Skip to content
Guide

Incident replay

Build a post-mortem timeline of what happened in your community with a single command.

1

Build a report

Run n!incident <timeframe> [title] in your server, for example n!incident 2h raid from #general. You can also generate a report from the Incidents page in the dashboard. Use n!incidents to list your stored reports.

2

What the timeline captures

The report merges member joins and leaves, bans and unbans, moderation cases, automod hits, message deletions and channel or role changes into one timestamped timeline. It also flags message spikes: channels that suddenly move far above their normal rate.

3

Reading the deleted messages

Expand a deletion in the timeline to see the message that was removed, plus the messages around it in that channel. Bulk deletes and purges show a sample of what went with them - the bot records up to 20 messages per purge - along with how many were deleted in total and how many people they came from.

4

Activity retention

Reports are built from the last 14 days of recorded activity. Older events can no longer be replayed, so generate a report soon after an incident if you want the full picture. Message content inside a report is kept for 7 days, matching how long deleted messages are stored; after that the timeline still shows who deleted what and where, just not the text.

5

The Incidents pages

Every report is a stored snapshot with a shareable dashboard link. The report page shows summary stats, headline actors and spike channels, plus the full timeline you can filter by event kind. The timeline reads oldest first by default, with the window start and end marked at either end; use the sort button to flip it.

What incident replay doesThe overview, with the highlights.