Summarise alerts

Counts and durations over a window, sliced however you ask. Takes the same filters as the search, so a figure here and the rows the search returns always describe the same population. Each groupBy switch adds a dimension, so groupByAssignee and groupBySeverity together give one row per person per severity. Set an aggregation to bucket by time, which also populates openAtBucketEnd - the backlog carried at the close of each bucket, which is the number a trend line should plot.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Query Params
string
Defaults to NONE

Time bucket - NONE, HOUR, DAY, WEEK or MONTH

int64

Restrict to alerts owned by this user

string

Restrict to one channel

boolean
Defaults to false
boolean
Defaults to false
boolean
Defaults to false
boolean
Defaults to false
boolean
Defaults to false
boolean
Defaults to false
string

Restrict to one host

boolean
Defaults to false

Include alerts folded into another as duplicates. Off by default.

boolean

Only alerts owned but unassigned

string

Restrict to alerts this person is accountable for

string

Published from, inclusive. ISO 8601. Defaults to seven days ago.

string

Published to, exclusive. ISO 8601. Defaults to now.

severity
array of strings

Restrict to these severities. Repeatable.

severity
string

Restrict to one deduplication shape

status
array of strings

Restrict to these statuses. Repeatable.

status
boolean

Restrict to alerts nobody is assigned to

Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json