> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coralogix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get incident aggregations

> Retrieve aggregated incident data with support for grouping and filtering.

Requires the following permissions:
- `incidents:read`



## OpenAPI

````yaml openapi_v4.yaml get /incidents/aggregations/v1
openapi: 3.0.0
info:
  title: ''
  version: 1.0.0
servers:
  - url: https://api.coralogix.com/mgmt/openapi/4
  - url: https://api.eu2.coralogix.com/mgmt/openapi/4
  - url: https://api.coralogix.us/mgmt/openapi/4
  - url: https://api.cx498.coralogix.com/mgmt/openapi/4
  - url: https://api.coralogix.in/mgmt/openapi/4
  - url: https://api.coralogixsg.com/mgmt/openapi/4
  - url: https://api.ap3.coralogix.com/mgmt/openapi/4
security:
  - apiKeyAuth: []
tags:
  - name: Recording Rules Service
    description: A service to manage recording rules.
    externalDocs:
      url: ''
  - name: Slos Service
    description: A service for managing Service Level Objectives (SLOs).
    externalDocs:
      url: ''
  - name: Scopes Service
    description: A service to manage scopes
    externalDocs:
      url: ''
  - name: Quota Allocation Rule Set service
    description: Manage quota allocation rules for different entity types.
    externalDocs:
      url: ''
  - name: Extension deployment service
    description: A service that enables querying for extension deployment information.
    externalDocs:
      description: Find out more about extensions in our documentation.
      url: https://coralogix.com/docs/integrations/extensions/
  - name: Contextual data integration service
    description: Query for contextual data integration information.
    externalDocs:
      url: ''
  - name: Alert events service
    description: >-
      Get information regarding your alert events - instances of alerts being
      triggered.
    externalDocs:
      description: Learn more about alert events and incidents in our documentation.
      url: https://coralogix.com/docs/user-guides/alerting/incidents/
  - name: Views service
    description: Create and manage views.
    externalDocs:
      url: ''
  - name: Retentions Service
    description: View and manage retentions
    externalDocs:
      url: ''
  - name: Extension testing service
    externalDocs:
      description: Find out more about extensions in our documentation.
      url: https://coralogix.com/docs/integrations/extensions/
  - name: Rule Groups Service
    description: A service to manage rule groups.
    externalDocs:
      url: ''
  - name: Global routers service
    description: >-
      View and manage your global routers - entities that direct notifications
      to configured destinations based on conditions
    externalDocs:
      description: Lean more about global routers in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/routing/introduction/
  - name: Connectors service
    description: >-
      View and manage your connectors - integration instances for notification
      destinations
    externalDocs:
      description: Lean more about connectors in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/connectors/introduction/
  - name: IP access service
    description: >-
      IP access service provides the API for managing company IP access
      settings.
    externalDocs:
      url: ''
  - name: Dashboard folders service
    description: Manage your dashboard folders.
    externalDocs:
      url: ''
  - name: Events Service
    description: A service for querying events.
    externalDocs:
      description: Learn more about alerts in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts/
  - name: Data Usage Service
    description: A service to manage data usage metrics.
    externalDocs:
      url: ''
  - name: Extension service
    description: A service that enables querying for extension information.
    externalDocs:
      description: Learn more about extensions in our documentation.
      url: https://coralogix.com/docs/integrations/extensions/
  - name: Outgoing webhooks service
    externalDocs:
      description: Find out more about outbound webhooks in our documentation.
      url: >-
        https://coralogix.com/docs/user-guides/alerting/outbound-webhooks/generic-outbound-webhooks-alert-webhooks/
  - name: Presets service
    description: >-
      View and manage your presets - pre-configured templates for notification
      content rendering
    externalDocs:
      description: Lean more about presets in our documentation
      url: >-
        https://coralogix.com/docs/user-guides/notification-center/presets/introduction/
  - name: API Keys Service
    description: Manage your API Keys.
    externalDocs:
      url: ''
  - name: Events2Metrics Service
    description: Manage your events2metrics.
    externalDocs:
      url: ''
  - name: Custom Enrichments Service
    description: Manage your enrichments.
    externalDocs:
      url: ''
  - name: Alert definitions service
    description: >-
      View and manage your alerts using alert definitions - data structures that
      contain the configuration required to create an alert.
    externalDocs:
      description: Learn more about alerts in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/introduction-to-alerts/
  - name: Folders for views service
    description: Create and manage view folders.
    externalDocs:
      url: ''
  - name: Policies Service
    description: View and manage your TCO policies
    externalDocs:
      url: ''
  - name: Cases service
    description: >-
      Manage cases throughout their lifecycle. Create, view, assign,
      acknowledge, resolve, and close cases to streamline investigations and
      follow-ups.
    externalDocs:
      description: Learn more about Cases in our documentation
      url: https://coralogix.com/docs/user-guides/cases/
  - name: Team Groups Management Service
    description: Manage Team Groups.
    externalDocs:
      url: ''
  - name: API Keys Admin Service
    description: Administrative operations for API Keys management.
    externalDocs:
      url: ''
  - name: Dashboard service
    description: Get information about the Coralogix Dashboard catalog.
    externalDocs:
      url: ''
  - name: Actions Service
    description: View and manage your Actions.
    externalDocs:
      url: ''
  - name: Target Service
    description: View and manage your storage targets for logs.
    externalDocs:
      description: Find out more about archives
      url: >-
        https://coralogix.com/docs/user-guides/data-flow/s3-archive/connect-s3-archive/
  - name: Integration service
    description: A service that enables querying for integration information.
    externalDocs:
      description: Find out more about integrations in our documentation.
      url: https://coralogix.com/docs/integrations/getting-started/
  - name: Alert Scheduler Rule service
    description: Manage your alert scheduler rules.
    externalDocs:
      url: ''
  - name: Entities service
    description: Query information about registered entities in the notification center
    externalDocs:
      description: Lean more about the notification center in our documentation
      url: https://coralogix.com/docs/user-guides/notification-center/introduction/
  - name: Incidents service
    description: >-
      Handle all operations related to incident management within Coralogix.
      Identify, manage, and resolve incidents efficiently through automated
      workflows and team collaboration.
    externalDocs:
      description: Find out more about incident management in our documentation
      url: https://coralogix.com/docs/user-guides/alerting/incidents/
  - name: Metrics Data Archive Service
    description: View and manage your storage targets for metrics.
    externalDocs:
      description: Find out more about archives
      url: >-
        https://coralogix.com/docs/user-guides/data-flow/s3-archive/connect-s3-archive/
  - name: Enrichments Service
    description: Manage your enrichments.
    externalDocs:
      url: ''
  - name: SAML Configuration Service
    description: Manage your SAML configuration
    externalDocs:
      url: ''
  - name: Role Management Service
    description: Service for managing system and custom roles.
    externalDocs:
      url: ''
paths:
  /incidents/aggregations/v1:
    get:
      tags:
        - Incidents service
      summary: Get incident aggregations
      description: >-
        Retrieve aggregated incident data with support for grouping and
        filtering.


        Requires the following permissions:

        - `incidents:read`
      operationId: IncidentsService_ListIncidentAggregations
      parameters:
        - in: query
          name: filter
          required: false
          schema:
            description: Filter configuration for incidents
            externalDocs:
              url: ''
            properties:
              applicationName:
                type: array
                items:
                  type: string
                  description: Filter by application names
              assignee:
                type: array
                items:
                  type: string
                  description: Filter by assignee
              contextualLabels:
                additionalProperties: {}
                description: Filter by contextual labels
                type: object
              createdAtRange: {}
              displayLabels:
                additionalProperties: {}
                description: Filter by display labels
                type: object
              endTime:
                type: string
                description: >-
                  Filters all incidents that were open in the given timeframe
                  end time (deprecated, use incident_open_range instead)
                format: date-time
                deprecated: true
              incidentDurationRange: {}
              isMuted:
                type: boolean
                description: Indicates if the incident is muted
              metaLabels:
                items:
                  title: Incident meta label
                  type: object
                  properties:
                    key:
                      type: string
                      example: key
                    value:
                      type: string
                      example: value
                  externalDocs:
                    url: ''
                type: array
              metaLabelsOp:
                $ref: '#/components/schemas/v1.FilterOperator'
              searchQuery: {}
              severity:
                type: array
                items:
                  $ref: '#/components/schemas/IncidentSeverity'
              startTime:
                type: string
                description: >-
                  Filters all incidents that were open in the given timeframe
                  start time (deprecated, use incident_open_range instead)
                format: date-time
                deprecated: true
              state:
                type: array
                items:
                  $ref: '#/components/schemas/IncidentState'
              status:
                type: array
                items:
                  $ref: '#/components/schemas/IncidentStatus'
              subsystemName:
                type: array
                items:
                  type: string
                  description: Filter by subsystem names
            title: Incident query filter
            type: object
        - in: query
          name: group_bys
          required: false
          schema:
            items:
              oneOf:
                - $ref: '#/components/schemas/GroupByContextualLabel'
                - $ref: '#/components/schemas/GroupByIncidentField'
            type: array
        - in: query
          name: pagination
          required: false
          schema:
            title: Pagination request
            required:
              - pageSize
            type: object
            properties:
              pageSize:
                type: integer
                description: Number of items to return per page
                format: int64
                example: 10
              pageToken:
                type: string
                description: Token for the next page of results
                example: next_page_token
            description: Pagination parameters for list requests
            externalDocs:
              url: ''
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListIncidentAggregationsResponse'
          description: ''
        '400':
          content:
            application/json: {}
          description: Bad Request
        '401':
          content:
            application/json: {}
          description: Unauthorized request
        '500':
          content:
            application/json: {}
          description: Internal server error
      externalDocs:
        url: ''
components:
  schemas:
    v1.FilterOperator:
      enum:
        - FILTER_OPERATOR_OR_OR_UNSPECIFIED
        - FILTER_OPERATOR_AND
      type: string
    IncidentSeverity:
      enum:
        - INCIDENT_SEVERITY_UNSPECIFIED
        - INCIDENT_SEVERITY_INFO
        - INCIDENT_SEVERITY_WARNING
        - INCIDENT_SEVERITY_ERROR
        - INCIDENT_SEVERITY_CRITICAL
        - INCIDENT_SEVERITY_LOW
      type: string
    IncidentState:
      enum:
        - INCIDENT_STATE_UNSPECIFIED
        - INCIDENT_STATE_TRIGGERED
        - INCIDENT_STATE_RESOLVED
      type: string
    IncidentStatus:
      enum:
        - INCIDENT_STATUS_UNSPECIFIED
        - INCIDENT_STATUS_TRIGGERED
        - INCIDENT_STATUS_ACKNOWLEDGED
        - INCIDENT_STATUS_RESOLVED
      type: string
    GroupByContextualLabel:
      title: Incident group by
      required:
        - field
      type: object
      properties:
        contextualLabel:
          type: string
          description: The contextual label to group by.
        orderByDirection:
          $ref: '#/components/schemas/v1.OrderByDirection'
      additionalProperties: false
      externalDocs:
        url: ''
    GroupByIncidentField:
      title: Incident group by
      required:
        - field
      type: object
      properties:
        incidentField:
          $ref: '#/components/schemas/IncidentFields'
        orderByDirection:
          $ref: '#/components/schemas/v1.OrderByDirection'
      additionalProperties: false
      externalDocs:
        url: ''
    ListIncidentAggregationsResponse:
      title: List incident aggregations response
      required:
        - incidentAggs
        - pagination
      type: object
      properties:
        incidentAggs:
          type: array
          items:
            $ref: '#/components/schemas/IncidentAggregation'
        pagination:
          $ref: '#/components/schemas/incidents.v1.PaginationResponse'
      description: Response containing aggregated incident data and pagination information
      externalDocs:
        url: ''
    v1.OrderByDirection:
      enum:
        - ORDER_BY_DIRECTION_UNSPECIFIED
        - ORDER_BY_DIRECTION_ASC
        - ORDER_BY_DIRECTION_DESC
      type: string
    IncidentFields:
      enum:
        - INCIDENTS_FIELDS_UNSPECIFIED
        - INCIDENTS_FIELDS_ID
        - INCIDENTS_FIELDS_SEVERITY
        - INCIDENTS_FIELDS_NAME
        - INCIDENTS_FIELDS_CREATED_TIME
        - INCIDENTS_FIELDS_CLOSED_TIME
        - INCIDENTS_FIELDS_STATE
        - INCIDENTS_FIELDS_STATUS
        - INCIDENTS_FIELDS_LAST_STATE_UPDATE_TIME
        - INCIDENTS_FIELDS_APPLICATION_NAME
        - INCIDENTS_FIELDS_SUBSYSTEM_NAME
        - INCIDENTS_FIELDS_DURATION
      type: string
    IncidentAggregation:
      title: Incident aggregation
      required:
        - groupBysValue
        - aggStateCount
        - aggStatusCount
        - aggSeverityCount
        - aggAssignmentsCount
        - firstCreatedAt
        - lastClosedAt
        - allValuesCount
        - listIncidentsId
        - lastStateUpdateTime
        - aggMetaLabelsCount
      type: object
      properties:
        aggAssignmentsCount:
          type: array
          items:
            $ref: '#/components/schemas/IncidentAssignmentCount'
        aggMetaLabelsCount:
          type: array
          items:
            $ref: '#/components/schemas/IncidentMetaLabelsCount'
        aggSeverityCount:
          type: array
          items:
            $ref: '#/components/schemas/IncidentSeverityCount'
        aggStateCount:
          type: array
          items:
            $ref: '#/components/schemas/IncidentStateCount'
        aggStatusCount:
          type: array
          items:
            $ref: '#/components/schemas/IncidentStatusCount'
        allValuesCount:
          type: integer
          format: int64
        firstCreatedAt:
          type: string
          format: date-time
        groupBysValue:
          type: array
          items:
            $ref: '#/components/schemas/GroupByValues'
        lastClosedAt:
          type: string
          format: date-time
        lastStateUpdateTime:
          type: string
          format: date-time
        listIncidentsId:
          type: array
          items:
            type: string
      externalDocs:
        url: ''
    incidents.v1.PaginationResponse:
      title: Pagination response
      required:
        - totalSize
      type: object
      properties:
        nextPageToken:
          type: string
          description: Token for the next page of results
          example: next_page_token
        totalSize:
          type: integer
          description: Total number of items available
          format: int64
          example: 100
      description: Pagination information for list responses
      externalDocs:
        url: ''
    IncidentAssignmentCount:
      title: Incident assignment count
      required:
        - assignedTo
        - count
      type: object
      properties:
        assignedTo:
          $ref: '#/components/schemas/incidents.v1.UserDetails'
        count:
          type: integer
          format: int64
          example: 10
      externalDocs:
        url: ''
    IncidentMetaLabelsCount:
      title: Incident meta labels count
      required:
        - metaLabel
        - count
      type: object
      properties:
        count:
          type: integer
          format: int64
          example: 10
        metaLabel:
          $ref: '#/components/schemas/incidents.v1.MetaLabel'
      externalDocs:
        url: ''
    IncidentSeverityCount:
      title: Incident severity count
      required:
        - severity
        - count
      type: object
      properties:
        count:
          type: integer
          format: int64
          example: 10
        severity:
          $ref: '#/components/schemas/IncidentSeverity'
      externalDocs:
        url: ''
    IncidentStateCount:
      title: Incident state count
      required:
        - state
        - count
      type: object
      properties:
        count:
          type: integer
          format: int64
          example: 10
        state:
          $ref: '#/components/schemas/IncidentState'
      externalDocs:
        url: ''
    IncidentStatusCount:
      title: Incident status count
      required:
        - status
        - count
      type: object
      properties:
        count:
          type: integer
          format: int64
          example: 10
        status:
          $ref: '#/components/schemas/IncidentStatus'
      externalDocs:
        url: ''
    GroupByValues:
      oneOf:
        - $ref: '#/components/schemas/GroupByValuesIncidentField'
        - $ref: '#/components/schemas/GroupByValuesContextualLabels'
    incidents.v1.UserDetails:
      title: User details
      required:
        - userId
      type: object
      properties:
        userId:
          type: string
          example: user_id
      externalDocs:
        url: ''
    incidents.v1.MetaLabel:
      title: Incident meta label
      type: object
      properties:
        key:
          type: string
          example: key
        value:
          type: string
          example: value
      externalDocs:
        url: ''
    GroupByValuesIncidentField:
      type: object
      properties:
        incidentField:
          $ref: '#/components/schemas/IncidentFieldOneOf'
      additionalProperties: false
    GroupByValuesContextualLabels:
      type: object
      properties:
        contextualLabels:
          $ref: '#/components/schemas/ContextualLabels'
      additionalProperties: false
    IncidentFieldOneOf:
      oneOf:
        - $ref: '#/components/schemas/IncidentFieldOneOfSubsystemName'
        - $ref: '#/components/schemas/IncidentFieldOneOfDuration'
        - $ref: '#/components/schemas/IncidentFieldOneOfClosedAt'
        - $ref: '#/components/schemas/IncidentFieldOneOfStatus'
        - $ref: '#/components/schemas/IncidentFieldOneOfApplicationName'
        - $ref: '#/components/schemas/IncidentFieldOneOfId'
        - $ref: '#/components/schemas/IncidentFieldOneOfSeverity'
        - $ref: '#/components/schemas/IncidentFieldOneOfName'
        - $ref: '#/components/schemas/IncidentFieldOneOfCreatedAt'
        - $ref: '#/components/schemas/IncidentFieldOneOfState'
        - $ref: '#/components/schemas/IncidentFieldOneOfLastStateUpdateTime'
    ContextualLabels:
      title: Incident contextual labels
      required:
        - fieldName
        - fieldValue
      type: object
      properties:
        fieldName:
          type: string
          example: field_name
        fieldValue:
          type: string
          example: field_value
      externalDocs:
        url: ''
    IncidentFieldOneOfSubsystemName:
      type: object
      properties:
        subsystemName:
          type: string
      additionalProperties: false
    IncidentFieldOneOfDuration:
      type: object
      properties:
        duration:
          type: string
      additionalProperties: false
    IncidentFieldOneOfClosedAt:
      type: object
      properties:
        closedAt:
          type: string
          format: date-time
      additionalProperties: false
    IncidentFieldOneOfStatus:
      type: object
      properties:
        status:
          $ref: '#/components/schemas/IncidentStatus'
      additionalProperties: false
    IncidentFieldOneOfApplicationName:
      type: object
      properties:
        applicationName:
          type: string
      additionalProperties: false
    IncidentFieldOneOfId:
      type: object
      properties:
        id:
          type: string
      additionalProperties: false
    IncidentFieldOneOfSeverity:
      type: object
      properties:
        severity:
          $ref: '#/components/schemas/IncidentSeverity'
      additionalProperties: false
    IncidentFieldOneOfName:
      type: object
      properties:
        name:
          type: string
      additionalProperties: false
    IncidentFieldOneOfCreatedAt:
      type: object
      properties:
        createdAt:
          type: string
          format: date-time
      additionalProperties: false
    IncidentFieldOneOfState:
      type: object
      properties:
        state:
          $ref: '#/components/schemas/IncidentState'
      additionalProperties: false
    IncidentFieldOneOfLastStateUpdateTime:
      type: object
      properties:
        lastStateUpdateTime:
          type: string
          format: date-time
      additionalProperties: false
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: API key authentication

````