Skip to main content

Investigate Configuration Changes

Start with the Configuration Intelligence overview to identify drift, then use the Change Timeline to understand the actor, fields, risk, impact, and related activity.

Monitor Configuration Intelligence

Open Configuration Intelligence > Overview and review:

  • The number of recent changes.
  • Drift Alerts against pinned baselines.
  • Recent High-Risk Changes that need review.
  • Cluster snapshot health and the most recent schedule result.
  • Quick actions for Change Timeline, Compare to Live, and As-Built Report.
Screenshot of the Configuration Intelligence dashboard highlighting drift alerts and recent high-risk CUCM changes

Spot Unusual Changes

Review the Drift Alerts area before treating a high change count as an incident. Select a drift card to open its pinned-baseline comparison. A large planned migration and an unexpected off-hours change require different responses.

Use Investigate on an Unusual Activity Detected anomaly to open the Timeline in the relevant cluster context. Confirm the cluster, time window, object type, and source before drawing a conclusion.

Filter the Change Timeline

Open the Timeline tab and narrow the investigation:

  1. Choose the date range.
  2. Select a cluster or keep All Clusters.
  3. Filter by object type.
  4. Use More for kind, actor, source, or granularity.
  5. Select a risk chip when you want to focus on one severity.

The chart helps identify bursts of additions, modifications, or removals. Select a chart interval to focus the event list on that window.

Understand Risk and Change Intelligence

Risk is a deterministic prioritization signal, not an approval decision. Read the explanation together with the object type, changed fields, confidence-based actor correlation, and maintenance context.

  • Critical and High events should be reviewed first.
  • Medium events may affect individual devices or users.
  • Low events are often descriptive, but can still matter when external processes depend on the field.

Expand an event to see the changed fields and the explanation attached to that specific record.

Screenshot of an expanded Configuration Intelligence timeline event with risk, actor confidence, changed fields, and a deterministic risk explanation

Review Impact

Select Show Impact on an expanded event to inspect related configuration objects. Use the impact view to understand the likely blast radius before you approve a follow-up change or start a restore plan.

Impact describes relationships visible to Configuration Intelligence. Confirm critical routing behavior in CUCM before taking action.

Share and Discuss a Change

Use the event actions to move the investigation forward:

  • View Diff opens the relevant before-and-after comparison.
  • Show Impact opens the relationship view.
  • Discuss in Webex sends the event into a configured review room.
  • Comments and review annotations keep the decision context attached to the change.

When the current state must be checked against a known reference, continue to Compare.

Compare and Restore Configuration →