Incident timeline calculator

Reconstruct detection, investigation and recovery intervals from UTC timestamps.

Free to use. Save a file draft or explicitly enable storage on this device.

Working draft · v2

Incident timeline

Save / export

Current result

Detection: Unknown min

Incomplete or uncertain. Review the fields and warnings.

Review results

Start with your data or try an illustrative example.

File drafts are available without browser storage. Current draft matches the last save or initial state.

Inputs & calculation

Impact began
Incident detected
Page acknowledged
Investigation began
Mitigation applied
Service recovered
Onset is uncertain: enter observation bounds

Leave exact onset blank when it is not known. Use the earliest and latest plausible onset supported by your evidence.

Detection
Unknown min
Acknowledgment
Unknown min
Detection to investigation
Unknown min
Investigation to recovery
Unknown min
Total impact
Unknown min

Mitigation attempts

Record each attempt without replacing the milestone timestamps above.

Results

Review and export

This is incomplete or has review issues. You can save a draft; exports retain unknowns and warnings.

Incident timeline report

Incident timeline
User-entered draft; verify against source evidence.
Tool version 2 · https://aiopssre.com/incident-timeline-calculator/
Name: Untitled

Detection: Unknown minutes
Acknowledgment: Unknown minutes
Detection to investigation: Unknown minutes
Investigation to recovery: Unknown minutes
Total impact: Unknown minutes

Incident notes: 
Single-incident durations are not means. Bounds reflect supplied observations, not a probability interval.
Milestone / attemptOriginal timestampUTC timestampEvidence / outcome
Impact beganUnknown
Incident detectedUnknown
Page acknowledgedUnknown
Investigation beganUnknown
Mitigation appliedUnknown
Service recoveredUnknown

Continue the incident workflow

Carry incident notes and the timing report into a follow-up action draft. Transfer uses this browser tab’s temporary storage, not a shared URL.

Use explicit endpoints

Detection measures impact onset to first discovery. Acknowledgement, mitigation and recovery are separate milestones. Leave unknown timestamps blank and record the evidence behind each timestamp. A single incident duration is not a mean; use the MTTD calculator to aggregate comparable incidents.

Use and review the result

Set a clear service and time window, check source data, then save the worksheet with your evidence. Downloads are editable; browser print can save a PDF. Illustrative examples are not production results.

Read the accompanying guide · Source and further reading

Calculation and worksheet review: September 29, 2026.

Full Incident Response Toolkit · Get new guides by email