ENGINEERING GUIDE ยท OPERATIONS

Network Monitoring & Observability

Build useful network monitoring with SNMP, Syslog, ICMP, flow data, baselines and actionable alerts.

The important bit: Monitoring should tell you what changed, how much it changed and whether users are affected.

Monitoring layers

ICMP tests reachability; SNMP exposes interface counters and device health; Syslog supplies event context; flow data shows traffic relationships.

SNMP

SNMP commonly provides interface status, octet counters, errors, discards, CPU, memory and environmental data. Prefer SNMPv3 where supported.

Syslog

Central Syslog collection preserves link changes, authentication failures, routing events and hardware faults for correlation.

Flow data

NetFlow, IPFIX and equivalents provide traffic summaries for capacity and traffic analysis. They do not replace packet capture when payload-level detail is required.

Baselines

Learn normal utilisation, latency, packet loss, errors and resource consumption before setting aggressive thresholds.

Alert design

Prefer actionable conditions such as sustained packet loss or a failed uplink over noisy one-off events. Suppress related alarms where possible.

Checklist

  • Monitor core and WAN availability.
  • Collect interface errors, discards and utilisation.
  • Collect link, authentication and routing events.
  • Monitor hardware health.
  • Track STP and topology changes.
  • Retain enough history to identify trends.
  • Test alert delivery and escalation.

Related tools

Use packet and neighbour analysis when monitoring identifies an issue requiring deeper investigation.

Packet Capture Analyser โ†’   LLDP / CDP Neighbour Analyser โ†’