Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Chronological alert data in an alert group

Visualize the chronological sequence of events within an alert group in Express List using the Timeline view. This feature provides a comprehensive overview of when the alerts occurred, their severity changes, and other pertinent data for efficient triage and Mean Time to Resolution (MTTR).

In Timeline view, each alert is represented by a bar, enabling you to quickly discern the order of occurrence, severity transitions, and closure status. The timeline begins with the creation of the first alert and extends to the present moment.

Image omitted: el-timeline-view.png
Sample timeline view in Express List.

Standard severity colors are used in the bars, with gray segments indicating periods before alert creation or after its closure. Hovering over a severity bar reveals a tooltip with key alert details.

ColorSeverity
Image omitted: el-timeline-red.png
Red used to represent Critical severity in the alert severity bar.|Critical|

|

Image omitted: el-timeline-orange.png
Orange used to represent Major severity in the alert severity bar.|Major|

|

Image omitted: el-timeline-yellow.png
Yellow used to represent Minor severity in the alert severity bar.|Minor|

|

Image omitted: el-timeline-blue.png
Blue used to represent Warning severity in the alert severity bar.|Warning|

|

Image omitted: el-timeline-green.png
Green used to represent OK in the alert severity bar.|OK|

The title of the Timeline view for an alert group summarizes the group's description, number, state, severity, and grouping type, derived from the primary alert. Detailed information including alert number, state, severity, a brief description, and associated Configuration Item (CI) or node, when available, is displayed for each alert within the group.

Related topics

View a timeline of the alerts in an alert group