18
Alerting Essentials Nick Kephart, Sr. Director of Product Marketing

ThousandEyes Alerting Essentials for Your Network

Embed Size (px)

Citation preview

Page 1: ThousandEyes Alerting Essentials for Your Network

Alerting Essentials

Nick Kephart, Sr. Director of Product Marketing

Page 2: ThousandEyes Alerting Essentials for Your Network

1

About ThousandEyes

Established and backed by

network experts

Relied on for critical operations by leading enterprises

Recognized as an innovative

new approach

ThousandEyes delivers visibility into every network your organization relies on.

24 of the Fortune 500

Page 3: ThousandEyes Alerting Essentials for Your Network

2

Anatomy of an Alert

Alert Rule 1

Conditions Notifications

Test A Test B Test C

Alert Rule 2

• Email•Webhooks• PagerDuty

• Thresholds• Agents• Rounds

Each Alert Rule has a set of trigger conditions and notification policy

Tests and Alert Rules have a many-to-many relationship

Page 4: ThousandEyes Alerting Essentials for Your Network

3

Network and BGP Alerts

Scenario Test Type Threshold

High loss Network Loss > __%

High latency Network Latency > ___ms60ms (US)120ms (trans-Atlantic)200ms (trans-Pacific)

Prefix Hijacking BGP Origin ASN not in ___

Peering Changes, Route Flaps BGP Path Changes > 1 Reachability < 100%

DDoS Mitigation Activation BGP Origin ASN in ___Prefix not in ___

Prepending Errors BGP Next Hop ASN not in ___

Page 5: ThousandEyes Alerting Essentials for Your Network

4

Web and DNS Alerts

Scenario Test Type Threshold

Slow DNS resolution/DDoS HTTP DNS Time ≥ ___ms

Long response time HTTP Response Time ≥ ___ms

Slow throughput HTTP Throughput ≤ ___kBps

Long page load time Page Load Page Load Time > __ms

Component load time (CDN, javascript, ads, embeds)

Page Load Domain in ___Total Time ≥ ___ms

Slow transaction, shopping cart Transaction Duration ≥ ___ms

Slow DNS resolution/DDoS DNS Server Resolution Time ≥ ___ms

DNS Hijacking, Cache Poisoning DNS ServerDNS Trace

Mapping is not in ___

Page 6: ThousandEyes Alerting Essentials for Your Network

5

Scope by Component or Geography

Scope by geo

Scope by domain

Page 7: ThousandEyes Alerting Essentials for Your Network

6

Scope by Network or Device

Scope by rDNS, IP

Scope by ASN

Page 8: ThousandEyes Alerting Essentials for Your Network

7

Alert Conditions: Reducing False Positives

• Define threshold and operator• Response time, page load time, latency can auto-set threshold

• Conditional AND, OR for multiple thresholds• Require multiple agents to trigger

• NEW! Percentage of agents in the test• Agents with ‘Local agent issues’ are excluded

• Require consecutive rounds to trigger

Page 9: ThousandEyes Alerting Essentials for Your Network

8

Works out of the box• Select list of emails to notify• Customize the email message• Optionally send an email when alert clears

Configuring Notifications

Most configurable and extensible• HTTP POST request with alert payload • Sent to an endpoint of your choice• Use to build custom workflows (chat, ticketing)

Email

Webhooks

Popular incident management integration• Configure escalation policy, on-call schedule• Alert via email, mobile push, SMS, phone• Integrate with notifications from other services

PagerDuty

Page 10: ThousandEyes Alerting Essentials for Your Network

9

Additional Resources

• Reducing Alert Fatigue– https://blog.thousandeyes.com/top-5-prescriptions-for-alert-fatigue/

• Alerts by Type– https://blog.thousandeyes.com/proactive-bgp-alerting/– https://blog.thousandeyes.com/tips-instrumenting-dns-alerts/– https://blog.thousandeyes.com/alerting-on-network-performance/– https://blog.thousandeyes.com/alerting-by-geography-network-and-device/

• PagerDuty– https://blog.thousandeyes.com/thousandeyes-pagerduty-integration/– https://support.thousandeyes.com/entries/58264440-PagerDuty-Integration– http://www.pagerduty.com/docs/guides/thousandeyes-integration-guide/

• Webhooks– https://support.thousandeyes.com/entries/58631344-Using-Webhooks-server-sample-code-

included-

Page 11: ThousandEyes Alerting Essentials for Your Network

10

Demo

Page 12: ThousandEyes Alerting Essentials for Your Network

11

Configure Alerts on a Test

Choose from default alerts

Or customize your own alert rules

Page 13: ThousandEyes Alerting Essentials for Your Network

12

Your Alert RulesTests with each rule

Create your own defaults

Expand to edit or

duplicate

Page 14: ThousandEyes Alerting Essentials for Your Network

13

Create a New Alert RuleSelect type and see

compatible tests

Choose tests to add to

Add additional thresholds

Configure conditions

Page 15: ThousandEyes Alerting Essentials for Your Network

14

Configure Notifications

Add list of emails

Configure PagerDuty

Configure Webhooks

Page 16: ThousandEyes Alerting Essentials for Your Network

15

Component-Specific Alerts

Customize by components

Duplicate rule

Page 17: ThousandEyes Alerting Essentials for Your Network

16

Active Alerts and Alert HistorySelect time range for past 90 days

Search by test, alert type, alert rule, status

Expand to see details

and test link

Page 18: ThousandEyes Alerting Essentials for Your Network

See what you’re missing.

Watch the webinar

www.thousandeyes.com/webinars/alerting