{"_id":"@calltelemetry/cisco-dime-mcp","name":"@calltelemetry/cisco-dime-mcp","dist-tags":{"latest":"0.4.0"},"versions":{"0.4.0":{"name":"@calltelemetry/cisco-dime-mcp","version":"0.4.0","type":"module","description":"MCP server for CUCM operational debugging: DIME logs, AXL config, RIS device status, PerfMon counters, service health, packet capture, and pcap analysis","license":"MIT","repository":{"type":"git","url":"git+https://github.com/calltelemetry/cisco-dime-mcp.git"},"bin":{"cisco-dime-mcp":"build/index.js"},"publishConfig":{"access":"public"},"engines":{"node":">=18"},"packageManager":"yarn@4.12.0","scripts":{"build":"vite build && chmod +x build/index.js","start":"node build/index.js","dev":"tsx src/index.ts","typecheck":"tsc --noEmit","lint":"eslint src/ test/ --max-warnings=50","lint:fix":"eslint src/ test/ --fix","format":"prettier --write 'src/**/*.ts' 'test/**/*.ts'","format:check":"prettier --check 'src/**/*.ts' 'test/**/*.ts'","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage","validate":"yarn typecheck && yarn lint && yarn test","prepack":"yarn build && yarn test"},"dependencies":{"@modelcontextprotocol/sdk":"^1.12.1","fast-xml-parser":"^4.5.3","ssh2":"^1.16.0","zod":"^3.24.2"},"devDependencies":{"@eslint/js":"^9.39.3","@types/node":"^25.1.0","@types/ssh2":"^1.15.4","@vitest/coverage-v8":"^4.0.18","eslint":"^9.39.3","prettier":"^3.8.1","tsx":"^4.19.4","typescript":"^5.7.3","typescript-eslint":"^8.56.1","vite":"^7.3.1","vitest":"^4.0.18"},"_id":"@calltelemetry/cisco-dime-mcp@0.4.0","gitHead":"165d731fe378e0a8554f136171775eaf5c19ddaa","bugs":{"url":"https://github.com/calltelemetry/cisco-dime-mcp/issues"},"homepage":"https://github.com/calltelemetry/cisco-dime-mcp#readme","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-FljScwwSMskkvSER9tR9sZKGlohq3w8/9KiGZ1sW0iTx9R1PPBZRpaP21CeWtXTAN3z/xgLce6BUNARXWnMGZQ==","shasum":"b3ccf7250a38904e165cc6f88866e86f2c9bb237","tarball":"https://registry.npmjs.org/@calltelemetry/cisco-dime-mcp/-/cisco-dime-mcp-0.4.0.tgz","fileCount":5,"unpackedSize":2228657,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD5XXLEJ+o0f1liKPP6jziaU4jNHyOOdQX1IAz5IkO17AIgXRhYRaNpfE1uq8inUnLwf8akkcWpEirDi+gP/7+bw9M="}]},"_npmUser":{"name":"jasonbarbee","email":"jason.barbee@gmail.com"},"directories":{},"maintainers":[{"name":"jasonbarbee","email":"jason.barbee@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cisco-dime-mcp_0.4.0_1772341860145_0.9607247594559833"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-01T05:10:59.943Z","0.4.0":"2026-03-01T05:11:00.347Z","modified":"2026-03-01T05:11:00.630Z"},"maintainers":[{"name":"jasonbarbee","email":"jason.barbee@gmail.com"}],"description":"MCP server for CUCM operational debugging: DIME logs, AXL config, RIS device status, PerfMon counters, service health, packet capture, and pcap analysis","homepage":"https://github.com/calltelemetry/cisco-dime-mcp#readme","repository":{"type":"git","url":"git+https://github.com/calltelemetry/cisco-dime-mcp.git"},"bugs":{"url":"https://github.com/calltelemetry/cisco-dime-mcp/issues"},"license":"MIT","readme":"# Cisco DIME MCP\n\n[![npm](https://img.shields.io/npm/v/@calltelemetry/cisco-dime-mcp)](https://www.npmjs.com/package/@calltelemetry/cisco-dime-mcp)\n[![CI](https://github.com/calltelemetry/cisco-dime-mcp/actions/workflows/ci.yml/badge.svg)](https://github.com/calltelemetry/cisco-dime-mcp/actions/workflows/ci.yml)\n[![codecov](https://codecov.io/gh/calltelemetry/cisco-dime-mcp/branch/main/graph/badge.svg)](https://codecov.io/gh/calltelemetry/cisco-dime-mcp)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n\nMCP (Model Context Protocol) server for Cisco CUCM operational debugging.\n\n## Capabilities\n\n- **DIME Log Collection** — Query and download trace/log files via CUCM DIME SOAP services on `:8443`\n- **Syslog** — Query and download system log files via DIME\n- **RisPort70 (Real-time Device Status)** — Query phone/gateway/trunk registration status via selectCmDevice\n- **PerfMon (Performance Monitoring)** — Collect real-time counters (call counts, CPU, memory, SIP stats)\n- **ControlCenter (Service Status)** — Query CUCM service health: Started, Stopped, Not Activated (read-only)\n- **Packet Capture** — Start/stop captures via CUCM CLI over SSH, download `.cap` files via DIME\n- **Pcap Analysis** — Analyze captured pcaps locally via tshark: SIP flows, SCCP messages, RTP quality metrics\n\n## Installation\n\n```bash\nnpx @calltelemetry/cisco-dime-mcp\n```\n\n## Quick Start\n\n### Claude Code\n\n```bash\nclaude mcp add cucm -- npx -y @calltelemetry/cisco-dime-mcp@latest\n```\n\n### Manual Configuration\n\nAdd to your `.mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"cucm\": {\n      \"type\": \"stdio\",\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@calltelemetry/cisco-dime-mcp@latest\"],\n      \"env\": {\n        \"CUCM_DIME_USERNAME\": \"<dime-user>\",\n        \"CUCM_DIME_PASSWORD\": \"<dime-pass>\",\n        \"CUCM_SSH_USERNAME\": \"<ssh-user>\",\n        \"CUCM_SSH_PASSWORD\": \"<ssh-pass>\"\n      }\n    }\n  }\n}\n```\n\n## Configuration\n\n### DIME (HTTPS on :8443)\n\n| Variable | Description |\n|----------|-------------|\n| `CUCM_DIME_USERNAME` | DIME SOAP username |\n| `CUCM_DIME_PASSWORD` | DIME SOAP password |\n| `CUCM_DIME_PORT` | DIME port (default: `8443`) |\n\n### SSH (CLI)\n\n| Variable | Description |\n|----------|-------------|\n| `CUCM_SSH_USERNAME` | SSH username (often `administrator`) |\n| `CUCM_SSH_PASSWORD` | SSH password |\n| `CUCM_SSH_PORT` | SSH port (default: `22`) |\n\n### AXL (Phone Configuration)\n\n| Variable | Description |\n|----------|-------------|\n| `CUCM_AXL_USERNAME` | AXL username (falls back to DIME creds) |\n| `CUCM_AXL_PASSWORD` | AXL password (falls back to DIME creds) |\n\n### TLS\n\nCUCM lab environments often use self-signed certificates. By default this server sets `NODE_TLS_REJECT_UNAUTHORIZED=0`.\n\n| Variable | Description |\n|----------|-------------|\n| `CUCM_MCP_TLS_MODE` | `permissive` (default) or `strict` |\n\n### tshark (Pcap Analysis)\n\nThe pcap analysis tools require **tshark** (Wireshark CLI). Discovered automatically:\n\n1. `TSHARK_PATH` env var\n2. `tshark` in PATH\n3. `/Applications/Wireshark.app/Contents/MacOS/tshark` (macOS)\n4. `/usr/bin/tshark` (Linux)\n5. `/opt/homebrew/bin/tshark` (Homebrew)\n\n| Variable | Description |\n|----------|-------------|\n| `TSHARK_PATH` | Override tshark binary location |\n| `CUCM_MCP_TSHARK_TIMEOUT_MS` | Execution timeout (default: `60000`) |\n\n### Serviceability APIs (RIS, PerfMon, ControlCenter)\n\nThese APIs share the same credentials and port as DIME. No additional environment variables needed.\n\n### Capture State Persistence\n\nPacket capture metadata is persisted to a local JSON file for recovery after MCP restarts.\n\n| Variable | Description |\n|----------|-------------|\n| `CUCM_MCP_STATE_PATH` | State file path (default: `./.cucm-mcp-state.json`) |\n| `CUCM_MCP_CAPTURE_RUNNING_TTL_MS` | Running capture TTL (default: 6 hours) |\n| `CUCM_MCP_CAPTURE_STOPPED_TTL_MS` | Stopped capture TTL (default: 24 hours) |\n\n## Tools\n\n### Log Collection (DIME)\n\n| Tool | Description |\n|------|-------------|\n| `list_node_service_logs` | List CUCM cluster nodes and their available service logs |\n| `select_logs` | Query log files with date/time criteria |\n| `select_logs_minutes` | Convenience: find logs from the last N minutes |\n| `select_syslog_minutes` | Convenience: find system logs from the last N minutes |\n| `download_file` | Download a single file via DIME |\n\n### AXL (Phone Configuration)\n\n| Tool | Description |\n|------|-------------|\n| `axl_execute` | Execute any AXL SOAP operation |\n| `axl_download_wsdl` | Download the AXL WSDL schema |\n| `phone_packet_capture_enable` | Enable packet capture on a phone (updatePhone + applyPhone) |\n\n### RisPort70 (Real-time Device Status)\n\n| Tool | Description |\n|------|-------------|\n| `select_cm_device` | Query device registration status (phones, gateways, trunks) with filters |\n| `select_cm_device_by_ip` | Convenience: look up device registration by IP address |\n\n### PerfMon (Performance Monitoring)\n\n| Tool | Description |\n|------|-------------|\n| `perfmon_collect_counter_data` | Collect counter values for a PerfMon object (e.g. \"Cisco CallManager\") |\n| `perfmon_list_counter` | Discover available PerfMon objects and counters |\n| `perfmon_list_instance` | List instances of a PerfMon object |\n\n### ControlCenter (Service Status)\n\n| Tool | Description |\n|------|-------------|\n| `get_service_status` | Query CUCM service status — Started, Stopped, Not Activated (read-only) |\n\n### Packet Capture (SSH + DIME)\n\n| Tool | Description |\n|------|-------------|\n| `packet_capture_start` | Start capture via CUCM CLI over SSH |\n| `packet_capture_stop` | Stop a running capture |\n| `packet_capture_stop_and_download` | Stop + download `.cap` via DIME (with retries) |\n| `packet_capture_list` | List active in-memory captures |\n| `packet_capture_state_list` | List captures from persistent state file |\n| `packet_capture_state_get` | Get one capture record from state |\n| `packet_capture_state_clear` | Delete a capture record from state |\n| `packet_capture_download_from_state` | Download by captureId after MCP restart |\n\n### Pcap Analysis (tshark)\n\nThese tools analyze downloaded `.cap` files so an LLM can reason about VoIP calls without opening Wireshark.\n\n| Tool | Description |\n|------|-------------|\n| `pcap_call_summary` | High-level overview: protocols, endpoints, SIP/RTP counts |\n| `pcap_sip_calls` | SIP call flows grouped by Call-ID with setup timing |\n| `pcap_sccp_messages` | SCCP/Skinny messages with human-readable type names |\n| `pcap_rtp_streams` | RTP quality per stream: jitter, packet loss, codec, duration |\n| `pcap_protocol_filter` | Arbitrary tshark display filter for deeper investigation |\n\n### Utility\n\n| Tool | Description |\n|------|-------------|\n| `guess_timezone_string` | Build a DIME-compatible timezone string |\n\n## Examples (Real CUCM Output)\n\nExamples below are from a live CUCM 15.0 cluster.\n\n### Discover Cluster Nodes and Service Logs\n\n```\n→ list_node_service_logs({ host: \"192.168.125.10\" })\n\n{\n  \"nodes\": [\n    {\n      \"name\": \"cucm15-cluster1.calltelemetry.local\",\n      \"serviceCount\": 150,\n      \"services\": [\n        \"Cisco CallManager\",\n        \"Cisco CTIManager\",\n        \"Cisco Tftp\",\n        \"Cisco Certificate Change Notification\",\n        \"Cisco DRF Master\",\n        ...\n      ]\n    }\n  ]\n}\n```\n\n### Query Phone Inventory via AXL\n\n```\n→ axl_execute({\n    host: \"192.168.125.10\",\n    operation: \"listPhone\",\n    body: {\n      searchCriteria: { name: \"SEP%\" },\n      returnedTags: { name: \"\", model: \"\", description: \"\" }\n    }\n  })\n\n{\n  \"phone\": [\n    { \"name\": \"SEP0022905C7710\", \"model\": \"Cisco 7975\",  \"description\": \"Auto 1000 7975 Phone3\" },\n    { \"name\": \"SEP000832C78E0F\", \"model\": \"Cisco 7821\",  \"description\": \"Jason 7821\"            },\n    { \"name\": \"SEP505C885DF37F\", \"model\": \"Cisco 9841\",  \"description\": \"Cisco 9841 SIP\"        },\n    ...\n  ]\n}\n```\n\n### Collect Recent Trace Files\n\n```\n→ select_logs_minutes({\n    host: \"192.168.125.10\",\n    serviceName: \"Cisco CallManager\",\n    minutes: 30\n  })\n\n{\n  \"files\": [\n    {\n      \"name\": \"cdr_0000000004.txt\",\n      \"node\": \"cucm15-cluster1.calltelemetry.local\",\n      \"filesize\": \"47780\",\n      \"modifiedDate\": \"Fri Feb 28 08:23:26 UTC 2026\"\n    },\n    {\n      \"name\": \"cmr_0000000004.txt\",\n      \"node\": \"cucm15-cluster1.calltelemetry.local\",\n      \"filesize\": \"3830\",\n      \"modifiedDate\": \"Fri Feb 28 08:23:26 UTC 2026\"\n    },\n    {\n      \"name\": \"SDL001_100_001618.txt.gz\",\n      \"node\": \"cucm15-cluster1.calltelemetry.local\",\n      \"filesize\": \"1073817\",\n      \"modifiedDate\": \"Fri Feb 28 08:22:15 UTC 2026\"\n    }\n  ]\n}\n```\n\n### Query Registered Phones (RisPort70)\n\n```\n→ select_cm_device({\n    host: \"192.168.125.10\",\n    deviceClass: \"Phone\",\n    status: \"Any\",\n    selectItems: [\"*\"]\n  })\n\n{\n  \"totalDevicesFound\": 3,\n  \"cmNodes\": [\n    {\n      \"name\": \"cucm15-cluster1\",\n      \"returnCode\": \"Ok\",\n      \"devices\": [\n        {\n          \"name\": \"SEP000832C78E0F\",\n          \"ipAddress\": \"192.168.125.85\",\n          \"dirNumber\": \"1001-Registered\",\n          \"status\": \"Registered\",\n          \"protocol\": \"SIP\",\n          \"activeLoadId\": \"sip78xx.14-3-1-0001-60\"\n        },\n        {\n          \"name\": \"SEP0022905C7710\",\n          \"ipAddress\": \"192.168.125.178\",\n          \"dirNumber\": \"1000-Registered\",\n          \"status\": \"Registered\",\n          \"protocol\": \"SCCP\",\n          \"activeLoadId\": \"SCCP75.9-4-2SR4-3S\"\n        },\n        {\n          \"name\": \"SEP505C885DF37F\",\n          \"ipAddress\": \"192.168.125.234\",\n          \"dirNumber\": \"1003-Registered\",\n          \"status\": \"Registered\",\n          \"protocol\": \"SIP\",\n          \"activeLoadId\": \"PHONEOS.3-2-1-0003-28\"\n        }\n      ]\n    }\n  ]\n}\n```\n\n### Collect Performance Counters (PerfMon)\n\n```\n→ perfmon_collect_counter_data({\n    host: \"192.168.125.10\",\n    perfmonHost: \"192.168.125.10\",\n    object: \"Cisco CallManager\"\n  })\n\n[\n  { \"name\": \"\\\\\\\\192.168.125.10\\\\Cisco CallManager\\\\CallsActive\", \"value\": 0, \"cStatus\": 0 },\n  { \"name\": \"\\\\\\\\192.168.125.10\\\\Cisco CallManager\\\\CallsAttempted\", \"value\": 54, \"cStatus\": 0 },\n  { \"name\": \"\\\\\\\\192.168.125.10\\\\Cisco CallManager\\\\CallsCompleted\", \"value\": 44, \"cStatus\": 0 },\n  { \"name\": \"\\\\\\\\192.168.125.10\\\\Cisco CallManager\\\\RegisteredHardwarePhones\", \"value\": 3, \"cStatus\": 0 },\n  { \"name\": \"\\\\\\\\192.168.125.10\\\\Cisco CallManager\\\\RegisteredOtherStationDevices\", \"value\": 5, \"cStatus\": 0 }\n  // ... 134 counters total\n]\n```\n\n### Check Service Health (ControlCenter)\n\n```\n→ get_service_status({ host: \"192.168.125.10\" })\n\n[\n  { \"serviceName\": \"Cisco CallManager\",       \"serviceStatus\": \"Started\" },\n  { \"serviceName\": \"Cisco CTIManager\",        \"serviceStatus\": \"Started\" },\n  { \"serviceName\": \"Cisco Tftp\",              \"serviceStatus\": \"Started\" },\n  { \"serviceName\": \"Cisco AXL Web Service\",   \"serviceStatus\": \"Started\" },\n  { \"serviceName\": \"Cisco RIS Data Collector\",\"serviceStatus\": \"Started\" },\n  { \"serviceName\": \"Cisco CDR Agent\",         \"serviceStatus\": \"Started\" },\n  { \"serviceName\": \"Cisco DHCP Monitor Service\", \"serviceStatus\": \"Stopped\" }\n  // ... 81 services total (65 Started)\n]\n```\n\n### Packet Capture Workflow (End-to-End)\n\n**1. Start capture with SIP filter:**\n\n```\n→ packet_capture_start({\n    host: \"192.168.125.10\",\n    portFilter: 5060,\n    count: 5000\n  })\n\n{\n  \"captureId\": \"c2439a09-b082-4c91-ba1e-20b211f1a217\",\n  \"status\": \"running\",\n  \"fileBase\": \"packets\",\n  \"startedAt\": \"2026-02-28T08:25:44.000Z\"\n}\n```\n\n**2. Reproduce the issue** (place a test call, trigger the problem, etc.)\n\n**3. Stop and download:**\n\n```\n→ packet_capture_stop_and_download({\n    host: \"192.168.125.10\",\n    captureId: \"c2439a09-b082-4c91-ba1e-20b211f1a217\"\n  })\n\n{\n  \"localPath\": \"/tmp/cucm-mcp/readme-demo.cap\",\n  \"fileSize\": 10532,\n  \"status\": \"downloaded\"\n}\n```\n\n**4. Triage — what's in the capture?**\n\n```\n→ pcap_call_summary({ filePath: \"/tmp/cucm-mcp/readme-demo.cap\" })\n\n{\n  \"totalPackets\": 20,\n  \"protocols\": [\"SIP\", \"SDP\"],\n  \"sipCalls\": 2,\n  \"rtpStreams\": 1,\n  \"endpoints\": [\n    { \"ip\": \"192.168.125.10\", \"packets\": 10 },\n    { \"ip\": \"192.168.125.85\", \"packets\": 10 }\n  ]\n}\n```\n\n**5. SIP call flow detail:**\n\n```\n→ pcap_sip_calls({ filePath: \"/tmp/cucm-mcp/readme-demo.cap\" })\n\n{\n  \"calls\": [\n    {\n      \"callId\": \"6e51c0-60e94629-6-64257ec0@192.168.125.10\",\n      \"from\": \"\\\"1000\\\" <sip:1000@192.168.125.10>\",\n      \"to\": \"<sip:1001@192.168.125.10>\",\n      \"messages\": [\n        { \"method\": \"INVITE\",      \"status\": null,          \"timestamp\": \"08:25:56.742\" },\n        { \"method\": null,          \"status\": \"100 Trying\",  \"timestamp\": \"08:25:56.743\" },\n        { \"method\": null,          \"status\": \"180 Ringing\", \"timestamp\": \"08:25:56.754\" },\n        { \"method\": null,          \"status\": \"200 OK\",      \"timestamp\": \"08:25:57.899\" },\n        { \"method\": \"ACK\",         \"status\": null,          \"timestamp\": \"08:25:57.901\" },\n        { \"method\": \"BYE\",         \"status\": null,          \"timestamp\": \"08:26:12.555\" },\n        { \"method\": null,          \"status\": \"200 OK\",      \"timestamp\": \"08:26:12.556\" }\n      ],\n      \"setupTime\": \"1157 ms\",\n      \"codec\": \"PCMU (G.711 u-law)\",\n      \"sdpMedia\": \"audio 29390 RTP/AVP 0\"\n    }\n  ]\n}\n```\n\n**6. RTP audio quality:**\n\n```\n→ pcap_rtp_streams({ filePath: \"/tmp/cucm-mcp/readme-demo.cap\" })\n\n{\n  \"streams\": [\n    {\n      \"src\": \"192.168.125.85:29390\",\n      \"dst\": \"192.168.125.10:28770\",\n      \"codec\": \"PCMU (G.711 u-law)\",\n      \"packets\": 748,\n      \"lost\": 0,\n      \"lossPercent\": \"0.00%\",\n      \"maxJitter\": \"0.00 ms\",\n      \"duration\": \"14.9 s\"\n    }\n  ]\n}\n```\n\n## Recommended Workflow\n\n### Packet Capture + Analysis\n\n```\n1. packet_capture_start     → Start capture (runs on CUCM in background)\n2. (reproduce the issue)\n3. packet_capture_stop_and_download → Stop + download .cap file\n4. pcap_call_summary        → Quick triage: what's in the capture?\n5. pcap_sip_calls           → SIP INVITE → 200 OK → BYE flows\n6. pcap_rtp_streams         → Audio quality: jitter, loss, codec\n```\n\n### Auth Note\n\nCUCM deployments vary — SSH and DIME may accept different credentials:\n\n```bash\n# Verify DIME credentials (WSDL should return HTTP 200)\ncurl -k -u \"<user>:<pass>\" \\\n  \"https://<cucm-host>:8443/logcollectionservice2/services/LogCollectionPortTypeService?wsdl\" \\\n  -o /dev/null -w \"%{http_code}\\n\"\n```\n\n## Development\n\n```bash\nyarn install          # Install dependencies\nyarn build            # Build with Vite\nyarn test             # Run tests (vitest)\nyarn test:coverage    # Run tests with coverage\nyarn typecheck        # TypeScript type checking\nyarn lint             # ESLint\nyarn validate         # typecheck + lint + test\nyarn dev              # Run from source (tsx)\n```\n\n## Publishing\n\nReleases are automated via GitHub Actions on version tags:\n\n```bash\n# Bump version and tag\nnpm version patch     # or minor, major\ngit push --follow-tags\n```\n\nThe publish workflow runs typecheck, tests, builds, publishes to npm, and creates a GitHub release.\n\n## Acknowledgments\n\n- [MCP SDK](https://github.com/modelcontextprotocol/sdk) — Model Context Protocol framework\n- [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) — XML parsing\n- [ssh2](https://github.com/mscdex/ssh2) — SSH client for CUCM CLI\n- [tshark/Wireshark](https://www.wireshark.org/) — Pcap analysis\n\n## License\n\nMIT — see [LICENSE](LICENSE)\n","readmeFilename":"README.md","_rev":"1-22a773705f698cb2a7ac889efde54503"}