---
title: "Analytics"
description: "Incident volume, MTTA and MTTR per day, the alerts-to-incidents noise ratio and on-call load per user for a date range, in one call."
---

`GET /api/im/analytics`

Returns the data behind the Incident Management analytics page for one date range: incident volume with MTTA and MTTR per local day, the daily alert noise, and on-call minutes per user.

## Authentication

Any IM-eligible role (`admin`, `editor`, `responder`) or an organization-wide API token. Incident Management must be enabled for the organization.

## Query Parameters

| Parameter | Type | Required | Description |
|-----------|------|----------|-------------|
| `from` | ISO 8601 | Yes | Start of the range (inclusive). |
| `to` | ISO 8601 | Yes | End of the range (exclusive). Must be after `from`, at most 400 days later. |
| `tz` | number | No | Your UTC offset in minutes (e.g. `120` for UTC+2). Default `0`, clamped to plus or minus 1440. Used to cut `volumeTrend` into local days. |

## Example (cURL)

```bash
curl "$BASE_URL/api/im/analytics?from=2026-09-01T00:00:00Z&to=2026-10-01T00:00:00Z&tz=120" \
  -H "Authorization: Bearer $TOKEN"
```

## Response

```json
{
  "from": "2026-09-01T00:00:00.000Z",
  "to": "2026-10-01T00:00:00.000Z",
  "volumeTrend": [
    { "day": "2026-09-01T22:00:00.000Z", "count": 4, "mttaMinutes": 3.5, "mttrMinutes": 47.25 },
    { "day": "2026-09-02T22:00:00.000Z", "count": 1, "mttaMinutes": null, "mttrMinutes": null }
  ],
  "noiseQuote": [
    { "day": "2026-09-02", "alerts": 38, "deduped": 29, "incidents": 4 }
  ],
  "onCallLoad": [
    { "userId": "u_abc123", "userName": "Jana Weber", "minutes": 10080 }
  ]
}
```

| Field | Description |
|-------|-------------|
| `volumeTrend[].day` | UTC instant of local midnight for that day (shifted by `tz`). Format it in your own time zone. Only days with incidents appear. |
| `volumeTrend[].count` | Incidents triggered that day. Test incidents are excluded. |
| `volumeTrend[].mttaMinutes` | Average minutes from trigger to acknowledge, over incidents that were acknowledged. `null` if none was. |
| `volumeTrend[].mttrMinutes` | Average minutes from trigger to resolve, over resolved incidents. `null` if none was. |
| `noiseQuote[]` | Per UTC calendar day (`YYYY-MM-DD`, not shifted by `tz`), summed over all alert sources: inbound `alerts`, `deduped` alerts folded into an open one, and `incidents` opened. Covers every day from the date of `from` through the date of `to`. |
| `onCallLoad[]` | On-call minutes per user inside the range, same data as the [on-call report](/api/incident-management/reports#on-call-report). |

## Common errors

- `401 Unauthorized` (`unauthorized`) when not authenticated
- `403 Forbidden` (`customerScopedTokenForbidden`) for a customer-scoped token
- `403 Forbidden` (`imAccessDenied`) when the session has no IM-eligible role
- `403 Forbidden` (`imNotEnabled`) when Incident Management is not enabled for the organization
- `400 Bad Request` (`imReportRangeRequired`) when `from` or `to` is missing or not a valid date
- `400 Bad Request` (`imReportRangeInvalid`) when `from` is not before `to`
- `400 Bad Request` (`imReportRangeTooLarge`) when the range exceeds 400 days
