Build an evidence-first UC investigation

A useful investigation connects a specific symptom to evidence you can compare. Start with one affected call and resist widening the scope until the result gives you a reason.

Describe the symptom precisely

Record who called whom, when the call occurred, the path it should have taken, and the behavior that differed from expectations. Note the timezone. Distinguish signaling failure, unexpected treatment, and media failure before choosing a capture.

Choose a meaningful comparison

A successful call can help isolate differences, but only if the comparison is relevant. Check the same device family, route, direction, and transport where practical. Note every condition that differs rather than attributing the result to the first visible change.

Correlate the available evidence

  1. Identify the relevant call legs and timestamps.
  2. Follow signaling through the systems you can observe.
  3. Compare the offered and negotiated media details with the actual symptom.
  4. Include the routing and transformation context needed to explain the path.

A server accepting a request does not by itself prove audio delivery. A missing capture does not prove that no packet was sent. State where visibility ends.

Test one explanation

Write a prediction: if the suspected cause is correct, what observable behavior should change? Agree the change and rollback procedure, then repeat the scoped test. Keep the before and after evidence together.

Close the collection workflow

Confirm that temporary debug, trace, and recording settings were removed or restored as intended. Protect captured data according to the organization’s retention and access rules. Preserve a concise finding that another engineer can reproduce.

The goal is a supported explanation and a controlled next action.