Skip to main content

Code Agents alerts

Deploy a prebuilt set of alerts for Claude Code and GitHub Copilot activity. The Code Agents Alerts extension installs 12 ready-to-use metric threshold alerts that catch cost spikes, runaway sessions, unused licenses, adoption drops, and unapproved models before they become expensive or risky.

Use the alerts out of the box, or tune their thresholds to your environment. Each alert behaves like a standard Coralogix metric alert and integrates with your existing notification channels and workflows.

What you need​

  • Claude Code or GitHub Copilot metrics flowing into Coralogix through the Claude Code & Cowork or GitHub Copilot integrations.
  • An existing application and subsystem in your account. Alerts that group by model or user_email still evaluate account-wide; the application and subsystem you deploy under scope which data the extension can read.
  • The EXTENSIONS:READCONFIG permission, plus ALERTS:METRICSUPDATECONFIG to deploy the alerts. Without both, the extension is not deployable. See Permissions list.

Set up​

  1. In Coralogix, navigate to Integrations, then Extensions.
  2. Find the Code Agents Alerts card (search by name or filter by Observability) and select it to open the detail page.
  3. From the Version dropdown, select the version you want to deploy.
  4. From the Applications and Subsystems dropdowns, select the scope to deploy under.
  5. Under Alerts, all 12 alerts are selected by default. Deselect any alert you do not want to deploy.
  6. Select Deploy.

Code Agents Alerts extension detail page showing the extension header, overview, and 12-alert summary

The extension creates the 12 alerts in your account. To view them, navigate to Alerting, then Alert definition management. Alert names start with Claude code | or GitHub Copilot | .

Use it​

Customize an alert​

After deployment, the alerts behave like any other metric threshold alert. You can edit thresholds, schedules, notifications, group-by keys, and priority.

  1. In Coralogix, navigate to Alerting, then Alert definition management.
  2. Find the alert you deployed. Alert names start with Claude code | or GitHub Copilot | .
  3. Select the alert to open it for editing.
  4. Adjust the threshold, time window, evaluation window, group-by keys, or notification settings.
  5. Save your changes.

Update or remove the extension​

When a new version of the extension is published, the Extensions page shows an UPDATE AVAILABLE indicator on the card.

To install the new version:

  1. Navigate to Integrations, then Extensions.
  2. Select the Code Agents Alerts card.
  3. Select Update.

To uninstall the extension and its alerts, select Remove from the same page.

How it works​

Unlike alerts built on span data, the Code Agents Alerts extension evaluates PromQL directly against the metrics that the Claude Code & Cowork and GitHub Copilot integrations already emit (claude_code_* and github_copilot_*). There is no separate Events2Metrics conversion step: the extension deploys 12 metric threshold alerts as-is, using the standard Coralogix alerting engine.

Reference​

Alerts​

Each alert deploys with the query, condition, and severity below. Select an alert to expand it.

Code Agents Alerts alert detail view showing the PromQL query, group-by, and conditions for "Per-user daily cost spike"

Note

Thresholds and windows above are the extension's shipped defaults. Adjust them after deployment to match your team's usage patterns and budget, the same way you would customize any alert.

Limitations​

  • The extension currently covers Claude Code and GitHub Copilot. Support for other code agents (Cursor, Codex, and others) is planned.
  • Each alert evaluates a fixed PromQL query against the underlying claude_code_* or github_copilot_* metrics. To alert on a different aggregation or grouping, build a custom alert directly against those metrics instead of editing the deployed one.

Troubleshoot​

No alerts are firing. Cause: Claude Code or GitHub Copilot metrics are not flowing into the application and subsystem the extension was deployed under. Fix: confirm activity appears on the Claude Code or Copilot dashboards for that scope.

Learn more​

Last updated on