Using the integration for incident.io
How to use the integration for incident.io in Cortex
This article explains how to use the integration for incident.io. For configuration instructions, see Configuring the integration for incident.io. For instructions on connecting incident.io to entities, see Connecting entities to incident.io.
Viewing incident data
You can view incident data in the incident list and on an entity's details page.
Incident list
See every incident across your organization in one place, with metadata including severity, status, and affected entities.

To access the incident list:
From the main sidebar, expand Integrations, then select Data.
Select the Incidents tab.
The list is sorted by most recently opened incidents first.
Searching across and filtering the incident list
There are several ways to search and filter the list:
To find specific incidents, use the search bar in the upper-right corner of the page and type to search.
By default, the list sorts by most recently opened incident. Click Opened to reverse the order, or click Name to sort alphabetically instead.
Click Filter to narrow down your list by date range, severity level, or status.
Incidents on an entity's details page
View incidents in the following places on an entity's details page:
On the Overview tab; active incidents are prominently displayed at the top of the page

In the left details sidebar, locate Connections, then select Incidents

Viewing on-call information
On-call shift data
View all on-call shifts ingested via the incident.io integration in a single place. This allows you to see exactly what data Cortex has brought in from the integration and what entities it's been linked to within Cortex.
To access the on-call list:
From the main sidebar, expand Integrations, then select Data.
Select the On-call shifts tab.
Do one of the following:
Select the All tab to view all on-call shifts in your workspace.
Select the Mine tab to view only your on-call shifts.
The list is sorted alphabetically by schedule name. Click a row to open a side panel showing who's on call now, who's on call next, and the teams the schedule is associated with.

Searching across and sorting the on-call list
To search and sort the list:
Use the search bar in the upper-right corner of the page and type to search.
By default, the list sorts alphabetically by schedule name. Click Name to sort from Z to A.
On-call on an entity's details page
View current on-call information in the following places on an entity's details page:
In the metadata sidebar in the On-call now block

In the left details sidebar, locate Connections, then select On-call
Click a row to open a side panel showing who's on call now, who's on call next, and the teams the schedule is associated with.

Engineering homepage
View upcoming on-call rotations in the My on-calls block on your engineering homepage. Cortex shows on-call schedules up to six months out.

Creating Scorecard rules with incident.io data
Incident expressions
CQL lets you write rules and queries against incident data. See the CQL documentation for the complete list of available incident expressions.
On-call expressions
CQL lets you write rules and queries against on-call data. See the CQL documentation for the complete list of available on-call expressions.
Incident metrics in Eng Intelligence
Incident metrics in Eng Intelligence are powered by the same unified data pipeline as the incident list, so the numbers stay consistent across Cortex. Eng Intelligence supports the following incident metrics:
Incident frequency
Mean time to resolution (MTTR)
Syncing data from incident.io
Cortex syncs data from incident.io as follows:
Schedule data is synced every hour
Incident data is synced every 15 minutes
Viewing incident.io integration logs
While viewing an integration's settings page, select the Logs tab to view error logs from the last 7 days. You can filter the logs list by configuration and by operation (for example, you could filter to view errors surfaced only via Scorecards).

Click into a row to get more information, including time stamp, status code, full error, and request path.
Troubleshooting and FAQ
Last updated
Was this helpful?