Butler Use Case

Asking Butler to do it for me

Everything else has been Butler answering. Here it acts: changing a configuration, producing a document, putting a file in front of someone, all under the confirmation flow that governs the lot.

The Situation

Two very different things live under this heading, and they carry very different risk: changing a session border controller, and producing a report to email someone.

What they have in common is the tedium they remove. Find the call, export the capture, locate the file, attach it, write the subject, send it. Or: open the box, find the blacklist, edit it, save it, remember to activate. Both are one sentence in the thread where the problem was already being discussed.

Anyone senior will want to know what stops it doing something stupid long before they care how fast it is. That is what the conversation below is really about.

The Answers

Pick a question, read the whole exchange

Both ran against a synthetic demo fleet. Watch the order of operations in the first one rather than the speed.

#voice-opsChat
EN

Engineer 09:07
@VI – Butler Our carrier changed the IP behind their SIP hostname and updated DNS, but SBC-SUT-01 is still sending calls to the old address. Please fix it.
B

VI – Butler APP 09:07
get_host_listlookup_knowledge  query=“SBC DNS cache refresh hostname resolution”list_available_actions  query=“clear_dns_cache”
I understand the issue, Sir. When a carrier updates their SIP hostname’s DNS record, the SBC needs to refresh its cached resolution. I have found SBC-SUT-01. Let me look up the exact action name and the parameters it needs.
B

VI – Butler APP 09:07
Confirmation requiredThis will flush the DNS cache on SBC-SUT-01, clearing all DNS group cached lookups (A, SRV, NAPTR, LOCSRV, MCAST) and the SIP stack’s DNS caches. Static DNS local entries are preserved. In-flight DNS queries may briefly fail and new queries will be refused until the cache is rebuilt. Established calls are unaffected. No configuration activation is required after this action.
Shall I proceed with flushing the DNS cache on SBC-SUT-01?
EN

Engineer 09:08
@VI – Butler yes, go ahead
B

VI – Butler APP 09:08
device_action  clear_dns_cache, params={“confirm”: true}
The DNS cache flush has been accepted on SBC-SUT-01, job ID mcp_1790327318_10860. New DNS lookups will resolve the carrier’s hostname to the updated address.

The wording in the amber box is not Butler’s. It called the action plainly, the device refused it as destructive and returned its own description of what a flush does, and Butler relayed that verbatim and waited. That is the difference between an assistant that promises to be careful and one that cannot proceed until something else agrees. Notice too that it confirmed the exact action name with the catalogue rather than typing one from memory.

#voice-opsChat
EN

Engineer 03:36
@VI – Butler Hi Butler Add 15551234999 to the blacklist on SBC-SUT-01
B

VI – Butler APP 03:36
lookup_knowledge  query=“blacklist number add block”list_available_actions  category=writeget_host_list
Good afternoon, Sir. I shall add 15551234999 to the blacklist on SBC-SUT-01. First, let me look up the correct action for blacklist management.
I can see the blacklist is managed via custom files. I need to find the host, fetch the current file, then add the number and write it back.
B

VI – Butler APP 03:37
The blacklist file exists and currently contains:
0000000000,b,,
This is a CSV with columns for the calling number and its parameter, then the called number and its parameter. A b means blacklist. I’ll append a new line: 15551234999,b,,
The blacklist file has been updated successfully. To complete the process, you must now activate the configuration on SBC-SUT-01 for the change to take effect. Shall I do that now, Sir?
EN

Engineer 03:37
@VI – Butler Yes please
B

VI – Butler APP 03:37
Sir, the action requires confirmation. Here is the description:
Confirmation requiredThis will ACTIVATE the pending configuration on SBC-SUT-01. Routine changes (NAPs, routes, registrars, profiles, proxy ports, header and firewall rules) apply with no call impact, because apps hot-reload in a few seconds and active calls are not dropped. Only major infrastructure changes (IP addresses, point codes, interface teardown) can cause a brief interruption.
Shall I proceed with activation?
EN

Engineer 03:37
@VI – Butler YES!
B

VI – Butler APP 03:37
It is done, Sir. 15551234999 has been added to the blacklist on SBC-SUT-01 and the configuration has been activated. Calls from this number will now be blocked by the routing script filter.

Count the safeguards. Butler looked up how blacklisting works on this platform before touching anything, fetched the current file and showed you its contents, then appended one row and changed nothing else. It did not activate on its own; it asked. When you said yes it still would not proceed, and it spelled out what activation would and would not disturb before asking again. Four separate points where a person stays in the loop, on a change that took under a minute.

#voice-opsChat
B

VI – Butler APP 09:06
I am unable to retrieve the PCAP at this moment. What I can send instead:
  • A detailed call report in HTML, showing the full SIP ladder and the failure analysis
  • The CDR records in JSON
Shall I generate the call report and email that instead, Sir?
EN

Engineer 09:08
@VI – Butler Yes generate the call report with all fields checked please and send it to me
B

VI – Butler APP 09:09
vitrace_get_report  session_idemail_send  to, subject, attachment
Sir, I have generated the call report. To send it to you, may I have your email address?
B

VI – Butler APP 09:17
The call report has been emailed, with the subject line “Call Report, Session #3797941”. The report includes the full SIP ladder across all 13 hops, and the CDR details for each leg.

The first message is the one to read. Asked for a packet capture it could not produce, Butler did not stall and did not pretend: it named two things it could send instead and asked which you wanted. Then, before sending anything, it stopped to ask where to send it, because an address is not something to assume. Thirteen hops of SIP ladder and the CDR for every leg, attached and out, from one sentence.

#voice-opsChat
EN

Engineer 08:56
@VI – Butler We are getting hammered by a SIP scanner from 203.0.113.9. Can you block that IP at the SBC? IMPORTANT: do not execute any write action, just tell me exactly which action you would use and with what parameters.
B

VI – Butler APP 08:56
lookup_knowledge  query=“block IP address firewall ACL”
Sir, to block a SIP scanner IP globally on the SBC, I would use:
Actionblacklist_ip Parameters{ “ip”: “203.0.113.9” }
That creates a single DROP filter covering all protocols from that source address on any destination port, which is both simpler and wider than blocking each protocol separately.
The rule will be staged but not active until activate_config is run afterward.
If a more granular approach were needed, for example blocking only UDP SIP on specific ports, the alternative would be create_firewall_rule with an entry type of DROP, filters specifying protocol and source IP and optionally destination ports, and a priority, where lower is evaluated first.

Customers ask for this shape constantly: tell me what you would do, do not touch my box. It is also the right way to meet Butler if write access makes you uneasy. Asked to advise rather than act, it named the action, gave the exact parameter, volunteered that nothing takes effect until the configuration is activated, and offered the more granular alternative for a narrower block. You can run every one of these by hand and never grant write access at all.

#voice-opsChat
EN

Engineer 10:44
@VI – Butler I just got my fraud report. Can you help me add some IPs to the ACL?
B

VI – Butler APP 10:44
get_host_listlist_available_actions  category=write, query=“firewall”
Good morning, Sir. I see the available SBCs:
SBC-SUT-00 192.168.101.63SBC-SUT-01 192.168.101.96SBC-SUT-02 192.168.101.88APAC SBC the honeypot
To add IPs to the ACL I will need three things: which SBC, the addresses from your report, and the direction, so whether these are blocked from sending calls in or receiving calls out.
EN

Engineer 10:46
@VI – Butler Block all these IPs on the honeypot: 203.0.113.11,203.0.113.12,203.0.113.13,203.0.113.14,203.0.113.15,203.0.113.16,203.0.113.17,203.0.113.18,203.0.113.19
B

VI – Butler APP 10:47
lookup_knowledge  query=“how to block IPs in ACL blacklist”list_available_actions  category=write, query=“blacklist”
I found the blacklist_ip action. It is marked destructive and requires_confirmation, so I will first show you what it will do for each address, then await your confirmation before proceeding.
TO BE BLACKLISTED ON APAC SBC, DROP, ALL PROTOCOLS203.0.113.11203.0.113.12203.0.113.13203.0.113.14203.0.113.15203.0.113.16203.0.113.17203.0.113.18203.0.113.19
EN

Engineer 10:48
@VI – Butler confirmed
B

VI – Butler APP 10:48
Done, Sir. All nine addresses are staged as firewall DROP rules blocking all traffic from each source. The rules are staged in the configuration and will not take effect until activate_config is run.
EN

Engineer 10:49
@VI – Butler can you undo that, and instead of making 9 rules just make one rule with 9 filters, and then activate, no need to ask for confirmation.
B

VI – Butler APP 10:51
The nine rules are removed and replaced with a single consolidated rule, now activated:
HONEYPOT_BLACKLISTentry type DROPpriority 1automatic falsefilters F1 to F9, each protocol ALL with a /32

Every other exchange on this site ends with an answer. This one ends with a change in the world, and the monitoring proves it: the honeypot had been taking two to six call legs a minute for hours, and at 10:51, when the blacklist went active, it went to zero and stayed there. Of the 117 call records in the preceding 45 minutes, 113 came from addresses on that list. A fraud report on a Monday morning became an enforced firewall change, by somebody typing in a chat window, in about ten minutes. Read the middle of the thread for the part that makes it safe: four boxes on the fleet and it refused to guess which one, then it listed all nine addresses back and stopped dead until a human typed “confirmed”. When it was later told not to ask again, it honoured that for the follow-up and did not carry the permission anywhere else.

Ask It This Way

Changes to the SBC

Every one of these reads the current state first, proposes, and waits.

Add 1 555 123 4999 to the blacklist on sbc-01
When you’d ask

A nuisance or fraud source has been identified and you want it stopped before you write the ticket about it.

What comes back

The current file, the proposed single-row change, then a request to activate as a separate step.

Then ask

Show me the file againActivate itUndo that
Add 203.0.113.44 to the ACL on NAP UPSTREAM_SOFTSWITCH
When you’d ask

A partner has added a new signalling host and calls are being rejected until you let it in.

What comes back

The same pattern: current ACL, proposed addition, confirm, activate as its own step.

Then ask

What else is on this ACL?Did their calls start working?
And Then

Documents and delivery

Lower risk, and the part people reach for every day.

Can you email the PCAP for that call to [email protected] and put in the subject “Attention David, per our phone call”?
When you’d ask

You are on the phone to support and they want the capture out of Voice Intelligence Trace. The alternative is six manual steps in three windows.

What comes back

Confirmation of what was sent, to whom, with what subject. Butler holds no mail credential of its own; it hands the message to a gateway that owns the account and records what went out.

Then ask

Copy me on thatAdd the SIP ladder as text in the body
Can you generate a PDF of the call and upload it here?
When you’d ask

The investigation is done and somebody outside the thread needs the evidence.

What comes back

The report as a file in the conversation on Slack and Telegram. On Teams, Butler emails it instead and says so rather than failing quietly.

Then ask

All fields checked, pleaseSend that to the customer instead
More

Yes, generate the call report with all fields checked please and send it to me
Write up what we just found as a one-page incident summary I can send the customer, and email it to me
Here’s a PCAP from our other vendor. Read it and tell me where the call broke.
Working With It

How the guardrails work

Every write is confirmed before it runs, and activating it is a second confirmation after that. One change at a time, each reversible in one step, each shown to you in full beforehand, with the effect of the change described before you are asked to approve it.
Email recipients are restricted by domain, and the restriction does not live inside Butler. A gateway owns the mail account, enforces which domains a given Butler may write to, and records an audit line for every message, so “email it to the customer” can be permitted while “email it anywhere” stays closed.
Butler never sends on its own initiative, though it will offer. It has ended a diagnosis by suggesting a report as the obvious next step, and that offer still waits for your yes.
Where the file lands depends on the chat app, since Slack and Telegram can take a file in the conversation and Teams cannot. Butler emails the artefact instead and tells you that is what it is doing.
Butler Use Cases

One number and maybe a time. Butler finds the call and says whose side ended it.

Counts, groupings, thresholds and KPIs across a population of calls.

Routing tables, regex and SDP profiles in plain English.

Ask in French, Spanish or Portuguese, get the answer from the English documentation.

Do it for me

Changes, reports, files and email, each one waiting for your yes.

Paste the complaint in the customer’s own words and let Butler find the call.

All Butler use cases

See the confirmation flow on your own box

Deployed in 48 hours, month to month, in the chat app your team already has open.

By submitting this form, your information will be processed in accordance with our Privacy Policy.