Skip to content

Metrics Dictionary Guide

This page is the canonical field reference for all event families exported by the collector. Use it to build queries, design dashboards, and troubleshoot data issues.

Log sourcePurposeTypical use
MSTeams_CallRecords_CallMetadataCall-level summaryCall volume, type, and overall health
MSTeams_CallRecords_StreamDetailsStream-level qualityTroubleshoot jitter, RTT, packet loss
MSTeams_CallRecords_PSTNPSTN activityTelephony usage and call details
MSTeams_CallRecords_DirectRoutingDirect Routing activitySIP/routing troubleshooting
MSTeams_CallRecords_AutoAttendantAuto attendant usageVoice workflow visibility
MSTeams_CallRecords_CallQueueCall queue usageQueue behavior monitoring
MSTeams_ServiceAnnouncementMicrosoft incidentsCorrelate degradations with official incidents
MSTeams_RemoteCollectionHealthRemote collection status (extension)Verify extension-based agent health
MSTeams_CollectionHealthCollector statusVerify ingestion health
ModelLog sourceFields
AutoAttendantLogMSTeams_CallRecords_AutoAttendant28
CallMetadataLogMSTeams_CallRecords_CallMetadata12
CallQueueLogMSTeams_CallRecords_CallQueue21
CollectionHealthLogMSTeams_CollectionHealth10
RemoteCollectionHealthLogMSTeams_RemoteCollectionHealth10
DirectRoutingCallLogMSTeams_CallRecords_DirectRouting22
PstnCallLogMSTeams_CallRecords_PSTN22
ServiceHealthLogMSTeams_ServiceAnnouncement17
StreamDetailsLogMSTeams_CallRecords_StreamDetails89
  • Log source: MSTeams_CallRecords_AutoAttendant
NameTypeDescription
serviceServiceMetadata | NoneBuild metadata attached to the service that produced the log.
log.sourcestrIdentifier for the log source (log family) of this record.
loglevelLogLevelTechnical log severity level.
call.idstr | NoneUnique call identifier (GUID). Use this to correlate with other call-record logs.
timestampdatetime | NoneCollection timestamp for the log entry (UTC datetime).
durationAny | NoneDuration of the call in seconds.
firstIsCallerAny | NoneWhether the first user in the record is the caller.
firstUPNstr | NoneUserPrincipalName (sign-in name) of the first user in the record.
pstnCallTypestr | NoneType of PSTN call (e.g. user call, conference call).
pstnConnectivityTypestr | NonePSTN connectivity type (Calling Plan, Direct Routing, Teams Phone Mobile, ACS).
pstnCallDurationAny | NoneDuration of the PSTN leg of the call, in seconds.
record.timestampdatetime | NoneTimestamp of the source record as reported by the upstream service.
startDateTimedatetime | NoneCall start time (UTC datetime).
autoAttendantCallFlowstr | NoneThe Auto Attendant call flow used for the call.
autoAttendantCallResultstr | NoneFinal result of the call in the Auto Attendant (e.g. terminated, transferred).
autoAttendantCallerActionCountsAny | NoneCount of actions selected by the caller in the Auto Attendant during the call.
autoAttendantChainDurationInSecsAny | NoneDuration of the call inside the Auto Attendant chain, in seconds.
autoAttendantChainIndexAny | NonePosition of the Auto Attendant in the call chain (nesting).
autoAttendantChainStartTimedatetime | NoneTime when the Auto Attendant chain started.
autoAttendantCountAny | NoneNumber of Auto Attendants the call passed through.
autoAttendantDirectorySearchMethodstr | NoneMethod used to search the directory (DTMF or voice).
autoAttendantIdstr | NoneAuto Attendant unique identifier (GUID).
autoAttendantIdentitystr | NoneName or identity of the Auto Attendant.
autoAttendantTransferActionstr | NoneTransfer action taken by the Auto Attendant.
avgAutoAttendantChainDurationSecondsfloat | NoneAverage duration of the Auto Attendant chain, in seconds.
avgCallDurationfloat | NoneAverage call duration, in seconds.
totalAudioStreamDurationfloat | NoneTotal audio stream duration, in seconds.
totalCallCountfloat | NoneTotal number of calls (1 per record, used for sums).
  • Log source: MSTeams_CallRecords_CallMetadata
NameTypeDescription
serviceServiceMetadata | NoneBuild metadata attached to the service that produced the log.
log.sourcestrIdentifier for the log source, set to ‘MSTeams_CallRecords_CallMetadata’ for this model.
loglevelLogLevelTechnical log severity level.
timestampdatetime | NoneCollection timestamp for the log entry (UTC datetime).
startDateTimedatetime | NoneCall start time (UTC datetime).
call.idstrUnique call identifier (GUID). Use this to correlate with other call-record logs.
typestrCall type and direction (e.g. peerToPeer, group, PSTN outbound/inbound).
callHealthstrAggregated health classification for the call across all streams (e.g. Good, Poor, Unclassified).
modalitieslist[str]Modalities observed in the call (e.g. audio, video, screenSharing).
callDurationSintDuration of the call in milliseconds.
participantsNameslist[str]List of participant identifiers present in the call (user ids or endpoint ids).
countParticipantsintNumber of participants counted using legacy rules (user/guest identities only).
  • Log source: MSTeams_CallRecords_CallQueue
NameTypeDescription
serviceServiceMetadata | NoneBuild metadata attached to the service that produced the log.
log.sourcestrIdentifier for the log source (log family) of this record.
loglevelLogLevelTechnical log severity level.
call.idstr | NoneUnique call identifier (GUID). Use this to correlate with other call-record logs.
dialogIdstr | NoneDialog identifier, used for troubleshooting purposes.
timestampdatetime | NoneCollection timestamp for the log entry (UTC datetime).
durationAny | NoneDuration of the call in seconds.
agentNamestr | NoneUserPrincipalName of the agent who handled the call.
record.timestampdatetime | NoneTimestamp of the source record as reported by the upstream service.
startDateTimedatetime | NoneCall start time (UTC datetime).
pstnCallTypestr | NoneType of PSTN call (e.g. user call, conference call).
pstnConnectivityTypestr | NonePSTN connectivity type (Calling Plan, Direct Routing, Teams Phone Mobile, ACS).
pstnCallDurationAny | NoneDuration of the PSTN leg of the call, in seconds.
callQueueAgentCountAny | NoneNumber of agents configured in the call queue.
callQueueAgentOptInCountAny | NoneNumber of agents opted-in to the call queue.
callQueueCallResultstr | NoneFinal result of the call (abandoned, agent answered, overflowed, timed out, no agents, other).
callQueueDurationSecondsAny | NoneCall duration inside the call queue, in seconds.
callQueueFinalStateActionstr | NoneFinal state action of the call (overflow, timeout, no agents) with routing outcome.
callQueueIdstr | NoneCall queue unique identifier (GUID).
callQueueIdentitystr | NoneName of the resource account attached to the call queue.
callQueueTargetTypestr | NoneTarget type of the call outcome (abandoned, agent answered, overflowed, timed out, no agents).
  • Log source: MSTeams_CollectionHealth
NameTypeDescription
serviceServiceMetadata | NoneBuild metadata attached to the service that produced the log.
log.sourcestrIdentifier for the log source (log family) of this record.
loglevelLogLevelTechnical log severity level.
timestampdatetime | NoneHealth log emission timestamp.
versionstr | NoneCollector application version.
statsHealthStats | NoneCanonical collection-health KPIs grouped by collect, process, deliver, and overall phases.
licenseHealthLicense | NoneLicense status snapshot included in health logs.
featuresHealthFeatures | NoneFeature toggle states at collection time.
outputHealthOutput | dict[str, Any] | NoneConfigured output destination URLs (compatibility section).
cycleHealthCycle | NoneCycle metadata.
  • Log source: MSTeams_RemoteCollectionHealth
NameTypeDescription
serviceServiceMetadata | NoneBuild metadata attached to the service that produced the log.
log.sourcestrIdentifier for the log source (log family) of this record.
loglevelLogLevelTechnical log severity level.
timestampdatetime | NoneHealth log emission timestamp.
versionstr | NoneCollector application version.
statsHealthStats | NoneCanonical collection-health KPIs grouped by collect, process, deliver, and overall phases.
licenseHealthLicense | NoneLicense status snapshot included in health logs.
featuresHealthFeatures | NoneFeature toggle states at collection time.
outputHealthOutput | dict[str, Any] | NoneConfigured output destination URLs (compatibility section).
cycleHealthCycle | NoneCycle metadata.
  • Log source: MSTeams_CallRecords_DirectRouting
NameTypeDescription
serviceServiceMetadata | NoneBuild metadata attached to the service that produced the log.
log.sourcestrIdentifier for the log source (log family) of this record.
loglevelLogLevelTechnical log severity level.
call.idstr | NoneUnique call identifier.
userPrincipalNamestr | NoneUserPrincipalName (sign-in name) in Microsoft Entra ID.
userDisplayNamestr | NoneDisplay name of the user.
startDateTimedatetime | NoneCall start time.
inviteDateTimedatetime | NoneThe date and time when the initial invite was sent.
failureDateTimedatetime | NoneOnly exists for failed (not fully established) calls.
timestampdatetime | NoneCollection timestamp for the log entry (UTC datetime).
durationint | NoneDuration of the call in seconds.
callTypestr | NoneCall type and direction.
successfulCallbool | NoneSuccess or attempt.
calleeNumberstr | NoneNumber of the user or bot who received the call. E.164 format, but might include other data.
callerNumberstr | NoneNumber of the user or bot who made the call. E.164 format, but might include other data.
mediaPathLocationstr | NoneThe datacenter used for media path in a nonbypass call.
signalingLocationstr | NoneThe datacenter used for signaling for both bypass and nonbypass calls.
finalSipCodeint | NoneThe final response code with which the call ended. For more information, see RFC 3261.
callEndSubReasonint | NoneIn addition to the SIP codes, Microsoft has subcodes that indicate the specific issue.
finalSipCodePhrasestr | NoneDescription of the SIP code and Microsoft subcode.
trunkFullyQualifiedDomainNamestr | NoneFully qualified domain name of the session border controller.
mediaBypassEnabledbool | NoneIndicates whether the trunk was enabled for media bypass.
  • Log source: MSTeams_CallRecords_PSTN
NameTypeDescription
serviceServiceMetadata | NoneBuild metadata attached to the service that produced the log.
log.sourcestrIdentifier for the log source (log family) of this record.
loglevelLogLevelTechnical log severity level.
call.idstr | NoneCall identifier. Not guaranteed to be unique.
userPrincipalNamestr | NoneThe user principal name (sign-in name) in Microsoft Entra ID.
userDisplayNamestr | NoneDisplay name of the user.
startDateTimedatetime | NoneCall start time.
timestampdatetime | NoneCollection timestamp for the log entry (UTC datetime).
durationint | NoneHow long the call was connected, in seconds.
chargefloat | str | NoneAmount of money or cost of the call that is charged to your account.
callTypestr | NoneIndicates whether the call was a PSTN outbound or inbound call and the type of call
currencystr | NoneType of currency used to calculate the cost of the call (ISO 4217).
calleeNumberstr | NoneNumber dialed in E.164 format.
callerNumberstr | NoneNumber that received the call for inbound calls or the number dialed for outbound calls.
usageCountryCodestr | NoneCountry code of the user. For details, see ISO 3166-1 alpha-2.
tenantCountryCodestr | NoneCountry code of the tenant. For details, see ISO 3166-1 alpha-2.
connectionChargefloat | str | NoneConnection fee price.
destinationNamestr | NoneCountry or region dialed.
licenseCapabilitystr | NoneThe license used for the call.
inventoryTypestr | NoneUser’s phone number type, such as a service or toll-free number.
operatorstr | NoneThe telecommunications operator which provided PSTN services for this call.
callDurationSourcestr | NoneThe source of the call duration data.
  • Log source: MSTeams_ServiceAnnouncement
NameTypeDescription
servicestr | NoneAffected service
log.sourcestrIdentifier for the log source (log family) of this record.
loglevelLogLevelTechnical log severity level.
timestampdatetime | NoneCollection timestamp (UTC datetime).
startDateTimedatetime | NoneCall start time (UTC datetime).
endDateTimedatetime | NoneEnd time of the service event.
idstr | NoneServiceHealthIssue.id
titlestr | NoneIssue title
classificationstr | NoneServiceHealthClassificationType value
originstr | NoneIssue origin (microsoft/thirdParty/etc.)
impactDescriptionstr | NoneImpact description from the SDK
serviceHealthStatusServiceHealthStatus | NoneServiceHealthStatus value
featurestr | NoneFeature name
featureGroupstr | NoneFeature group
detailsstr | NoneContent of the most recent post
post.typePostType | NonePostType of the most recent post
post.formatBodyType | NoneContentType of the most recent post
  • Log source: MSTeams_CallRecords_StreamDetails
NameTypeDescription
serviceServiceMetadata | NoneBuild metadata attached to the service that produced the log.
log.sourcestrIdentifier for the log source (log family) of this record.
loglevelLogLevelTechnical log severity level.
timestampdatetime | NoneCollection timestamp for the log entry.
stream.idstr | NoneUnique identifier for the stream.
startDateTimedatetime | NoneUTC time when the stream started.
streamDurationSint | NoneDuration of the stream in seconds.
streamDirectionstr | NoneDirection of the stream.
mediaLabelstr | NoneMedia type of the stream (audio, video, screen-sharing).
call.idstr | NoneUnique call identifier.
typestr | NoneCall type and direction.
caller.idstr | NoneIdentifier of the calling endpoint or user.
caller.displayNamestr | NoneDisplay name of the caller.
caller.userPrincipalNamestr | NoneUserPrincipalName (sign-in name) of the caller.
caller.deviceNamestr | NoneName of the caller’s device.
caller.cpuNamestr | NoneCPU information for the caller’s device.
caller.platformstr | NonePlatform of the caller’s client.
caller.productFamilystr | NoneProduct family of the caller’s client.
caller.teamsVersionstr | NoneTeams client version reported by the caller.
caller.isBotboolTrue if the caller endpoint is a Graph service/bot (serviceUserAgent).
caller.botRolestr | NoneGraph ServiceRole of the caller bot (e.g. customBot, voicemail).
caller.botAppIdstr | NoneApplication ID of the caller bot, extracted from userAgent headerValue.
callerNetwork.ipAddressstr | NoneCaller network IP address.
callerNetwork.subnetstr | NoneCaller network subnet.
callerNetwork.reflexiveipAddressstr | NoneCaller reflexive (NAT) IP address.
callerNetwork.relayIPAddressstr | NoneRelay IP address used by the caller if any.
callerNetwork.connectionTypestr | NoneCaller network connection type (wired/wifi/mobile).
callerNetwork.networkTransportProtocolstr | NoneTransport protocol used by the caller’s network.
caller.audio.input.deviceNamestr | NoneCaller audio input device name.
caller.audio.input.driverVersionstr | NoneDriver version for the caller’s audio input device.
caller.audio.input.signalLevelint | NoneSignal level of the caller’s audio input.
caller.audio.input.noiseLevelint | NoneNoise level measured on the caller’s audio input.
caller.audio.output.deviceNamestr | NoneCaller audio output device name.
caller.audio.output.driverVersionstr | NoneDriver version for the caller’s audio output device.
caller.audio.events.cpuInsufficiencyRatiofloat | NoneFraction of the call where the caller’s client reported insufficient CPU for audio processing.
caller.audio.events.inputFailureRatiofloat | NoneFraction of the call with input failures on the caller side.
caller.audio.events.outputFailureRatiofloat | NoneFraction of the call with output failures on the caller side.
caller.audio.events.deviceGlitchRatiofloat | NoneFraction of the call with device glitches on the caller side.
caller.audio.events.lowSpeechToNoiseRatiofloat | NoneFraction of time the caller’s speech-to-noise ratio was low.
caller.audio.events.lowSpeechLevelRatiofloat | NoneFraction of time the caller’s speech level was low.
caller.audio.events.clippingRatiofloat | NoneFraction of audio frames clipped on the caller side.
caller.audio.events.howlingCountint | NoneHowling events count detected for the caller.
caller.audio.events.outputZeroVolumeRatiofloat | NoneFraction of the call where the caller’s output volume was zero.
caller.audio.events.outputMuteRatiofloat | NoneFraction of the call where the caller’s output was muted.
callee.audio.input.deviceNamestr | NoneCallee audio input device name.
callee.audio.input.driverVersionstr | NoneDriver version for the callee’s audio input device.
callee.audio.input.signalLevelint | NoneSignal level of the callee’s audio input.
callee.audio.input.noiseLevelint | NoneNoise level measured on the callee’s audio input.
callee.audio.output.deviceNamestr | NoneCallee audio output device name.
callee.audio.output.driverVersionstr | NoneDriver version for the callee’s audio output device.
callee.audio.events.cpuInsufficiencyRatiofloat | NoneFraction of the call where the callee’s client reported insufficient CPU for audio processing.
callee.audio.events.inputFailureRatiofloat | NoneFraction of the call with input failures on the callee side.
callee.audio.events.outputFailureRatiofloat | NoneFraction of the call with output failures on the callee side.
callee.audio.events.deviceGlitchRatiofloat | NoneFraction of the call with device glitches on the callee side.
callee.audio.events.lowSpeechToNoiseRatiofloat | NoneFraction of time the callee’s speech-to-noise ratio was low.
callee.audio.events.lowSpeechLevelRatiofloat | NoneFraction of time the callee’s speech level was low.
callee.audio.events.clippingRatiofloat | NoneFraction of audio frames clipped on the callee side.
callee.audio.events.howlingCountint | NoneHowling events count detected for the callee.
callee.audio.events.outputZeroVolumeRatiofloat | NoneFraction of the call where the callee’s output volume was zero.
callee.audio.events.outputMuteRatiofloat | NoneFraction of the call where the callee’s output was muted.
callerNetwork.traceRouteHopslist[TraceRouteHopLog]Traceroute hops observed from the caller to the media endpoint.
calleeNetwork.traceRouteHopslist[TraceRouteHopLog]Traceroute hops observed from the callee to the media endpoint.
streamHealthStreamHealthStatusComputed health classification for the stream.
streamHealthCausestr | NonePrimary cause for the stream health classification.
streamHealthCauseDetailsstr | NoneDetailed information about the stream health cause.
averageRoundTripTimeMsint | NoneAverage network round-trip time in milliseconds.
averageJitterMsint | NoneAverage network jitter in milliseconds.
averagePacketLossRatePercentfloat | NoneAverage packet loss rate as a percentage.
averageVideoFrameLossPercentagefloat | NoneAverage percentage of video frames lost.
averageVideoFrameRatefloat | NoneAverage video frames per second.
postForwardErrorCorrectionPacketLossRatefloat | NonePacket loss rate after forward error correction (FEC).
videoCodecstr | NoneCodec name used to encode video for transmission on the network.
callee.idstr | NoneIdentifier of the callee endpoint or user.
callee.displayNamestr | NoneDisplay name of the callee.
callee.userPrincipalNamestr | NoneUserPrincipalName (sign-in name) of the callee.
callee.deviceNamestr | NoneName of the callee’s device.
callee.cpuNamestr | NoneCPU information for the callee’s device.
callee.platformstr | NonePlatform of the callee’s client.
callee.productFamilystr | NoneProduct family of the callee’s client.
callee.teamsVersionstr | NoneTeams client version reported by the callee.
callee.isBotboolTrue if the callee endpoint is a Graph service/bot (serviceUserAgent).
callee.botRolestr | NoneGraph ServiceRole of the callee bot (e.g. customBot, voicemail).
callee.botAppIdstr | NoneApplication ID of the callee bot, extracted from userAgent headerValue.
calleeNetwork.ipAddressstr | NoneCallee network IP address.
calleeNetwork.subnetstr | NoneCallee network subnet.
calleeNetwork.reflexiveipAddressstr | NoneCallee reflexive (NAT) IP address.
calleeNetwork.relayIPAddressstr | NoneRelay IP address used by the callee if any.
calleeNetwork.connectionTypestr | NoneCallee network connection type (wired/wifi/mobile).
calleeNetwork.networkTransportProtocolstr | NoneTransport protocol used by the callee’s network.

If dashboard quality drops while MSTeams_ServiceAnnouncement shows an active incident, investigate Microsoft-side impact before changing local configuration.