21 of 168 calls have more than one leg. 0 records carry no correlation identifier and are not merged into anything.
20 of 168 calls are drawn, most legs first. Call-path rows are in the workbook and call-path CSV. The full source record list remains in the Records sheet and record CSV.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-01T14:18:00.000Z
DN-1
DN-2
—
QUEUE-1
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-01T14:18:01.000Z
DN-1
DN-2
—
QUEUE-1
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-01T14:18:30.000Z
DN-2
DN-3
—
QUEUE-1
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-01T14:18:31.000Z
DN-2
DN-3
DN-2
QUEUE-1
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-01T17:00:00.000Z
DN-4
DN-2
—
QUEUE-2
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-01T17:00:01.000Z
DN-4
DN-2
—
QUEUE-2
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-01T17:00:30.000Z
DN-2
DN-3
—
QUEUE-2
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-01T17:00:31.000Z
DN-2
DN-3
DN-2
QUEUE-2
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-01T19:36:00.000Z
DN-5
DN-2
—
QUEUE-3
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-01T19:36:01.000Z
DN-5
DN-2
—
QUEUE-3
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-01T19:36:30.000Z
DN-2
DN-3
—
QUEUE-3
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-01T19:36:31.000Z
DN-2
DN-3
DN-2
QUEUE-3
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-02T14:18:00.000Z
DN-1
DN-2
—
QUEUE-1
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-02T14:18:01.000Z
DN-1
DN-2
—
QUEUE-1
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-02T14:18:30.000Z
DN-2
DN-3
—
QUEUE-1
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-02T14:18:31.000Z
DN-2
DN-3
DN-2
QUEUE-1
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-02T17:00:00.000Z
DN-4
DN-2
—
QUEUE-2
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-02T17:00:01.000Z
DN-4
DN-2
—
QUEUE-2
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-02T17:00:30.000Z
DN-2
DN-3
—
QUEUE-2
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-02T17:00:31.000Z
DN-2
DN-3
DN-2
QUEUE-2
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-02T19:36:00.000Z
DN-5
DN-2
—
QUEUE-3
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-02T19:36:01.000Z
DN-5
DN-2
—
QUEUE-3
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-02T19:36:30.000Z
DN-2
DN-3
—
QUEUE-3
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-02T19:36:31.000Z
DN-2
DN-3
DN-2
QUEUE-3
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-03T14:18:00.000Z
DN-1
DN-2
—
QUEUE-1
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-03T14:18:01.000Z
DN-1
DN-2
—
QUEUE-1
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-03T14:18:30.000Z
DN-2
DN-3
—
QUEUE-1
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-03T14:18:31.000Z
DN-2
DN-3
DN-2
QUEUE-1
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-03T17:00:00.000Z
DN-4
DN-2
—
QUEUE-2
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-03T17:00:01.000Z
DN-4
DN-2
—
QUEUE-2
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-03T17:00:30.000Z
DN-2
DN-3
—
QUEUE-2
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-03T17:00:31.000Z
DN-2
DN-3
DN-2
QUEUE-2
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-03T19:36:00.000Z
DN-5
DN-2
—
QUEUE-3
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-03T19:36:01.000Z
DN-5
DN-2
—
QUEUE-3
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-03T19:36:30.000Z
DN-2
DN-3
—
QUEUE-3
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-03T19:36:31.000Z
DN-2
DN-3
DN-2
QUEUE-3
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-04T14:18:00.000Z
DN-1
DN-2
—
QUEUE-1
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-04T14:18:01.000Z
DN-1
DN-2
—
QUEUE-1
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-04T14:18:30.000Z
DN-2
DN-3
—
QUEUE-1
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-04T14:18:31.000Z
DN-2
DN-3
DN-2
QUEUE-1
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-04T17:00:00.000Z
DN-4
DN-2
—
QUEUE-2
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-04T17:00:01.000Z
DN-4
DN-2
—
QUEUE-2
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-04T17:00:30.000Z
DN-2
DN-3
—
QUEUE-2
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-04T17:00:31.000Z
DN-2
DN-3
DN-2
QUEUE-2
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-04T19:36:00.000Z
DN-5
DN-2
—
QUEUE-3
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-04T19:36:01.000Z
DN-5
DN-2
—
QUEUE-3
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-04T19:36:30.000Z
DN-2
DN-3
—
QUEUE-3
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-04T19:36:31.000Z
DN-2
DN-3
DN-2
QUEUE-3
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-05T14:18:00.000Z
DN-1
DN-2
—
QUEUE-1
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-05T14:18:01.000Z
DN-1
DN-2
—
QUEUE-1
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-05T14:18:30.000Z
DN-2
DN-3
—
QUEUE-1
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-05T14:18:31.000Z
DN-2
DN-3
DN-2
QUEUE-1
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-05T17:00:00.000Z
DN-4
DN-2
—
QUEUE-2
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-05T17:00:01.000Z
DN-4
DN-2
—
QUEUE-2
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-05T17:00:30.000Z
DN-2
DN-3
—
QUEUE-2
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-05T17:00:31.000Z
DN-2
DN-3
DN-2
QUEUE-2
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-05T19:36:00.000Z
DN-5
DN-2
—
QUEUE-3
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-05T19:36:01.000Z
DN-5
DN-2
—
QUEUE-3
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-05T19:36:30.000Z
DN-2
DN-3
—
QUEUE-3
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-05T19:36:31.000Z
DN-2
DN-3
DN-2
QUEUE-3
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-06T14:18:00.000Z
DN-1
DN-2
—
QUEUE-1
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-06T14:18:01.000Z
DN-1
DN-2
—
QUEUE-1
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-06T14:18:30.000Z
DN-2
DN-3
—
QUEUE-1
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-06T14:18:31.000Z
DN-2
DN-3
DN-2
QUEUE-1
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-06T17:00:00.000Z
DN-4
DN-2
—
QUEUE-2
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-06T17:00:01.000Z
DN-4
DN-2
—
QUEUE-2
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-06T17:00:30.000Z
DN-2
DN-3
—
QUEUE-2
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-06T17:00:31.000Z
DN-2
DN-3
DN-2
QUEUE-2
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-06T19:36:00.000Z
DN-5
DN-2
—
QUEUE-3
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-06T19:36:01.000Z
DN-5
DN-2
—
QUEUE-3
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-06T19:36:30.000Z
DN-2
DN-3
—
QUEUE-3
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-06T19:36:31.000Z
DN-2
DN-3
DN-2
QUEUE-3
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-07T14:18:00.000Z
DN-1
DN-2
—
QUEUE-1
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-07T14:18:01.000Z
DN-1
DN-2
—
QUEUE-1
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-07T14:18:30.000Z
DN-2
DN-3
—
QUEUE-1
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-07T14:18:31.000Z
DN-2
DN-3
DN-2
QUEUE-1
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
Call path
Aliased by field: calling, called and redirecting numbers, queues, agents, devices and gateways. An alias is built from the kind of field a value came from and the value itself: one value your file carries in two kinds of field reads as two aliases, and a value that repeats within one kind keeps its alias, so the call still reads.
Leg inventory
Leg
Started
From
To
Redirected by
Attributed group
Attributed handler
From device
To device
Gateway
Site
Outcome
Cause
Declared
Read from
L01
2026-08-07T17:00:00.000Z
DN-4
DN-2
—
QUEUE-2
Unassigned
—
—
GATEWAY-1
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L02
2026-08-07T17:00:01.000Z
DN-4
DN-2
—
QUEUE-2
AGENT-1
—
DEVICE-1
—
—
Answered
—
Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L03
2026-08-07T17:00:30.000Z
DN-2
DN-3
—
QUEUE-2
AGENT-1
DEVICE-1
—
—
—
Not connected
—
Related reason (deflection); Call outcome (success); Remote call ID (link); Transfer related call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
L04
2026-08-07T17:00:31.000Z
DN-2
DN-3
DN-2
QUEUE-2
AGENT-2
—
DEVICE-2
—
—
Answered
—
Related reason (deflection); Redirect reason (redirect); Original reason (redirect); Call outcome (success); Remote call ID (link)
Report ID, Correlation ID, Local call ID, Remote call ID, Transfer related call ID, Related call ID, Network call ID
Transitions
From
To
Basis
Declared feature
Elapsed
L01
L02
declared
—
1.0 s
L02
L03
declared
—
29.0 s
L03
L04
declared
—
1.0 s
No contradiction was found between the legs of this call.
Findings
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L03)
calling success not answered The record’s Call outcome is Success although the leg was not answered. Webex Calling defines Success to include busy and no-answer, so the outcome field does not say the call was answered. (L03)
calling transfer related leg The record’s Transfer related call ID names another record’s Local call ID: the leg on the other side of a transfer. Cisco’s example populates it on two of four records, so its absence on a neighbouring record is not a gap. (L03)
calling deflection The record’s Related reason is Deflection. A blind transfer surfaces only as deflection, a value shared with auto-attendant transfer and call centre exit, so this record alone does not say which produced it. (L04)
calling redirected The record carries both an Original reason and a Redirect reason: the call reached this leg by redirection. The fields give the first and the last redirector; if the call was redirected more than once, no field gives an intermediate hop. (L04)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L01, L02)
calling two records one leg These records share a Network call ID: the source says they are the sides of one leg, not separate legs. Each is drawn because each carries its own party and location. (L03, L04)
Legs are grouped only by a correlation identifier the source supplied. Records without one are listed separately and are not inferred.
A transition marked as declared means the source’s own leg identifiers link the two legs: one names the other. It does not say whether a transfer, a redirect or a forward produced that link. Where the later leg’s own record states a feature — a CUCM join on behalf of transfer, a Calling related reason — the arrow says so and the finding beside it cites the field. Every other transition means only that both legs carry the same correlation identifier and that one follows the other in time.
Leg order is start time, then the source’s own leg identifier. A leg whose timestamps contradict that order is flagged, never re-ordered.
Where a file carries no timestamp that fixes both a date and a time zone, legs are ordered by their position in the capture and labelled as capture order. A capture position is never shown as a time and never used as a duration.
A call that reached an agent, a device or an endpoint outside this export has legs this file cannot show. A gap in a chain is not proof that nothing happened.
Durations are shown only where the source supplied a connect or disconnect time. A missing time stays unknown and is not treated as zero.
What this file can show
Calling records are call legs as one side records them. Unanswered legs are not queue abandons, and Contact Center durations are unavailable in this profile.
Grouping uses supplied names. Identically named locations are combined; this file does not establish distinct object identities.
A call is drawn record by record. Records that share a Network call ID are the sides of one leg; they are drawn as separate records because each carries its own party, device and location, and a finding names the group.
No field in this export is a media-quality metric: nothing here reports jitter, packet loss, latency or a quality score, because the Detailed Call History carries none.
Legs are grouped by the Correlation ID, which Cisco describes as tying the legs of one session. It is unchanged across a blind transfer in Cisco’s example and takes three values across the four records of a call park, so a parked call can appear as more than one call here.
A transition is declared where one record names the other by identifier: Remote call ID (the other side of the same leg), Transfer related call ID (the other side of a transfer) or Related call ID (a call this call created through a service). Where the two records also share a Network call ID, that arrow joins the two sides of one leg rather than two legs, and the finding beside it says so. Cisco’s example populates Transfer related call ID on two of four records, so its absence is not a gap. A Remote call ID names the other record of the same leg and a Related call ID a different call, so neither is a missing leg of this call when its record is absent; each is a link only when the record it names is in this file, and neither absence is reported as a gap. Only an unresolved Transfer related call ID is a gap, because it names another leg of this call.
The Control Hub report and the API spell six columns differently in capitalisation and spacing; both spellings are read as one field. Three names appear on one surface only and are not read: External customer ID, AI Agent ID, Transfer type.
Fields read without a knowledge-base claim behind their meaning, on the column’s name alone: Start time, Answer time, Release time, Answered, Answer indicator, Calling number, Called number, User, Location, Device Mac, Inbound trunk, Outbound trunk.
A JSON page from the API carries no marker of whether further pages followed; a partial harvest cannot be detected from the file.
Direction publishes ORIGINATING and TERMINATING; they are shown as outbound and inbound from the recording side’s point of view.
A Start time must carry a zone or an offset. A row whose time carries neither is excluded rather than read against a guessed zone.
File coverage is not verified against the source system. An empty day can mean no records or an incomplete export.
FICTIONAL SAMPLE DATA — generated without customer records or bearer tokens.