Project · Monitoring
Network and server monitoring in Elastic Stack
Several thousand devices under constant watch: one dashboard that shows the state of the network in 30 seconds.
Foundation
Monitoring you actually own
The whole monitoring environment runs on-premise on the Basic licence - no subscription fees and no infrastructure data leaving the company.
This is not an off-the-shelf box with a per-device licence. We assemble the Elastic Stack around one specific network: the data sources, the processing and the views that are genuinely used.
Collection
Where the data comes from
We collect data where it is produced. Logstash takes SNMP from network devices and reads the system syslog. Filebeat picks up logs of every kind, Winlogbeat the Windows event logs, and Metricbeat the performance metrics.
It all lands in one store in Elasticsearch. A switch entry, a Windows server event and a machine metric end up side by side - instead of sitting in four separate tools you have to jump between.
The operational view
One screen, an answer in 30 seconds
It is all tied together by a single complete dashboard - an instant view of the most important nodes on the network, showing link saturation and node response times.
The goal is simple and measurable: 30 seconds after opening that screen you know whether anything is happening on the network. No logging into devices one by one, no guessing where to start.
Alerting
Alerts that reach a human
Monitoring without alerting is just a pretty chart. Thresholds watch resources and selected errors in the logs, and the notification goes where somebody will actually see it.
Resources under threshold
Disk usage, CPU and memory - the alert fires before space or power runs out.
Errors in the logs
Log analysis for selected errors, not just collecting data.
E-mail, SMS and chat
The notification lands where the team actually looks.
