Template
Incident timeline template
A consistent way to capture what happened and when — from detection to resolution — so every incident is legible afterward and metrics like time-to-acknowledge and time-to-resolve are easy to compute.
# Incident timeline: <Incident title> Incident ID: Severity: Status: Detected at: Resolved at: Duration: Affected services: | Time (<tz>) | Event | Actor | Notes | |---|---|---|---| | HH:MM | Detected — monitor failed / alert received | | | | HH:MM | Incident declared, severity set | | | | HH:MM | On-call paged | | | | HH:MM | Acknowledged | | | | HH:MM | Investigation / key finding | | | | HH:MM | Mitigation applied | | | | HH:MM | Customer status update posted | | | | HH:MM | Resolved — confirmed healthy | | | Key metrics - Time to acknowledge (detection → ack): - Time to resolve (detection → resolved): - Customer updates posted:
Why a consistent timeline matters
When each incident is recorded the same way, patterns become visible: where detection lags, where paging stalls, and which services recur. A consistent timeline is the raw material for a good postmortem and for honest reliability metrics.
EverUptime builds this timeline as the incident unfolds — detection, paging, acknowledgment, actions, status updates, and resolution — so you are recording facts, not reconstructing them from memory afterward.
Let the timeline write itself.
EverUptime records the incident timeline as it happens.
Free plan available · no credit card required