MTTA and MTTR reports
About the Response Metrics MTTA (Mean Time to Acknowledge) and MTTR (Mean Time to Resolve) reports in Splunk On-Call.
The Response Metrics MTTA (Mean Time to Acknowledge) and MTTR (Mean Time to Resolve) Report tells the story of your investment in Splunk On-Call and the practice of DevOps. Track evolution and goals over time, and tell key stakeholders the story by relaying key metrics directly related to the cost of downtime.
Navigate to Reports then Response Metrics.
Response metrics graph view
By default, the MTTA and MTTR lines will be displayed in the graph view if incidents are present in a specific time period. Incidents are displayed in vertical columns to relay the aggregated incident number in a specific time frame, while also displaying the individual incidents making up the time range.
Select and deselect items in the graph key to include the data points that are important to you.
-
Hover over an incident to learn key metrics, and click an individual incident to get the granular information surrounding a specific data point. For the bucket averages, only the hover state is available.
-
Select individual incidents to drill into more granular incident data.
-
Select and deselect items in the graph key to include the data points that are important to you.
Track response metrics with team filtering
Track both your organization and team’s MTTA and MTTR and incident metrics by leveraging the team filter. These are directly related to the associated team’s escalation policies.
Routing Key Filtering
Target specific or multiple routing keys to understand metrics around different components.
MTTA and MTTR goal tracking
Incident volume by date range and bucketing
Aggregate MTTA and MTTR averages and incident volume by daily, weekly, and monthly buckets.
Table view for recent incidents
The table view adjusts to match the 100 most recent incidents associated with the selected segment filter. Click on a specific row to learn more about a specific incident, including its ACK/RES history, as well as the individual alert payload.
CSV file download
The data delivered in the CSV file will reflect the date range and team segmenting designed in the setting views. Changing the segment by filters and date range bucketing will have no effect on the contents of the download.
Things to note about the CSV file:
-
Time stamps are at millisecond granularity
-
CSV is sorted by Incident ID in descending order
CSV file column headings
When downloading the Response Metrics CSV file, you can expect to find the following columns to include the unit of time/time zone that the incident is recorded in. Time-related column headings will appear in this format:
Time to Acknowledge (seconds) Time to Resolve (seconds) Incident Start Time (UTC) Acknowledge Time (UTC) Resolve Time (UTC)