the alerts out of the box, or tune their thresholds to your environment. Each alert behaves like a standard Coralogix metric alert and integrates with your existing notification channels and workflows.

## What you need[​](#what-you-need "Direct link to What you need")

* Claude Code or GitHub Copilot metrics flowing into Coralogix through the [Claude Code & Cowork](https://coralogix.com/docs/user-guides/ai/code-agents/claude-code.md) or [GitHub Copilot](https://coralogix.com/docs/user-guides/ai/code-agents/copilot.md) integrations.
* An existing application and subsystem in your account. Alerts that group by `model` or `user_email` still evaluate account-wide; the application and subsystem you deploy under scope which data the extension can read.
* The `EXTENSIONS:READCONFIG` permission, plus `ALERTS:METRICSUPDATECONFIG` to deploy the alerts. Without both, the extension is not deployable. See [Permissions list](https://coralogix.com/docs/user-guides/aaa/access-control/permissions/permissions-list.md).

## Set up[​](#set-up "Direct link to Set up")

1. In Coralogix, navigate to **Integrations**, then **Extensions**.
2. Find the **Code Agents Alerts** card (search by name or filter by **Observability**) and select it to open the detail page.
3. From the **Version** dropdown, select the version you want to deploy.
4. From the **Applications** and **Subsystems** dropdowns, select the scope to deploy under.
5. Under **Alerts**, all 12 alerts are selected by default. Deselect any alert you do not want to deploy.
6. Select **Deploy**.

[![Code Agents Alerts extension detail page showing the extension header, overview, and 12-alert summary](/docs/assets/images/extension-overview-510c399947084bdffd629a412dea86f8.webp)](https://coralogix.com/docs/assets/images/extension-overview-510c399947084bdffd629a412dea86f8.webp)

The extension creates the 12 alerts in your account. To view them, navigate to **Alerting**, then **Alert definition management**. Alert names start with `Claude code | `or `GitHub Copilot | `.

## Use it[​](#use-it "Direct link to Use it")

### Customize an alert[​](#customize-an-alert "Direct link to Customize an alert")

After deployment, the alerts behave like any other metric threshold alert. You can edit thresholds, schedules, notifications, group-by keys, and priority.

1. In Coralogix, navigate to **Alerting**, then **Alert definition management**.
2. Find the alert you deployed. Alert names start with `Claude code | `or `GitHub Copilot | `.
3. Select the alert to open it for editing.
4. Adjust the threshold, time window, evaluation window, group-by keys, or notification settings.
5. Save your changes.

### Update or remove the extension[​](#update-or-remove-the-extension "Direct link to Update or remove the extension")

When a new version of the extension is published, the **Extensions** page shows an **UPDATE AVAILABLE** indicator on the card.

To install the new version:

1. Navigate to **Integrations**, then **Extensions**.
2. Select the **Code Agents Alerts** card.
3. Select **Update**.

To uninstall the extension and its alerts, select **Remove** from the same page.

## How it works[​](#how-it-works "Direct link to How it works")

Unlike alerts built on span data, the Code Agents Alerts extension evaluates PromQL directly against the metrics that the Claude Code & Cowork and GitHub Copilot integrations already emit (`claude_code_*` and `github_copilot_*`). There is no separate Events2Metrics conversion step: the extension deploys 12 metric threshold alerts as-is, using the standard Coralogix alerting engine.

## Reference[​](#reference "Direct link to Reference")

### Alerts[​](#alerts "Direct link to Alerts")

Each alert deploys with the query, condition, and severity below. Select an alert to expand it.

[![Code Agents Alerts alert detail view showing the PromQL query, group-by, and conditions for \&quot;Per-user daily cost spike\&quot;](/docs/assets/images/alert-detail-1824996d253ed482523ee4b87ed732ac.webp)](https://coralogix.com/docs/assets/images/alert-detail-1824996d253ed482523ee4b87ed732ac.webp)

Claude code | New or unapproved Claude model detected (7-day offset)

**P2.** Fires when token usage is recorded against a Claude model that had no usage over the preceding 7 days.

```
count by (model) (increase(claude_code_token_usage_tokens_total[24h]))

unless

count by (model) (increase(claude_code_token_usage_tokens_total[7d] offset 24h))
```

Condition: more than `0`, at least once in 1 minute. Group by `model`.

Claude code | Per-user daily cost spike

**P2.** Fires when a single user's cumulative spend over 24 hours crosses the threshold.

```
sum by (user_email) (increase(claude_code_cost_usage_USD_total[24h]))
```

Condition: more than `100`, at least once in 5 minutes. Group by `user_email`.

Claude code | Cost rate anomaly (spike vs baseline)

**P2.** Compares the last 15-minute cost rate against the 1-hour rolling average.

```
sum(rate(claude_code_cost_usage_USD_total[15m]))

/ sum(rate(claude_code_cost_usage_USD_total[1h]))
```

Condition: more than `3`, at least once in 5 minutes.

Claude code | Model cost concentration

**P3.** Fires when a single model accounts for more than the threshold share of total spend.

```
sum by (model) (increase(claude_code_cost_usage_USD_total[1h]))

/ ignoring(model) group_left sum(increase(claude_code_cost_usage_USD_total[1h]))
```

Condition: more than `0.8` (80%), at least once in 5 minutes. Group by `model`.

Claude code | Runaway session: active time

**P2.** Fires when a single session accumulates more than the threshold of active agent time.

```
max by (session_id, user_email) (

  increase(claude_code_active_time_total_s_total[3h])

)
```

Condition: more than `7200` seconds (2 hours), at least once in 5 minutes. Group by `session_id`, `user_email`.

Claude code | Single session token runaway

**P2.** Fires when any individual session consumes more than the threshold of tokens in a 1-hour window.

```
max by (session_id, user_email) (

  increase(claude_code_token_usage_tokens_total[1h])

)
```

Condition: more than `50000000` tokens, at least once in 5 minutes. Group by `session_id`, `user_email`.

GitHub Copilot | Single user CLI token concentration

**P3.** Fires when one user accounts for more than the threshold share of total CLI tokens (prompt + output) over the last 24 hours.

```
(sum by (user_email) (sum_over_time(github_copilot_user_cli_prompt_tokens_sum[24h]))

+ sum by (user_email) (sum_over_time(github_copilot_user_cli_output_tokens_sum[24h])))

/ on() group_left() (

  sum(sum_over_time(github_copilot_user_cli_prompt_tokens_sum[24h]))

  + sum(sum_over_time(github_copilot_user_cli_output_tokens_sum[24h]))

  + 1

)
```

Condition: more than `0.6` (60%), at least once in 5 minutes. Group by `user_email`.

GitHub Copilot | Org-wide code acceptance rate drop

**P3.** Fires when accepted suggestions as a share of total generated suggestions over the last 24 hours drops below the threshold.

```
sum(sum_over_time(github_copilot_org_code_acceptance_activity_count[24h]))

/ (sum(sum_over_time(github_copilot_org_code_generation_activity_count[24h])) + 1)
```

Condition: less than `0.2` (20%), at least once in 5 minutes.

GitHub Copilot | Zero daily active users

**P2.** Fires when there have been no active users at all over the last 24 hours.

```
sum(max_over_time(github_copilot_org_daily_active_users[24h]))
```

Condition: less than or equal to `0`, at least once in 5 minutes. Missing values are treated as `0`.

GitHub Copilot | Unused licensed seats (wasted spend)

**P3.** Fires when billed seats exceed monthly active users by more than the threshold.

```
sum(sum_over_time(github_copilot_billing_net_quantity[24h]))

- sum(max_over_time(github_copilot_org_monthly_active_users[24h]))
```

Condition: more than `20`, at least once in 5 minutes.

GitHub Copilot | Billing net amount spike

**P2.** Fires when Copilot net billing increases more than the threshold compared to 7 days ago.

```
sum(sum_over_time(github_copilot_billing_net_amount[24h]))

/ (sum(sum_over_time(github_copilot_billing_net_amount[24h] offset 7d)) + 1)
```

Condition: more than `1.3` (a 30% increase), at least once in 5 minutes.

GitHub Copilot | New or unapproved model detected (7-day offset)

**P2.** Fires when a model records org-wide Copilot interactions in the last 24 hours but had none over the preceding 7 days.

```
count by (model) (

  sum_over_time(github_copilot_org_user_initiated_interaction_count_by_model_feature[24h])

)

unless

count by (model) (

  sum_over_time(github_copilot_org_user_initiated_interaction_count_by_model_feature[7d] offset 24h)

)
```

Condition: more than `0`, at least once in 1 minute. Group by `model`.

Note

Thresholds and windows above are the extension's shipped defaults. Adjust them after deployment to match your team's usage patterns and budget, the same way you would [customize any alert](#customize-an-alert).

## Limitations[​](#limitations "Direct link to Limitations")

* The extension currently covers Claude Code and GitHub Copilot. Support for other code agents (Cursor, Codex, and others) is planned.
* Each alert evaluates a fixed PromQL query against the underlying `claude_code_*` or `github_copilot_*` metrics. To alert on a different aggregation or grouping, build a custom alert directly against those metrics instead of editing the deployed one.

## Troubleshoot[​](#troubleshoot "Direct link to Troubleshoot")

**No alerts are firing.** Cause: Claude Code or GitHub Copilot metrics are not flowing into the application and subsystem the extension was deployed under. Fix: confirm activity appears on the [Claude Code](https://coralogix.com/docs/user-guides/ai/code-agents/claude-code.md) or [Copilot](https://coralogix.com/docs/user-guides/ai/code-agents/copilot.md) dashboards for that scope.

## Learn more[​](#learn-more "Direct link to Learn more")

* [Code Agents Intelligence](https://coralogix.com/docs/user-guides/ai/code-agents.md)
* [Claude Code & Cowork](https://coralogix.com/docs/user-guides/ai/code-agents/claude-code.md)
* [GitHub Copilot](https://coralogix.com/docs/user-guides/ai/code-agents/copilot.md)
* [Quick-Start extensions](https://coralogix.com/docs/user-guides/getting-started/packages-and-extensions/extension-packages.md)
* [Introduction to alerts](https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts.md)
* [AI Center alerts and metrics](https://coralogix.com/docs/user-guides/ai/alerts.md)
