Cloudflare Automated Security Threat Alerts
Every hour, WebRun opens Cloudflare, reads blocked threats, traffic volume, and error rates for each zone, logs any threshold breach as an Airtable record, and emails you a summary through Gmail so a spike gets flagged the same hour it happens.
How do I get alerted when Cloudflare traffic or security events spike?
WebRun checks your Cloudflare zones every hour, reading blocked threats, traffic volume, and error rates from the analytics dashboard. When a zone crosses a threshold you set, it logs the incident in Airtable with the metric and value, then emails you a summary, so a traffic spike or attack gets flagged within the hour instead of surfacing days later.
- Traffic spikes and attacks get flagged within the hour
- Every threshold breach is logged with the exact metric and value
- Your inbox stays quiet on days nothing crosses a threshold
Built for Web agencies · DevOps teams · site reliability engineers · ecommerce site owners
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
dash.cloudflare.comin a real browser with your saved login - no setup, no API keys. -
1
Cloudflare - scan traffic and security events
WebRun opens Cloudflare to scan traffic and security events. - Open the Cloudflare dashboard for each zone
- Read blocked threats, traffic volume, and error rate from the analytics view
- Flag any zone crossing the usage or security threshold you set
Done when Every zone has a current reading and any breach is flagged.
-
2
Airtable - log the incident
WebRun opens Airtable to log the incident. - Log each threshold breach as a new record with the zone, metric, and value
- Keep a running history so patterns over time are visible
- Skip zones that are within normal range this run
Done when Every breach this run is logged as an Airtable record.
-
3
Gmail - email the summary
WebRun opens Gmail to email the summary. - Draft a summary email listing the zones that crossed a threshold this run
- Include the metric and value that triggered each alert
- Skip sending when nothing crossed a threshold this run
Done when You have an email in your inbox only on runs with a real breach.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it change any Cloudflare settings, like DNS or firewall rules?
No. WebRun only reads analytics and security event data. It never edits a DNS record, firewall rule, or any other Cloudflare setting.
What counts as a threshold breach?
You set the numbers, for example a spike in blocked threats or a jump in server error rate for a zone. WebRun compares each run's reading against those numbers and only logs and emails when one is crossed.
Does it email me even when nothing is wrong?
No. The email only goes out on runs where at least one zone crosses a threshold, so a quiet day means a quiet inbox.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.