Monitoring layers
ICMP tests reachability; SNMP exposes interface counters and device health; Syslog supplies event context; flow data shows traffic relationships.
SNMP
SNMP commonly provides interface status, octet counters, errors, discards, CPU, memory and environmental data. Prefer SNMPv3 where supported.
Syslog
Central Syslog collection preserves link changes, authentication failures, routing events and hardware faults for correlation.
Flow data
NetFlow, IPFIX and equivalents provide traffic summaries for capacity and traffic analysis. They do not replace packet capture when payload-level detail is required.
Baselines
Learn normal utilisation, latency, packet loss, errors and resource consumption before setting aggressive thresholds.
Alert design
Prefer actionable conditions such as sustained packet loss or a failed uplink over noisy one-off events. Suppress related alarms where possible.
Checklist
- Monitor core and WAN availability.
- Collect interface errors, discards and utilisation.
- Collect link, authentication and routing events.
- Monitor hardware health.
- Track STP and topology changes.
- Retain enough history to identify trends.
- Test alert delivery and escalation.
Related tools
Use packet and neighbour analysis when monitoring identifies an issue requiring deeper investigation.