Butler Use Case

Seeing what’s happening across my network

A population of calls rather than a single one, counted and grouped and compared, asked in the words you already used when you thought of the question.

The Situation

These questions normally get answered by whoever knows the reporting tool well enough to build the query, which in practice means one or two people per company. Everyone else waits for them, or does without.

The gap is rarely the data. It is knowing which field the failure lives in, remembering that the detailed cause is not the same thing as the SIP code, and being fluent enough in the filter syntax to express “grouped by host” before you have lost interest. Butler takes the sentence and does that part.

The Answers

Pick a question, read the whole exchange

Both of these are unedited machine transcripts, including the parts where the honest answer is a small number.

#voice-opsChat
EN

Engineer 15:32
@VI - Butler Can you give me a summary of calls that terminated with cause 216 for the last 48 hours
B

VI - Butler APP 15:32
vitrace_find_sessions  cause=216, last 48hvitrace_search_cdrs  same window
I found only 1 call with cause code 216 (RES_ALLOC_FAILED, Resource Allocation Failed) in the last 48 hours.
FIELD VALUETime 15:30:50 UTCFrom 5XX 0800To 8XX 1807NAP NAP_ACCESS_11Direction InboundDuration 0 ms (not connected)PDD 106 msTermination cause NoAnswer (SIP 480)Original cause RES_ALLOC_FAILED(216)Legs 3
Notes

  • Cause 216 indicates the SBC could not allocate the resources needed to handle the call, such as media channels, transcoding resources or call slots.
  • The call was terminated with SIP 480 and mapped to NoAnswer.
  • One call in 48 hours is very low volume, so this reads as an isolated resource constraint rather than a widespread issue.
Would you like me to investigate why resources may have been unavailable at that time, or look at the SIP ladder for this specific call?

The useful part of this answer is the number one. A cause code you have never seen before feels like the start of an outage, and the first thing worth knowing is whether it is a pattern or a single event. Butler also did the translation nobody asked for: 216 is the detailed cause, the call signalled as a SIP 480, and those are two different fields that a search can disagree about.

#voice-opsChat
EN

Engineer 09:48
@VI - Butler Was yesterday worse than the same day last week? Compare completion rate.
B

VI - Butler APP 09:49
LAST WEEK YESTERDAYTotal call legs 8,640 8,628Answered call legs 7,200 7,190Completion rate 83.33% 83.33%
No, yesterday was not worse. The completion rates are virtually identical at 83.33%. Volume was down 12 legs, answered calls were down 10, so the dip was matched proportionally and the rate itself did not move. Nothing meaningful shifted between the two days.

An illustration rather than a case study: this one was run against synthetic data to show the shape of the answer, because no customer has asked it yet. What it demonstrates is a comparison holding its nerve. Volume fell and answered calls fell with it, and the answer is that nothing changed, which is a harder thing for a report to say than finding a problem.

#voice-opsChat
EN

Engineer 10:19
@VI - Butler I can’t reach the web UI on SBC-SUT-02. Is the box still alive and reporting to you, or is it down?
B

VI - Butler APP 10:19
get_host_listget_item_last_sample  item_key=“tmedia.status”
Found SBC-SUT-02. Let me check its liveness.
Good news, Sir. SBC-SUT-02 is alive and reporting normally. Last sample received 10:18:38 UTC, about a minute ago, state normal.
The box is healthy on our end. If the web UI is unreachable, the issue is likely network connectivity between you and the SBC. Shall I check any other aspect of its status, such as NAP availability or recent events?

One call, one number, the right conclusion. “I cannot reach it” and “it is down” feel identical at the moment you notice and lead to completely different afternoons, and the box reporting a minute ago settles which one you are in. Notice what it does not do: having answered, it stops, rather than filling the space with a list of things that might be wrong with your network.

Ask It This Way

The prompts, and where each one leads

A failure mode, a time window and a grouping, in one English sentence.

Give me a summary of calls that terminated with cause 216 for the last 48 hours
When you’d ask

You have seen one instance of a cause code and want to know whether it is a pattern or a one-off.

What comes back

The count over the window, with the calls behind it available to open one by one.

Then ask

Group that by SBC hostWhich NAPs did they come in on?Retry for the last 7 days
How many calls did we have yesterday, and what was the ASR?
When you’d ask

The shape a manager asks in rather than an engineer. One line, two standard metrics, no dashboard to open.

What comes back

Volume and answer-seizure ratio for the period, in the thread.

Then ask

Break that down per carrierHow does it compare to last Tuesday?
Can you show me the amount of peak current calls per NAP for today?
When you’d ask

Capacity planning, or a complaint that calls are being rejected at busy hour.

What comes back

Peak concurrency per NAP for the period, so you can see which trunk is near its ceiling.

Then ask

What time did that peak happen?Were any calls rejected at that moment?
Between 08:00 and 08:20 UTC today a lot of calls appeared with error 403 on NAP_A_TCP and NAP_A_UDP. Can you check what’s going on?
When you’d ask

Something else spotted the spike. You already know what. You want why.

What comes back

The cluster examined as a group: what the calls had in common, which side returned the 403, and whether it is still happening.

Then ask

Has it stopped?Show me one of them in full
We’ve had complaints about these numbers. Fetch all calls to them that go over the 15 minute mark and list them.
When you’d ask

A threshold search rather than a failure search. Not every investigation is about something broken.

What comes back

Every matching call over the duration you named, listed with the detail you would need to open any of them.

Then ask

Which NAP carried the longest one?Put that in a report I can send on
List the total number of calls made to 5XX 2244 per day
When you’d ask

Somebody wants to know whether traffic to a destination is growing, falling or steady.

What comes back

A per-day breakdown. Say “retry for the last 7 days” and it re-runs the same question on the wider window.

Then ask

Retry for the last 7 daysInclude the alternate format of that number
More, once you are comfortable

Find the termination cause for a call made today with calling 6XX 3904 and called 5XX 5200
How many calls yesterday were delivered with attestation level C or no attestation at all, and which trunks did they come in on?
Was yesterday worse than the same day last week? Compare completion rate by carrier.
The recorder has stopped showing calls in call trace. Can you check the service?
Working With It

How to ask so the numbers come back right

Ask for the figure you want, whenever you want it. Nothing here is a scheduled report. Watching for the anomaly is the job of Voice Intelligence Nodes, which raises threshold alerts programmatically on rules you set, and Butler is where you take the alert once you have it.
A cause code is not always the cause, since some failure modes travel as a detailed vendor attribute on a call the signalling considers successful. Butler searches both fields, and this is the single most useful thing on the page to understand, because it explains why a count built on SIP codes alone can come back as zero while your customers are still complaining.
Keep the window inside your retention period. Ask for a longer stretch than your Voice Intelligence Trace instance still holds and Butler will tell you where the data runs out, rather than quietly handing back a smaller number that looks complete.
Butler Use Cases

One number and maybe a time. Butler finds the call and says whose side ended it.

What’s happening across my network?

Counts, groupings, thresholds and KPIs across a population of calls.

Routing tables, regex and SDP profiles in plain English.

Ask in French, Spanish or Portuguese, get the answer from the English documentation.

Changes, reports, files and email, each one waiting for your yes.

Paste the complaint in the customer’s own words and let Butler find the call.

All Butler use cases

Ask Butler what your network did yesterday

Deployed in 48 hours, month to month, in the chat app your team already has open.

By submitting this form, your information will be processed in accordance with our Privacy Policy.