Cisco CDR
September 22nd, 2025
If you are running Cisco Unified Communications Manager (CUCM), you know how critical it is to your business. However if toll fraud started happening on your system today, would you know right away?
If you are running Cisco Unified Communications Manager (CUCM), you know how critical it is to your business. But here’s a question worth asking:
If toll fraud started happening on your system today, would you know right away? Or would you only find out next month when a massive phone bill arrives?
Toll fraud doesn’t happen often, and your CUCM may not be vulnerable. But imagine your security team asks you tomorrow: “What safeguards do we have in place to catch this?” Would you have a good answer?
What Toll Fraud Might Look Like in CUCM CDR
Until you spot the weird outside number, it looks like a normal CDR. But that number is in Russia and someone has just found a way to make your phone system work against you.
How to Spot It With Sideview
It can be as simple as saving this search in our Cisco CDR Reporting and Analytics App:
initial_type="incoming" finalCalledPartyCountry=* NOT finalCalledPartyCountry="United States"
This says find me any calls whose earliest call leg was an “incoming” aka inbound leg, but that also had at least one call leg outbound to some country that’s not the US.
Here’s what the results look like when you run that search and find results. Note we’ve added the optional field “finalCalledPartyCountry” and it has the value “Russian Federation”.
Both this “finalCalledPartyCountry” field and the “initial_type” field are ones that the Sideview product adds — you won’t find those fields in the raw CDR anywhere. Nonetheless in this product you
can filter, exclude, chart, pivot, and build dashboards around these values just as though they were.
Next if you’d like to get alerted if such a call ever happens again, simply click “Save Report”, set scheduling properties so Splunk runs this search every hour or every day and it can email you if it ever finds results.
This Is Just The Beginning
This example above just allows you to pull out one little “known-bad” cohort of calls. You can repeat this model for anything you might need. However… you can also take larger strides.
For larger environments, we can help you define leg types in the app. This gives your team structured insight into all of your Unity call flows, and then the monitoring for “bad” flows becomes almost a natural by-product of your dashboards. Leg types are a deeper topic that we’ll save or another day.
Next let’s walk through another search which can identify a spike in international calls.
Building a Dashboard for International Call Spikes
Now you’ve got a chart that highlights unusual international calls daily. You can even have Splunk email the dashboard as a PDF every morning.
Why This Matters
Toll fraud isn’t just about money. It’s about:
Many organizations are already using Splunk for security. With the Cisco CDR Reporting and Analytics app, you get continuous monitoring, targeted searches, and dashboards that make suspicious activity easy to spot, before the bill comes!
👉 Contact us today to get a trial license and see how it works in your environment https://sideviewapps.com.
The finalMobileCallingPartyNumber field is critical to SNR analysis, but it also illustrates the importance of looking beyond the more familiar fields.
December 30th, 2025
What to do when the RTMT installer just quietly fails on you every time.
September 3rd, 2025
Practical steps to investigate and diagnose audio issues in CUCM, including one-way audio, from sanity checking your ports and configuration, to using Sideview's app as your command center.
June 19th, 2025
We never require manual migration! (well... almost never. there are some easy steps you have to do for 7.2)
February 16th, 2024