Networking
The full domain, and the other capabilities within it.
Know that something is wrong before the first user calls.
Network monitoring is discovery, telemetry collection, thresholding, alerting and reporting. Done properly it answers three questions: is it up, is it healthy, and is it getting worse.
The failure mode is not missing data, it is unread alerts. A system that pages on every interface flap trains people to ignore it, and by the time it reports something real nobody is looking. Tuning is the work.
If more than one of these is true, this is usually the right place to start.
| Deliverable | What it contains |
|---|---|
| Monitoring inventory | Every device and interface in scope, with coverage stated as a figure and the gaps named. |
| Baseline and thresholds | Observed normal per metric and the thresholds derived from it, including time-of-day variation. |
| Alert policy | Severity, routing, escalation and suppression rules — with what is deliberately not alerted on, and why. |
| Dashboards | An operational view for diagnosis and a trend view for capacity, each built for its audience. |
A reference, not a template. Your estate decides which parts apply and in what order they arrive.
Targets are agreed with you before the work starts, and reported against for its duration.
Most organisations do. The difference is usually coverage and tuning: devices never added, thresholds left at defaults, and alerts routed to a channel nobody watches. The tool is rarely the problem.
Baseline first, then thresholds from the baseline; suppress the dependent alerts that follow a single root cause; and delete alerts nobody has acted on in six months. That last one is unpopular and it is where most of the noise lives.
Streaming gives higher resolution and scales better on modern platforms; polling still covers the older devices that will be in your estate for years. Most designs are a mix, and the mix is decided by what your hardware supports.
It should. Monitoring that stops at the data centre leaves the parts of the path users actually complain about unmeasured, which is why branch and cloud connectivity are in scope from the start.
Selectively. Operational telemetry and security telemetry overlap but are not the same, and sending everything to a SIEM is how licence costs get out of hand. The design states what crosses over and why.
Yes, as a managed service. Monitoring is one of the capabilities where consistency matters more than intensity, and where an out-of-hours rota is difficult to sustain with a small internal team.
The full domain, and the other capabilities within it.
Switching, routing and structured cabling designed for the traffic you will have in five years, not the traffic you had when the building opened.
RF design, controller policy and validation surveys for wireless that holds up under density — measured on site, not predicted from a floor plan.
The fastest way to a useful answer is a short, scoped look at what you already have.