incidents command targets one application, identified either by name and environment (--app "MyApp" --environment production) or by ID (--app-id <APP_ID>, the long hexadecimal app ID from appsignal-cli apps list). The --environment flag is only needed when several apps share a name. Add --org to override your default organization. See Apps and organizations for how apps are identified.
List incidents
To list recent incidents of all types for an app:Shell
List by type
Three commands narrow the results to a single incident type:Shell
Filter and search
The list commands share a set of filters:incidents list, list-exceptions, and list-performance also accept:
To find timeout errors:
Shell
web namespace:
Shell
The list commands return recent incidents, so older ones may not appear even when they’re still open. To open a specific incident regardless of age, use
incidents show with its number.Show an incident
To see the full details of a single incident, pass its number:Shell
show also lists the error causes from the incident’s trace data. Sometimes one error wraps another, such as a timeout that surfaces as a generic request error. When that happens, the underlying causes appear next to the top-level exception, so you can find the root cause without opening a trace in the web UI.
Update an incident
Update an incident’s state, severity, notification frequency, assignees, or description by number:Shell
To change several incidents at once, pass a comma-separated list of numbers. Bulk updates currently support
--state only:
Shell
Set notification frequency
--notification-frequency controls when AppSignal notifies you about an incident’s occurrences. It takes the same options as the notification setting in the AppSignal UI, described in Notification settings:
To be notified only when a closed incident happens again:
Shell
NTH_IN_HOUR and NTH_IN_DAY use --notification-threshold to set which occurrence sends the notification. Pass it together with the frequency. To be notified on every tenth occurrence each day:
Shell
Assign an incident
To assign an incident to yourself, use--assign-me. It needs no user ID:
Shell
--assign, comma-separated. A user ID is a long hexadecimal string. Find names and IDs with apps resources users, which lists each user’s name, ID, and email:
Shell
--assign:
Shell
--unassign the same way.
Notes
Notes record what you found on an incident and stay with it, so whoever opens the incident next has the context. You can add a note, list the notes on an incident, and edit or remove the ones you wrote.Add a note
Shell
Shell
$'...' quoting turns \n into a real newline in Bash and Zsh. In a shell without it, pass the content as a quoted multi-line string.
List notes
Editing or deleting a note needs its ID. List an incident’s notes to find it, along with each note’s author, source, timestamp, and whether you can edit or delete it:Shell
Update or delete a note
Pass the note ID fromlist-notes. update-note replaces the note’s content:
Shell
delete-note removes it:
Shell
You can update and delete only the notes you wrote.
list-notes marks them in its CAN EDIT and CAN DELETE columns.JSON output
Like every command, the incidents commands accept the global--output json (or --format json) flag, which returns machine-readable output for scripts and AI agents:
Shell
incidents show:
Shell