Timeline
Every kind of event, across every monitor you own, on one calendar — incidents, maintenance, cron runs, alerts, SSL and domain expiries, and configuration changes.
What is the Timeline?
The Timeline (the Timeline item in the sidebar, at /dashboard/timeline) is a single calendar of everything that has happened — and everything that's coming — across all of your monitors, regardless of type.
Most monitoring tools give you a feed per thing: incidents in one place, maintenance in another, cron runs somewhere else. The Timeline merges all of it into one month, week, or day grid, so you can see how events relate to each other in time.
Example: "We had an outage on the 14th. What else happened that day?" — open the Timeline, click the 14th, and you see the incident, the alerts it fired, the config change someone made 20 minutes earlier, and the maintenance window that ended just before it.
The Timeline is read-only. You don't create, edit, pause, acknowledge, or resolve anything from here — it's a lens over data the rest of the product produces. Every event links out to the page where you can act on it.
Timeline vs. the other activity screens
Enori has several places that show "what happened". They overlap on purpose, but each is best at something different:
| Screen | Best for | Not for |
|---|---|---|
Timeline (/dashboard/timeline) | "Show me everything, on a calendar, for any past month." Cross-type correlation, monthly reviews, planning around expiries and maintenance, exporting a date range. | Complete history of one event type — it's a survey (see below). |
| Recent Activity (dashboard panel) | "What just happened?" A live, short backward feed on your dashboard. | Anything older than recent. |
| Upcoming (dashboard panel) | "What's coming?" Forward-looking renewals, expiries, scheduled maintenance. | The past. |
Incidents (/dashboard/incidents) | Full incident history, acknowledging and resolving, postmortems. | Non-incident events. |
Audit log (/dashboard/audit-log) | The complete, searchable record of every configuration change — who, when, from which IP. | Incidents, runs, expiries. |
Jobs overview (/dashboard/jobs) | Cron and scheduled-task operations — live Up/Late/Down status and a run calendar. | Anything that isn't a job. |
Rule of thumb: if you know which type of thing you're looking for, go to that type's page. If you're looking for how different types line up in time, the Timeline is the only screen that shows that.
When to use it
- Monthly ops review. Open a month grid and see clusters at a glance — three incidents in the same week, all on the same day of the month, or always right after a deploy-shaped config change.
- Post-incident correlation. "What else was going on around the outage?" One day view answers it without cross-referencing four pages.
- Renewal and maintenance planning. SSL and domain expiries appear on their future dates, next to your scheduled maintenance windows — so you can see conflicts before you schedule anything.
- Handing a date range to someone else. Export the visible window as CSV or JSON for a report, an audit request, or a spreadsheet.
- Keeping Enori in your own calendar. Subscribe from Google Calendar, Outlook, or Apple Calendar so upcoming maintenance and expiries sit next to your meetings.
When not to use it:
- To get a complete record of one event type — the Timeline deliberately shows only the most recent activity per source (see It's a survey, not a full record).
- To act on something — acknowledging an incident, editing a maintenance window, pausing a monitor all happen on their own pages. The Timeline links you there.
The seven event families
Every entry on the Timeline belongs to one of seven families. Each has its own colour and its own filter pill.
| Family | Pill label | What produces it |
|---|---|---|
| Incidents | Incidents | A monitor going down, plus a second entry when it recovers. A resolved incident therefore appears twice: the outage (with its duration) and the recovery. |
| Maintenance | Maintenance | Your maintenance windows — one-time and recurring — shown across their scheduled span with the affected monitors. |
| Jobs | Jobs | Individual cron / scheduled-task runs: success, fail, overdue, timeout, or slow. |
| Alerts | Alerts | Each notification Enori actually sent, with the channel it went to. |
| SSL | SSL | Certificate expiry dates for your monitored sites, plotted on the day they expire. |
| Domain | Domain | Domain registration expiry dates, same idea. |
| Changes | Changes | Configuration changes from your audit log — monitor created/updated/paused, alert channel changed, team updated, and so on. |
A few details worth knowing:
- SSL and domain entries look ahead. An SSL expiry shows up if it falls inside the window you're viewing or within 30 days after it; domain expiries reach 60 days past the window. They turn critical (red) at 7 days for SSL and 14 days for domains. That's why you'll see future expiries when browsing the current month.
- "Changes" means real configuration changes. Routine noise is filtered out — export actions and the background "user updated" record never appear, so the Changes count stays meaningful.
- Alerts are notifications, not incidents. One incident can produce several alert entries (one per channel). If you want the incident itself, use the Incidents pill.
The four views
A List · Month · Week · Day switcher sits at the top-left. The page opens on Month.
Month (the default)
A calendar grid, weeks starting Monday. Each day with activity gets:
- A background wash whose intensity scales with how busy the day was, tinted red if anything critical happened, amber for warnings, blue otherwise.
- Up to three coloured bars, one per event family present that day, with a small count when there was more than one. If more than three families were involved, you get two bars and a "+N more".
- A tooltip on hover spelling it out — "Mar 14: 2 incidents, 3 alerts, 1 changes".
Today's cell is ringed. Use the ‹ › arrows to change month; a ↩ Today link appears next to the month name whenever you've navigated away. Clicking any day jumps to the Day view for that date.
Screenshot: the Month grid on a busy month — several days with coloured bars, one clearly red/critical day, today ringed.
Week and Day
Both lay events out against a 24-hour axis, positioned at the time they happened. Events that overlap sit side by side instead of hiding each other. Events with a duration (incidents, maintenance, job runs) draw as blocks showing start → end and the elapsed time; point-in-time events (alerts, config changes) draw as thin labelled bars.
When you're viewing today, a red "Now" line marks the current time, and the view scrolls itself there on open. Otherwise it scrolls to the first event of the day. Click any event to open its detail panel.
List
Events grouped by day, newest first, with Today / Yesterday / full-date headers and a per-day count. Each row shows the title, the family, a short description, the time, and the monitor it belongs to. The list covers the same month as the Month view.
Filtering
Under the view switcher is a row of seven pills — Incidents, Maintenance, Jobs, Alerts, SSL, Domain, Changes. All are on by default. Click to toggle one off; click again to bring it back.
- Turning pills off narrows every view and what gets exported.
- Turning all of them off shows "No event types selected. Enable a filter above to see activity." rather than silently showing everything.
There is no monitor picker on this page — the Timeline is deliberately account-wide. To see one monitor's events on their own, open that monitor and expand the Calendar section on its detail page; it shows the same seven families scoped to that monitor alone.
Your view, month, and filter selections are not stored in the page URL, so the page opens on the current month with all pills on each time.
Reading the summary bar
Above the calendar is a row of counters for the range you're viewing: a Total, then one counter per family that has any events (families with zero are hidden). These count the events actually loaded for the window, so they always match what's drawn below.
It's a survey, not a full record
The Timeline is designed to answer "what happened around then", not to be a system of record. For a very busy account it loads only the most recent 500 entries per family for the window you're viewing. When that limit is hit you'll see:
Showing the most recent activity for this range. Narrow the window or open a specific monitor to see the full history.
If you see that line and you need everything, either narrow the range (a week instead of a month) or use the dedicated page for that type — Incidents, the Audit log, and the Jobs overview all hold the complete history.
Opening an event
Click any event — a list row, a block in Week/Day, or an entry after clicking through from Month — and a panel slides in from the right with:
- Family and sub-type (incident / down, job / fail, ssl / expiring_soon).
- Title and description.
- Severity — Critical, Warning, or Info.
- Start time, and the end time when the event has a duration.
- The monitor it belongs to.
- A Details block with extra fields for that family (incident id and HTTP status, job duration and exit code, the alert's channel and delivery status, days until expiry…).
- A link to where you can act on it — View incident, View monitor, View maintenance, View alerts, View audit log.
Press Esc or click the backdrop to close it.
Upcoming
On the Month and List views, an Upcoming section sits between the calendar controls and the grid. It's a forward-looking list — expiring certificates and domains, scheduled maintenance, snooze resumes, subscription and trial dates — for roughly the next 90 days, grouped into imminent / soon / later. It's hidden entirely when there's nothing upcoming, and on the Week and Day views.
Exporting a range
The Export button (top-right) downloads what you're currently looking at — the visible date range and your active type filters — in one of three formats:
| Format | Use it for |
|---|---|
| JSON | Feeding another tool, scripting, archiving with full structure. |
| CSV | Spreadsheets and reports. Columns: id, type, sub-type, timestamp, end timestamp, monitor id, monitor name, title, description, severity. |
| iCal (.ics) | A one-off file to import into a calendar app. |
The file is named timeline-. To export a different period, navigate to it first, then export.
A downloaded .ics is a snapshot — it never changes after you import it. If you want your calendar to stay current, subscribe instead.
Subscribing from your calendar app
The Calendar subscription card (on the Month and List views) gives you a private feed URL that Google Calendar, Outlook, or Apple Calendar can subscribe to. Unlike a downloaded file, a subscription keeps updating — your calendar app re-fetches it periodically.
The feed always covers a rolling window of the last 30 days and the next 60 days of your Timeline, and appears in your calendar app as "Enori Timeline". Maintenance windows and SSL/domain expiries come through as all-day entries; incidents, job runs, alerts, and changes come through as timed entries.
1. Enable the feed
On the Timeline, find the Calendar subscription card and click Enable calendar feed. Enori generates a private URL for your account. Nothing is shared until you do this — the feed is off by default.
2. Copy the URL
The card now shows a webcal://… URL. Click the copy icon next to it.
3. Add it to your calendar app
Paste the URL into your calendar's subscribe to calendar flow:
| App | Where |
|---|---|
| Google Calendar | Other calendars → + → From URL |
| Apple Calendar | File → New Calendar Subscription |
| Outlook | Add calendar → Subscribe from web |
Most apps also accept a pasted webcal:// link directly in the browser and hand it to your default calendar app.
4. Treat the URL as a secret
Anyone who has this URL can read your Timeline — there is no additional login on it. That's what makes it work in calendar apps, and it's why the card warns you. Don't paste it into a shared doc, a ticket, or a public repo.
Two controls sit under the URL:
- Rotate URL — issues a brand-new URL and immediately invalidates the old one. Use this if the link leaked or you shared it by accident. You'll need to re-subscribe in your calendar app with the new URL.
- Revoke — turns the feed off entirely. The URL stops working and existing subscriptions go dead. You can enable a fresh one later.
Screenshot: the Calendar subscription card in its enabled state — the webcal URL, the copy button, and the Rotate / Revoke actions.
How current is it?
The Timeline refreshes itself when incident, alert, configuration, or maintenance activity comes in while you have it open, and results are cached for a few seconds to keep the page fast. A handful of background state changes reconcile on the next load rather than pushing live — so if you're waiting to see something specific appear, reload the page.
Everything you see is bound by how long Enori keeps that data for your plan:
| Data | Base | Pro | Business |
|---|---|---|---|
| Incidents, job runs, alerts, check history | 30 days | 60 days | 90 days |
| Configuration changes (audit log) | 7 days | 30 days | 90 days |
Browsing to a month older than your retention will show little or nothing, even though those events did happen. Export regularly if you need a longer-lived record.
A note on time zones
Event times are rendered in your browser's local time zone, while the calendar buckets events into days by UTC date. For almost everything this is invisible. The one place it shows up is events near midnight: an event a couple of hours either side of UTC midnight can be grouped under the neighbouring calendar day from the one its displayed time suggests. If a run or incident seems to be filed on the "wrong" day, that's why.
The Jobs overview shows everything in UTC end to end, so if you're comparing the two screens for a late-night job, expect that offset.
FAQ
Can I create or change anything from the Timeline?
No. It's read-only by design. Every event links to the page where the action lives — the incident, the monitor, the maintenance list, the audit log.
Why does one incident appear twice?
A resolved incident produces two entries: the moment it went down (carrying the outage duration) and the moment it recovered. An incident that's still open only shows the first.
Why do I see SSL and domain expiries in the future?
Because that's when they happen. Expiry entries are plotted on the expiry date, and the Timeline deliberately reaches a little past the window you're viewing (30 days for SSL, 60 for domains) so a renewal never sneaks up on you at a month boundary.
What's the difference between the "Alerts" pill and the "Incidents" pill?
Incidents are the outages themselves. Alerts are the notifications Enori sent about them — one per channel. A single incident with email + Slack configured shows one incident entry and two alert entries.
Why does it say "showing the most recent activity"?
Your account produced more events in that window than the Timeline loads per family (500). It's a survey view, not a complete log. Narrow the range, or open the dedicated page for that event type to see everything.
Can I filter to one monitor?
Not from this page — the Timeline is account-wide. Open the monitor's detail page and expand the Calendar section for a single-monitor version of the same view.
Does the export include my filters?
Yes. Export downloads exactly what you're looking at: the visible date range plus whichever type pills are on.
How far back can I look?
As far as your plan's retention allows (see the table above). Any single request covers at most 90 days, and the page itself never loads more than a month at a time — use the ‹ › arrows to walk backwards.
Someone has my subscription URL. What do I do?
Click Rotate URL on the Calendar subscription card. The old URL stops working immediately. Then re-subscribe in your own calendar app with the new one.
Can I get this data programmatically?
Yes — the same timeline is available from the Enori API at /api/calendar/unified with an API key carrying the monitors:read scope. See the API reference.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| "No event types selected" | Every filter pill is toggled off. | Click at least one pill to turn it back on. |
| "No events in this date range" | Nothing happened in that window, filters exclude it, or the month predates your plan's retention. | Turn all pills on, move to a month you know had activity, and check your retention window. |
| "We couldn't load your timeline" | A transient error loading the range. | Click Retry. If it persists, reload the page. |
| A change I just made isn't showing | Results are cached briefly, and a few background state changes don't push live. | Wait a few seconds and reload the page. |
| An event looks like it's on the wrong day | Times display in your local zone; days are grouped by UTC. | Check the exact time in the event's detail panel — near-midnight events can sit on the neighbouring day. |
| The month is unusually empty for a busy account | A type filter is off, or you're past your plan's retention. | Re-enable all pills; compare against the Incidents / Audit log / Jobs pages, which hold full history. |
| My subscribed calendar stopped updating | The feed was rotated or revoked. | Open the Calendar subscription card; if it's disabled, enable it and re-subscribe with the new URL. |
| Export downloaded nothing | A transient error, or the current range genuinely has no events. | Confirm events are visible on screen first, then retry the Export button. |
Reference
| Setting | Value |
|---|---|
| Route | /dashboard/timeline (the old /dashboard/calendar redirects here) |
| Views | List · Month (default) · Week · Day |
| Event families | Incidents · Maintenance · Jobs · Alerts · SSL · Domain · Changes |
| Week start | Monday |
| Maximum window per request | 90 days (the page loads at most one month at a time) |
| Events loaded per family | Most recent 500 — a truncation hint appears when it's reached |
| Export formats | JSON · CSV · iCal (.ics), filename timeline- |
| Subscription feed window | Last 30 days + next 60 days, rolling |
| Subscription feed controls | Enable · Copy · Rotate URL · Revoke |
| Writes anything? | No — read-only (an export is recorded in your audit log) |
Related documentation
- Jobs overview — the operations view for cron and scheduled tasks, with live status and a run calendar
- Audit log — the complete record behind the "Changes" family
- Uptime reports — formal uptime and SLA reporting for a period
- API reference — reading the same timeline programmatically
Draft — last updated 2026-07-25. Feedback or corrections: support@enori.io