TranslatorX

A desktop application for reading, filtering, correlating, and visualizing signaling logs from Cisco collaboration systems and related endpoints.

Released August 3, 2026

TranslatorX 26.1.1 is now available

Version 26.1.1 is the first version of the new TranslatorX app, bringing native multi-window investigation, call and media analysis, remote collection, evidence-grounded AI assistance, and verified packages to macOS, Windows, and Linux.

Explore the 26.1.1 features

Functions

What TranslatorX does

The application keeps the original protocol detail available while adding a normalized view across different products and log formats.

Import trace data

Open files, folders, gzip logs, ZIP, TAR, TAR.GZ, TGZ, and nested archive bundles, packet captures, normalized TranslatorX exports, or text copied to the clipboard.

Order messages from multiple sources

Normalize timestamps to GMT, infer source timezones and missing years, and allow per-source time overrides when automatic alignment is not correct.

Search, filter, and decode

Use text search, structured reusable filters, protocol visibility, routine-traffic controls, and decoded details for supported signaling protocols.

Identify calls and SIP sessions

Review Unified CM CDR records, trace-derived SIP calls, and multi-leg sessions correlated by explicit identifiers, with a directed topology for retries, forks, transfers, and transit hops.

Visualize signaling across products

Follow messages between endpoints, Unified CM, CUBE, Expressway, and other systems in a chronological call-flow window with editable device labels and lanes.

Inspect media quality evidence

Decode endpoint, Webex App, CUBE, RFC 6035, and Unified CM CMR statistics; preserve the raw reports; and explain supported loss, jitter, delay, and reconciliation results.

Collect logs remotely

Collect a timeframe from Unified CM, CUBE, or Expressway; coordinate multiple devices; or run live CUBE and Expressway traces.

Analyze selected evidence with an LLM

Optionally analyze a SIP call, session, or filtered trace using Ollama, Anthropic, AWS Bedrock, or a custom endpoint compatible with Anthropic Messages or OpenAI Chat Completions.

Export results

Create readable text, a normalized re-importable trace, a call-flow diagram, or a portable AI analysis report in Markdown or PDF.

Main workspace

Trace data and context in one view

Select a marker to see how the main TranslatorX window supports common investigation tasks.

TranslatorX main window showing a synthetic SIP trace and the selected INVITE message

Compatibility

Sources and protocols

Support depends on the information present in each source. Summary-only logs can be correlated and displayed, but cannot provide message bodies that were never recorded.

Primary products

  • Cisco Unified CM SDL, SDI, calllogs, CDR, and CMR
  • Cisco CUBE and IOS gateway VoIP traces and SIP debugs
  • Cisco Expressway and VCS Network Log and diagnostic bundles
  • Webex App, Jabber, phones, and supported endpoint logs

Protocols

  • SIP and SDP
  • SCCP / Skinny
  • Q.931 / Q.SIG
  • MGCP and MGCP backhaul
  • H.225, RAS, and H.245

Additional inputs

  • SIP extracted from supported PCAP files
  • CUSP and BroadWorks signaling logs
  • Portable .txtrace files exported by TranslatorX

Remote access

  • HTTPS with TLS 1.2 or newer for supported APIs
  • Reusable HTTP and SOCKS5 proxy routes for HTTPS and SSH
  • SSH passwords, keys, FIDO2 security keys, and interactive MFA
  • Optional SSH jump hosts with separate credentials

Call List

Calls and sessions found from loaded data

TranslatorX separates standalone or embedded Unified CM CDR records from calls and sessions derived automatically from the signaling messages in the loaded traces.

SIP calls

Initial INVITEs are grouped by Call-ID with participants, result, duration, observed endpoints, and message counts. A selected call can be filtered, analyzed, or opened directly in Call Flow.

Current TranslatorX SIP Calls view using synthetic trace data

SIP sessions

Related call legs are correlated through explicit Session-ID and vendor identifiers. Open the Session Inspector to see their directed topology, numbered legs, media evidence, and event timeline without relying on phone-number or timing heuristics.

Current TranslatorX SIP Sessions view showing a synthetic multi-leg session

Unified CM CDR

Embedded and standalone CDR files remain available in their own tab with decoded disconnect causes, search, trace filtering, and complete record details.

Current TranslatorX CDR Calls view using synthetic Unified CM records

Call Flow

Visualize message flows across products

Follow signaling chronologically as a call moves between endpoints, Unified CM, CUBE, Expressway, and service-provider systems. Select any row to inspect its decoded message while retaining the complete flow as context.

TranslatorX call flow showing a fictional multi-device SIP session

SIP Session Inspector

Visualize the call flow topology

See how retries, forks, transfers, and transit hops branch across a correlated session.

  • Directed call progression. Follow the call from originators through transit hops to termination.
  • One device, multiple interfaces. Interfaces for the same signaling device are shown in one wider card, with each address on the side where it participates.
Synthetic SIP Session Inspector showing a branched call topology with a multi-interface signaling device
Entirely fictional demonstration data using reserved documentation addresses.

Media quality evidence

Put reported RTP statistics beside the stream they describe

Established Media Streams bring supported Cisco phone and Webex App statistics, CUBE P-RTP-Stat, RFC 6035 reports, and Unified CM CMR evidence into one explainable view while keeping every source report available.

  • Direction and viewpoint stay visible. Measurements remain attached to the reporter, call leg, stream direction, and source representation that produced them.
  • Conservative grading. Known impairments show the violated loss, jitter, delay, or no-media evidence; absent or ambiguous evidence is not presented as good.
  • Readable statistics. Decoded names, applicable units, concise bps rates, raw fields, and safe TX/RX comparisons make the evidence easier to verify.
Synthetic Media Streams detail showing impaired CUBE RTP statistics, quality thresholds, and source evidence
Simulated impairment values demonstrate the evidence and assessment workflow.

Remote Collection

Collect the right interval from the right systems

Saved connection profiles support focused historical collection, coordinated collection across products, bounded troubleshooting sessions, and real-time tracing.

01

Single-device collection

Collect a relative or absolute timeframe from one Unified CM, CUBE, or Expressway profile. A Unified CM publisher profile discovers and collects every cluster node.

Use when

The incident time is known and one product contains the evidence you need.

Products

Unified CM, CUBE, Expressway

02

Multi-device collection

Apply one relative or absolute timeframe to several saved profiles. Independent collectors run in parallel and the results open as one correlated timeline.

Use when

A known incident crossed product or network boundaries.

Products

Unified CM, CUBE, Expressway

03

Troubleshooting session

Select the participating systems, start the session, reproduce the issue, and stop. TranslatorX records the exact interval and coordinates Expressway diagnostic capture.

Use when

The issue can be reproduced now and the relevant devices are known.

Products

Unified CM, CUBE, Expressway

04

Live collection

Stream signaling from one or more CUBE and Expressway profiles. Incoming messages immediately update filters, call analysis, and open call-flow windows.

Use when

You need to watch signaling and calls while the issue occurs.

Products

CUBE, Expressway

Data handling

Local processing by default

Parsing, filtering, correlation, call-flow generation, and export run on the local computer. Remote collection connects only to profiles selected by the user.

Credentials and connections

Saved credentials are kept in the operating system credential manager. SSH host keys and HTTPS certificates that are not already trusted must be reviewed before use; accepted HTTPS certificates are pinned to the selected origin.

Optional AI analysis

Local Ollama analysis does not send trace evidence off the computer. Cloud providers receive evidence only after the user starts an analysis. Cloud identifier anonymization is enabled by default and can be disabled when organizational policy permits it.