7 Chapter 7 — NWS Data: Warnings, Forecasts, and Official Products
Every other chapter in this guide has been about observational data — what the atmosphere actually did, as measured by sensors and reported by observers. This chapter is different. The NWS Data section of the IEM is an archive of decisions: what forecasters thought was happening, what they warned the public about, when they issued those warnings relative to the event, and what language they used to justify the call. That is a fundamentally different kind of record, and it requires a different frame of mind to use effectively.
The NWS Mainpage at mesonet.agron.iastate.edu/nws/ is the hub for all of it. It is one of the most link-dense pages on the IEM — dozens of individual tools organized by category — and one of the easiest places to feel lost. This chapter works through it systematically, with the deepest treatment reserved for VTEC, which is the structural backbone that makes almost everything else here possible.
VTEC: The Backbone of the Warning Archive
Before touching any individual tool, you need to understand VTEC — not because it is complicated, but because once you do understand it, every warning archive tool on the IEM suddenly makes sense.
VTEC stands for Valid Time Event Code. It is the structured metadata system the NWS began embedding in its watch, warning, and advisory products in 2005. Before VTEC, a tornado warning was just a text product with a start time and a geographic area. There was no systematic way to track whether that warning was extended, updated, cancelled, or superseded by a new issuance. Post-event analysis required reading each text product manually and reconstructing the timeline by hand.
VTEC changed that by requiring each significant weather product to carry a machine-parseable code block that encodes everything needed to track the full lifecycle of that event. A typical VTEC string looks like this:
/O.NEW.KCTP.TO.W.0012.240615T2031Z-240615T2200Z/
Reading left to right: the /O. indicates this is an operational (not test) product. NEW is the action code — this is a new issuance. KCTP is the four-character WFO identifier (State College, Pennsylvania). TO is the phenomena code — tornado. W is the significance — Warning (as opposed to A for Watch, Y for Advisory, or S for Statement). 0012 is the Event Tracking Number (ETN) — the twelfth tornado warning issued by CTP in this calendar year. 240615T2031Z is the event begin time in UTC, and 240615T2200Z is the initial expiration time.
When forecasters update a warning — to extend its coverage, extend its time, or cancel it before the original expiration — they issue a follow-up product with its own VTEC string using action codes like CON (continued), EXT (extended), CAN (cancelled), or EXP (expired naturally). The IEM tracks all of these and links them together by ETN, giving you the complete lifecycle of every VTEC event in its archive rather than a pile of disconnected text products.
What the ETN Tells You
The Event Tracking Number is unique per WFO, per phenomena/significance combination, per calendar year. CTP’s twelfth tornado warning of 2024 is always CTP-TO.W-0012-2024, regardless of which county it covered or which day it was issued. This means ETNs reset on January 1 of each year, which has an important practical implication: when you are searching across a year boundary, you need to specify the year explicitly. A search for “CTP tornado warnings” without a year constraint will return results across all years, and the ETN numbering starts over each time.
The maximum ETN issued by a WFO in a given year is a rough proxy for event frequency. The IEM has a page at /vtec/maxetn.php that shows the highest ETN reached by each WFO each year for any phenomena/significance type. If you want to know whether 2024 was an unusually active tornado warning year for a specific WFO, this is the fastest way to check.
Phenomena and Significance Codes
The phenomena code is always two letters. The most common ones for weather enthusiasts: TO (Tornado), SV (Severe Thunderstorm), FF (Flash Flood), FA (Areal Flood), FL (Flood), WS (Winter Storm), WW (Winter Weather), BZ (Blizzard), IS (Ice Storm), ZR (Freezing Rain), WI (Wind), SC (Small Craft), FW (Fire Weather), HU (Hurricane), TS (Tropical Storm), SS (Storm Surge). The significance codes: W (Warning), A (Watch), Y (Advisory), S (Statement), O (Outlook), N (Synopsis), F (Forecast).
So SV.A is a Severe Thunderstorm Watch, WS.W is a Winter Storm Warning, FF.W is a Flash Flood Warning, and ZR.Y is a Freezing Rain Advisory. Once you have internalized this two-part structure, every IEM warning search interface becomes immediately legible.
The VTEC Browser
mesonet.agron.iastate.edu/vtec/
The VTEC Browser is the IEM’s event-level interface to the warning archive. It was substantially rewritten in June 2025, so if you have used it before and things look different, that is why. The interface asks you to select a WFO, a phenomena type, a significance, and a year and event number, then loads a complete event record with six tabs: Help, Event Info, Text Data, Interactive Map, Storm Reports, and List Events.
The power is in what each tab shows. Event Info gives you the structured metadata: issue time, expiration time, the full list of counties/parishes/zones included in the product, the polygon geometry if it is a storm-based warning, and the area in square kilometers. Text Data shows you the full raw text of every product associated with that event — the initial issuance and every subsequent update or cancellation in chronological order. Interactive Map overlays the warning polygon on an archival radar composite at the time of issuance — the IEM fetches the appropriate NEXRAD mosaic for the event time automatically. Storm Reports shows all Local Storm Reports within the warning’s political coverage area (the zone or county), and — for storm-based warnings — also filters the subset of LSRs that fall within the actual warning polygon. List Events shows every event of the selected type and year for that WFO, so you can browse and click through the season’s entire record.
The URL structure for a specific event is clean and bookmarkable: /vtec/YYYY-O-NEW-KWFO-PH-SIG-NNNN where KWFO is the four-character WFO, PH is phenomena, SIG is significance, and NNNN is the zero-padded ETN. For CTP’s twelfth tornado warning of 2024: /vtec/2024-O-NEW-KCTP-TO-W-0012. That URL takes you directly to that event — no navigation required. This makes it easy to construct links to specific events when discussing them on a forum.
Warning Search
mesonet.agron.iastate.edu/vtec/search.php
Where the VTEC Browser navigates event by event, the Warning Search is how you query the archive at scale. You can filter by WFO, phenomena type, significance, date range, and geography — either by selecting a state and county or by clicking a point on the map. Results return a table of matching events with their issue time, expiration, ETN, and area, each row linking directly into the VTEC Browser for that event.
The geographic point search is particularly powerful for personal-use questions: “how many tornado warnings have covered my town in the last twenty years?” Click your location on the map, set the date range and the phenomena filter, and the IEM returns every VTEC event whose polygon or county/zone coverage included that point. This is the tool to reach for when a forum discussion turns to “how warning-prone is this area” and you want to answer with actual data rather than anecdote.
The search also supports the reverse question: “show me everything CTP issued in June 2024.” Set the WFO to CTP, leave geography open, set the date range to June 2024, and select all warning types. The result is a complete operational log of that month’s warning activity for that office, sortable by time, type, or area.
Storm-Based Warnings and IEM Cow
Before October 1, 2007, NWS warnings were issued for entire counties. A tornado warning for Lancaster County, Pennsylvania covered all 946 square miles of it, regardless of where the storm was actually tracking. On that date, the NWS switched to Storm-Based Warnings (SBW) — polygonal areas drawn to cover the actual storm track, typically much smaller than a county, updated in real time as the storm moves. The IEM archives both the pre-SBW county-based warnings and the post-SBW polygon warnings, and the distinction matters enormously for verification work.
IEM Cow (Convective Warning Verification) at mesonet.agron.iastate.edu/cow/ is the tool built specifically to work with the SBW polygon archive. Its name is not an acronym — it is just a cow. The tool lets you select a WFO, a date range, and a warning type, and it computes verification statistics by comparing issued warning polygons against Local Storm Reports.
The core metrics Cow produces: probability of detection (POD, the fraction of LSRs inside a warning polygon), false alarm ratio (FAR, the fraction of warnings with no confirming LSR inside the polygon), and critical success index (CSI, which combines both). It also reports lead time — the median number of minutes between warning issuance and the first confirming LSR — and the area-weighted coverage statistics. These are the same metrics used in published NWS verification studies, so Cow results are directly comparable to the peer-reviewed literature on warning performance.
A few things to understand about interpreting Cow results. LSRs are the verification ground truth, which means Cow inherits all the limitations of the LSR network: spotter coverage is uneven, nighttime and rural events are underreported, and some event types (particularly wind damage) are systematically under-LSR’d in low-population areas. A high FAR on a rural WFO’s tornado warnings may reflect poor spotter coverage as much as it reflects poor warning skill. Cow is an excellent tool for trend analysis and comparative studies, but interpreting the absolute numbers requires contextual judgment about the LSR network’s completeness in the area being studied.
Cow works for dates after June 8, 2005, with the SBW polygon verification only meaningful after October 2007 when polygons became the operational standard. For dates before October 2007, the application runs in county-based mode.
The companion tool IEM Raccoon at mesonet.agron.iastate.edu/raccoon/ generates Microsoft PowerPoint presentations of storm-based warning records for a WFO and radar site, useful for training materials or post-event briefings where you want visual documentation of the full warning sequence.
Local Storm Reports
mesonet.agron.iastate.edu/lsr/
Local Storm Reports are the NWS’s real-time field observations of weather impacts: tornado touchdowns and paths, hail size and location, measured or estimated wind gusts, wind damage, flooding, waterspouts, and other significant phenomena. They are issued by WFO meteorologists and their spotter networks throughout an event and archived by the IEM in real time.
The LSR App at /lsr/ lets you query the archive by WFO, date range, event type, magnitude thresholds (minimum hail size, minimum wind speed), and geographic extent. Results display on an interactive map and in a sortable table, with each report showing the reporting source (trained spotter, law enforcement, public, emergency management, etc.), the time, the location, and any magnitude values.
For archived LSRs as shapefiles — useful for GIS analysis — the download portal is at /request/gis/lsrs.phtml, which covers the archive back to 2003. For the past 24 hours, a live shapefile, CSV, and GeoJSON are always available at static URLs in the IEM data directory:
- Shapefile:
/data/gis/shape/4326/us/lsr_24hour.zip - CSV:
/data/gis/shape/4326/us/lsr_24hour.csv - GeoJSON:
/data/gis/shape/4326/us/lsr_24hour.geojson
These files update every five minutes and are the fastest way to get a current snapshot of field reports during an active event.
What LSRs are not: they are not a complete record of impacts. They reflect what spotters and observers happened to report, which means sparsely populated areas, events that happen at night, and event types that do not produce easily visible damage are all systematically underrepresented. The IEM’s LSR Snowfall Analysis (Autoplot q=207) is one of the more instructive examples of this gap — the snowfall LSR map for any given winter storm will show dense reporting near population centers and conspicuous holes in rural areas where snowfall may have been just as heavy but no one submitted a report.
The Text Archive
mesonet.agron.iastate.edu/nws/text.php
The IEM archives essentially the full NOAAPORT text product feed — every text product transmitted by the NWS, going back to the mid-2000s for most product types. This includes Area Forecast Discussions (AFDs), Public Information Statements, Special Weather Statements (SPS), CLI daily climate summaries, CF6 monthly climate reports, hydro products, terminal forecasts, and the full body of watch and warning text. If the NWS transmitted it over NOAAPORT, there is a high probability the IEM has it.
The AFOS/AWIPS Identifier System
Every text product in the archive has an AFOS/AWIPS identifier — a 3 to 6 character code that uniquely identifies the product type and issuing center. The pattern is TTSSSS where the first two or three characters identify the product type and the remaining characters identify the WFO or center. Examples: AFDCTP is the Area Forecast Discussion from State College (CTP). TORDMX is a Tornado Warning from Des Moines (DMX). CFWCTP is a Coastal Flood Watch from CTP. RWRKCI is the Regional Weather Roundup from Kansas City.
The IEM assigns its own longer internal identifier to each product in the format YYYYmmddHHMM-CCCC-TTAAII-AFOSID, where the timestamp is UTC, CCCC is the issuing center, TTAAII is the WMO header, and AFOSID is the AFOS identifier. You can paste this full identifier directly into the IEM search box and land immediately on that product — useful when someone shares a specific product ID and you want to pull it up quickly.
The AFOS Product Finder
The primary interface for text retrieval is the AFOS Product Finder at mesonet.agron.iastate.edu/wx/afos/. You enter an AFOS identifier and optionally a date range, and it returns all matching products in reverse chronological order, each one displaying the full raw text. For AFD research — reading what CTP forecasters were thinking during a specific event — this is the tool. Enter AFDCTP, set a date range around the event, and read every AFD issued during the period.
The bulk retrieval API at /cgi-bin/afos/retrieve.py accepts date-range queries by AWIPS ID and returns the raw text, making it straightforward to collect a full season’s AFDs for text analysis without clicking through hundreds of individual products.
The List Products by WFO page at /wx/afos/list.phtml shows all products issued by a given WFO on a given date, organized by product type. If you know the date but not which specific products you want, this is the browsable starting point.
Area Forecast Discussions
AFDs deserve special mention because they are arguably the most valuable product in the text archive for weather enthusiasts trying to understand not just what happened but why. The AFD is where the forecaster exposes their reasoning — the synoptic pattern they are tracking, the model guidance they trust and distrust, the mesoscale features they are watching, the uncertainty in the forecast, and the specific thresholds that would trigger a warning or advisory upgrade. Reading AFDs for an event you lived through is the closest thing to sitting in the forecast office with the meteorologist.
For the Pennsylvania forecast region, CTP’s AFDs at AFDCTP are the primary product. Events that spanned multiple WFO boundaries — a major nor’easter, a line of severe thunderstorms moving east from the Ohio Valley — are illuminated by reading adjacent office AFDs alongside CTP’s: AFDPHI (Mount Holly, NJ), AFDPBZ (Pittsburgh), AFDLWX (Baltimore/Washington), AFDBGM (Binghamton). The AFD record for the most operationally interesting storms in the mid-Atlantic region is one of the richer archives of applied mesoscale reasoning that exists in any publicly accessible form.
CLI and CF6: Daily Climate Products
Two text product types are particularly useful for historical climate research. The CLI (Climate Report) is issued daily by each WFO for its primary ASOS stations and summarizes the previous day’s temperature, precipitation, and snowfall against the normal and record values. The IEM parses these and provides interactive tables and maps: the CLI interactive map is at /nws/climap.php and the text table at /nws/clitable.php. For any ASOS station that a WFO designates as a climate site, the CLI provides the official daily climate summary including the departure from normal and the record comparison.
The CF6 (Monthly/Daily Climate Data) is the monthly version, summarizing the calendar month’s climate statistics at each climate site. The IEM parses CF6 products and makes them available in tabular form at /nws/cf6table.php. For Harrisburg (KMDT), the CF6 archive going back through the IEM’s text product archive gives you the official monthly climate summary — maximum and minimum temperature, heating and cooling degree days, precipitation total and departure, snowfall total — in a consistent format across years.
SPC Products
The NWS Data section gives substantial coverage to Storm Prediction Center products, and for weather enthusiasts focused on severe weather climatology, these are essential.
Convective outlooks are archived in shapefile format at /request/gis/spc_outlooks.phtml. The outlook search by point at /nws/spc_outlook_search/ answers the question “when was my location last under a Moderate or High risk?” — which is a surprisingly hard question to answer from any other free source. Set your location, select the outlook category, and the IEM returns every instance going back through the archived record.
Mesoscale Convective Discussions (MCDs) are available as shapefiles at /request/gis/spc_mcd.phtml. MCDs are the products SPC issues when conditions are evolving and they want to flag forecasters and the public ahead of a potential watch. Reading the MCD text alongside the subsequent watch issuance (or non-issuance, when the situation does not materialize) gives you the SPC’s real-time situational awareness for a given event.
SPC Watches are archived at /request/gis/spc_watch.phtml and displayed interactively at /GIS/apps/rview/watch.phtml. The watch archive includes the polygon geometry, the issue and expiration times, and the watch type (Tornado Watch, Severe Thunderstorm Watch, PDS Watch). A listing of all SPC watches by year with their ETNs is at /nws/watches.php, and PDS watches specifically are listed at /nws/pds_watches.php.
The WPC (Weather Prediction Center) has analogous products for the precipitation side of operations. WPC Mesoscale Precipitation Discussions (MPDs) are at /request/gis/wpc_mpd.phtml, and the WPC outlook search by point at /nws/wpc_outlook_search/ answers the equivalent question for excessive rainfall outlooks.
Verification Autoplot Charts
Several Autoplot charts work directly with the VTEC archive for warning climatology analysis:
q=44 — Accumulated WFO Watch/Warning/Advisory totals. Plots the cumulative count of a specific warning type by WFO over a season or date range. Useful for comparing how active a particular warning type has been relative to prior years.
q=52 — Warning Gantt chart. Shows the timeline of all warnings of a given type from a WFO across a season, one row per event, colored by phenomena. The Gantt format makes patterns in warning clustering and seasonal distribution immediately visible.
q=92 — Days since last VTEC product. A map showing, for each WFO, how many days have elapsed since a specific warning type was last issued. Useful during quiet periods to contextualize how long the current stretch of inactivity is relative to the climatological distribution.
q=109 — Number of VTEC events by WFO. A choropleth map of warning counts by WFO for any selected type and time period — the fastest way to visualize the geographic distribution of warning activity across the country.
q=211 — Warning lead time distribution. A histogram of lead times (minutes between issuance and first confirming LSR) for tornado or severe thunderstorm warnings, by WFO and year. This is the visualization most directly connected to the Cow verification statistics.
River and Hydrology Products
The NWS Mainpage has a hydrology section that is often overlooked by severe weather-focused users but is valuable during flood events.
The River Forecast Point Monitor at mesonet.agron.iastate.edu/river/ summarizes Flood Stage Forecasts (FLS statements) by river and by WFO or state. It provides a tabular view of all river forecast points, their current stage versus action/flood/major/record stage, and the trend. For a flooding event, this is the IEM equivalent of the NWS’s Advanced Hydrologic Prediction Service (AHPS) viewer — organized differently but drawing from the same FLS product archive.
HML (Hydrometric Message Language) data is available as archived processed products at /request/hml.php, giving you the numeric river forecast data behind the FLS text products. Autoplot q=160 renders these as interactive plots of forecasted versus observed stage at any river forecast point — the same view the hydrologist at the WFO is looking at when they issue a flood statement.
What to Watch Out For
Pre-2005 warnings lack VTEC. The NWS began operational VTEC in 2005. Products before that date are in the text archive but have no structured VTEC metadata, meaning the Browser and Cow tools do not work with them. For historical warning research before 2005, you are working with raw text files and NCEI’s Storm Events Database, not IEM’s structured tools.
Pre-2007 polygon geometry. Storm-Based Warning polygons became operational in October 2007. Before that date, even post-VTEC warnings are county-based, and the polygon geometry in the VTEC Browser will show the county boundary rather than a storm-tracking polygon. Cow treats this correctly — it runs in county mode for pre-October 2007 dates automatically — but be aware of the shift when working across that boundary.
ETN resets and year-boundary searches. As noted above, ETNs reset on January 1. A search that spans December into January will return warning events with ETNs that restart at 1 in the new year. This is expected behavior, not a data error, but it can confuse automated analysis if you are not handling it explicitly.
LSR incompleteness as a verification floor. Because Cow and the VTEC Browser both use LSRs as the ground truth for verification, every caveat about LSR completeness applies to all derived statistics. An unusually high FAR for a specific WFO or year may reflect poor spotter coverage as much as poor warning accuracy. Context always matters.
The text archive has product type gaps. Not every product type has been archived continuously since 2005. Some product categories have gaps, particularly for the period 2005–2008 during the IEM’s early text archiving work. If you cannot find a specific product that you know was issued, check the IEM news archive for notes about that product type’s ingestion history.
Workflow 3 — Researching a Past Warning Event End to End
The question: On a specific date, a Tornado Warning was issued for Dauphin County, Pennsylvania. What was the lead time? What did the polygon look like? Were there any storm reports? What did the warning text say?
Start here: https://mesonet.agron.iastate.edu/vtec/search.php
The VTEC search page lets you find NWS warnings by county or by geographic point, filtered by phenomena type and date range. To find a Tornado Warning for Dauphin County, PA: select Pennsylvania from the state menu, select Dauphin County from the county menu, set the phenomena to Tornado Warning (TO.W), and set your date range. Submit.
The results table shows every Tornado Warning that touched Dauphin County within your date range — each row shows the issuing WFO (PHI or CTP for central Pennsylvania), the event date, the VTEC Event Tracking Number (ETN), the issuance time, the expiration time, and whether it was a storm-based warning with a polygon. Click the event link to go to the individual event page.
The event page is where the full picture assembles. At the top you get the warning metadata: issue time, expire time, phenomena and significance codes, WFO, ETN. Below that is the storm-based warning polygon rendered on a map, showing exactly what area was under the warning. Below the map is the raw NWS text product — the warning as it was originally transmitted, in full, with the original VTEC line intact.
From the event page, two additional tools are one click away. The IEM Cow link (at https://mesonet.agron.iastate.edu/cow/) provides verification statistics for that warning — whether a storm report fell within the polygon, what the lead time was to any confirmed tornado, and how the warning’s performance compares to the WFO’s averages. The Local Storm Reports link takes you to all LSRs within a user-specified buffer radius of the warning polygon around the time of the event, giving you the observed tornado touchdowns, hail reports, or wind damage reports that the warning was issued for.
One important constraint to know before you start: the IEM VTEC archive has no known gaps since November 12, 2005. Before that date, coverage depends on what was available for retroactive assignment. Tornado and Severe Thunderstorm Warnings before 2005 are partially present — IEM retroactively assigned VTEC identifiers using available data — but the completeness of pre-2005 warning events is variable and should not be assumed complete for any specific event.