Incident management
Analytics
Incident volume, MTTA and MTTR per day, the alerts-to-incidents noise ratio and on-call load per user for a date range, in one call.
GET /api/im/analytics
Returns the data behind the Incident Management analytics page for one date range: incident volume with MTTA and MTTR per local day, the daily alert noise, and on-call minutes per user.
Authentication
Any IM-eligible role (admin, editor, responder) or an organization-wide API token. Incident Management must be enabled for the organization.
Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
from | ISO 8601 | Yes | Start of the range (inclusive). |
to | ISO 8601 | Yes | End of the range (exclusive). Must be after from, at most 400 days later. |
tz | number | No | Your UTC offset in minutes (e.g. 120 for UTC+2). Default 0, clamped to plus or minus 1440. Used to cut volumeTrend into local days. |
Example (cURL)
curl "$BASE_URL/api/im/analytics?from=2026-09-01T00:00:00Z&to=2026-10-01T00:00:00Z&tz=120" \
-H "Authorization: Bearer $TOKEN"Response
{
"from": "2026-09-01T00:00:00.000Z",
"to": "2026-10-01T00:00:00.000Z",
"volumeTrend": [
{ "day": "2026-09-01T22:00:00.000Z", "count": 4, "mttaMinutes": 3.5, "mttrMinutes": 47.25 },
{ "day": "2026-09-02T22:00:00.000Z", "count": 1, "mttaMinutes": null, "mttrMinutes": null }
],
"noiseQuote": [
{ "day": "2026-09-02", "alerts": 38, "deduped": 29, "incidents": 4 }
],
"onCallLoad": [
{ "userId": "u_abc123", "userName": "Jana Weber", "minutes": 10080 }
]
}| Field | Description |
|---|---|
volumeTrend[].day | UTC instant of local midnight for that day (shifted by tz). Format it in your own time zone. Only days with incidents appear. |
volumeTrend[].count | Incidents triggered that day. Test incidents are excluded. |
volumeTrend[].mttaMinutes | Average minutes from trigger to acknowledge, over incidents that were acknowledged. null if none was. |
volumeTrend[].mttrMinutes | Average minutes from trigger to resolve, over resolved incidents. null if none was. |
noiseQuote[] | Per UTC calendar day (YYYY-MM-DD, not shifted by tz), summed over all alert sources: inbound alerts, deduped alerts folded into an open one, and incidents opened. Covers every day from the date of from through the date of to. |
onCallLoad[] | On-call minutes per user inside the range, same data as the on-call report. |
Common errors
401 Unauthorized(unauthorized) when not authenticated403 Forbidden(customerScopedTokenForbidden) for a customer-scoped token403 Forbidden(imAccessDenied) when the session has no IM-eligible role403 Forbidden(imNotEnabled) when Incident Management is not enabled for the organization400 Bad Request(imReportRangeRequired) whenfromortois missing or not a valid date400 Bad Request(imReportRangeInvalid) whenfromis not beforeto400 Bad Request(imReportRangeTooLarge) when the range exceeds 400 days