ENGINEERING TOOL
Telecom Trace Analyzer
A practical PCAP analysis tool for telecom engineers. Upload a PCAP/PCAPNG capture and inspect SIP signalling, Call-ID flows, authentication challenges, diagnostics and SIP failures.
Open Telecom Trace Analyzer
The live analyzer runs as a separate app on Streamlit. Your capture is uploaded to that app for analysis, so remove or anonymise subscriber data such as IMSI, phone numbers and IP addresses before uploading a trace from a live network. Details are in the privacy notice.
What is this tool?
The Telecom Trace Analyzer is part of this knowledge hub's practical engineering toolkit. It connects the theory in the SIP and Log Analysis sections with real packet captures and troubleshooting work.
The current version uses a payload-first SIP extraction approach so that SIP messages can still be recovered when normal TShark SIP dissection does not expose every message.
What it can analyse
- SIP message extraction — identify REGISTER, INVITE, ACK, BYE, CANCEL, SUBSCRIBE, NOTIFY and other SIP messages from PCAP/PCAPNG files.
- Call-ID flows — group SIP messages into individual signalling conversations.
- Authentication challenges — identify normal 401/407 Digest authentication challenges separately from actual SIP failures.
- SIP failures — highlight response codes and signalling conditions that require investigation.
- Diagnostics — surface useful observations around the extracted signalling.
- Message explorer — inspect individual SIP messages with frame and flow context.
Typical engineer workflow
- Capture or export the relevant PCAP/PCAPNG from the UE, simulator, network or test environment.
- Open the analyzer and upload the capture.
- Review the SIP message count and Call-ID flows.
- Separate expected authentication challenges from real failures.
- Inspect the message sequence and diagnostics.
- Use the SIP and Log Analysis notes in this knowledge hub to understand the signalling in more detail.
Example IMS registration
A normal IMS registration may contain the following sequence:
REGISTER
↓
401 Unauthorized ← Authentication challenge
↓
REGISTER + Authorization
↓
200 OKA 401 or 407 authentication challenge is therefore not automatically treated as a SIP failure by the analyzer.
Next development
The tool will continue to grow toward deeper transaction analysis, visual SIP call-flow diagrams and requirements/RFS evidence checking for telecom validation work.
Learn the signalling behind the trace
Read the SIP and Log Analysis sections before or after using the analyzer.