MTTD example: a 40-minute mean and a 15-minute median
Inspect a reusable incident dataset with discovery methods, an unknown onset and two reporting periods.
Illustrative dataset · Tool version 2 · Reviewed September 29, 2026
Why can the mean and median tell different stories?
The current period contains known durations of 5, 15 and 100 minutes. Their mean is 40 minutes and their median is 15. A further incident has no onset timestamp and remains missing. The previous period contains 10, 20 and 60 minutes, a mean of 30 and median of 20. These invented populations illustrate arithmetic, not evidence of operational improvement.
| Incident | Onset UTC | Discovery UTC | Method | Period | Included duration (min) |
|---|---|---|---|---|---|
| Example 1 | 2026-09-01T00:00 | 2026-09-01T00:05 | Monitoring | Current | 5 |
| Example 2 | 2026-09-01T00:00 | 2026-09-01T00:15 | Monitoring | Current | 15 |
| Example 3 | 2026-09-01T00:00 | 2026-09-01T01:40 | Customer report | Current | 100 |
| Example 4 | 2026-09-01T00:00 | 2026-09-01T00:10 | Monitoring | Previous | 10 |
| Example 5 | 2026-09-01T00:00 | 2026-09-01T00:20 | Monitoring | Previous | 20 |
| Example 6 | 2026-09-01T00:00 | 2026-09-01T01:00 | Monitoring | Previous | 60 |
| Unknown onset | Unknown | 2026-09-02T02:00 | Customer report | Current | Missing |
What this example does not establish
Filtering out customer-reported incidents changes the population. Keep the filter, counts and exclusions with every exported result.
Try a variation
Open the example, change one input, and review the result. Keep definitions and denominators constant when comparing scenarios. Save a named draft before changing to a different dataset.
Read the related guide · Source and further reading
These datasets and worksheets may be adapted for your team or training. Attribute AIOpsSRE and link to this example when redistributing. Third-party sources retain their own terms.
Get AIOpsSRE by email · Report a calculation or explanation issue