Administration

Analytics

Workload and response metrics across your cases, over a period you choose.

The headline numbers

Six cards sit at the top of the page.

CardWhat it counts
Total CasesCases created in the selected range.
EvidenceEvidence items collected in the range, across every case in it.
Cases ClosedCases closed during the range.
MTTRMean time to resolve. See below.
Total UsersActive user accounts on the installation right now, not a figure for the range.
Active UsersUsers who did at least one thing during the range.

What MTTR measures

MTTR averages the time from an incident's declaration to its resolution, across the incidents resolved during the range. Resolution is the moment an incident enters the final phase. An incident closed without ever reaching that phase counts up to its closure instead.

The figure covers incidents only. An investigation has no declaration time, so nothing marks the start.

The charts

  • Cases by Mode splits investigations from incidents, which shows the balance between planned work and reactive work.
  • Cases by Severity breaks cases down across critical, high, medium, low and info.
  • Cases by Status weighs open work against everything closed or archived.
  • Cases Over Time plots case creation across the range, with incidents and investigations on separate lines, which is where a spike shows up.
  • Evidence Over Time plots evidence collection, which tracks how heavy the work was rather than how much of it there was.

The date range

The picker in the top right filters the whole page. It starts on the last 30 days. Changing it updates every card and chart at once, so you can compare one period against another.

The numbers follow your access. The page needs the view_statistics permission, and it counts only the cases you can reach. A role holding view_all_cases widens that to the whole installation. Two people can therefore read different figures for the same range, and both are right.

Everything is computed from live case data when you open the page. There is no separate analytics store to refresh or fall behind.

← Audit log Support and diagnostics →