User Guide Functional Overview Requirements Architecture System Installation NetEye Additional Components Installation Setup The neteye Command Director NetEye Self Monitoring Tornado Business Service Monitoring IT Operation Analytics - Telemetry Geo Maps NagVis Audit Log Shutdown Manager Reporting ntopng Visual Monitoring with Alyvix Elastic Stack IT Operations (Command Orchestrator) Asset Management Service Level Management Cyber Threat Intelligence - SATAYO NetEye Update & Upgrade How To NetEye Extension Packs Troubleshooting Security Policy Glossary
module icon Functional Overview
Introduction to NetEye Monitoring Business Service Monitoring IT Operation Analytics Visualization Network Visibility Log Management & Security Orchestrated Datacenter Shutdown Application Performance Monitoring User Experience Service Management Service Level Management & Reporting
Functional Overview Requirements Architecture System Installation NetEye Additional Components Installation Setup The neteye Command Introduction to NetEye Monitoring Business Service Monitoring IT Operation Analytics Visualization Network Visibility Log Management & Security Orchestrated Datacenter Shutdown Application Performance Monitoring User Experience Service Management Service Level Management & Reporting Requirements for a Node Cluster Requirements and Best Practices NetEye Satellite Requirements TCP and UDP Ports Requirements Additional Software Installation Introduction Single Node Cluster NetEye Master Master-Satellite Architecture Underlying Operating System Acquiring NetEye ISO Image Installing ISO Image Single Nodes and Satellites Cluster Nodes Configuration of Tenants Satellite Nodes Only Nodes behind a Proxy Additional NetEye Components Single Node Cluster Node Satellites Nodes only Verify if a module is running correctly Accessing the New Module Cluster Satellite Security Identity and Access Management External Identity Providers Configure federated LDAP/AD Emergency Reset of Keycloak Configuration Advanced Configuration Authorization Resources Tuning Advanced Topics Basic Concepts & Usage Advanced Topics Monitoring Environment Templates Monitored Objects Import Monitored Objects Data Fields Deployment Icinga 2 Agents Configuration Baskets Dashboard Monitoring Status VMD Permissions Notifications Jobs API Configuring Icinga Monitoring Retention Policy NetEye Self Monitoring 3b Concepts Collecting Events Add a Filter Node WHERE Conditions Iterating over Event fields Retrieving Payload of an Event Extract Variables Create a Rule Tornado Actions Test your Configuration Export and Import Configuration Example Under the hood Development Retry Strategy Configuration Thread Pool Configuration API Reference Configure a new Business Process Create your first Business Process Node Importing Processes Operators The ITOA Module Configuring User Permissions Telegraf Metrics in NetEye Telegraf Configuration Telegraf on Monitored Hosts Visualizing Dashboards Customizing Performance Graph The NetEye Geo Map Visualizer Map Viewer Configuring Geo Maps NagVis 3b Audit Log 3b Overview Shutdown Manager user Shutdown Manager GUI Shutdown Commands Advanced Topics Overview User Role Management Cube Use Cases ntopng and NetEye Integration Permissions Retention Advanced Topics Overview User Roles Nodes Test Cases Dashboard Use Cases Overview Architecture Authorization Elasticsearch Overview Enabling El Proxy Sending custom logs to El Proxy Configuration files Commands Elasticsearch Templates and Retentions El Proxy DLQ Blockchain Verification Handling Blockchain Corruptions El Proxy Metrics El Proxy Security El Proxy REST Endpoints Agents Logstash Elastic APM Elastic RUM Log Manager - Deprecated Overview Authorization in the Command Orchestrator Module Configuring CLI Commands Executing Commands Overview Permissions Installation Single Tenancy Multitenancy Communication through a Satellite Asset collection methods Display asset information in monitoring host page Overview Customers Availability Event Adjustment Outages Resource Advanced Topics Introduction Getting Started SATAYO Items Settings Managed Service Mitre Attack Coverage Changelog Before you start Update Procedure Single Node Upgrade from 4.41 to 4.42 Cluster Upgrade from 4.41 to 4.42 Satellite Upgrade from 4.41 to 4.42 DPO machine Upgrade from 4.41 to 4.42 Create a mirror of the RPM repository Sprint Releases Feature Troubleshooting Tornado Networking Service Management - Incident Response IT Operation Analytics - Telemetry Identity Provider (IdP) Configuration Introduction to NEP Getting Started with NEPs Online Resources Obtaining NEP Insights Available Packages Advanced Topics Upgrade to NetEye 4.31 Setup Configure swappiness Restarting Stopped Services Enable stack traces in web UI How to access standard logs Director does not deploy when services assigned to a host have the same name How to enable/disable debug logging Activate Debug Logging for Tornado Modules/Services do not start Sync Rule fails when trying to recreate Icinga object How to disable InfluxDB query logging Managing an Elasticsearch Cluster with a Full Disk Some logs are not indexed in Elasticsearch Elasticsearch is not functioning properly Reporting: Error when opening a report Debugging Logstash file input filter Bugfix Policy Reporting Vulnerabilities Glossary 3b

Introduction to NetEye

Welcome to the NetEye product documentation.

The structure of this user guide follows that of the various modules provided in the NetEye distribution, and contains both conceptual and practical information on how to use NetEye system for many purposes you’ll find in the Introduction.

Product Overview

NetEye is a comprehensive solution for unified monitoring of your network and infrastructure. Based on Open Source tools, its functionalities allow monitoring of disparate resources: IoT and IIoT devices, remote infrastructure, business services, company assets.

The entire solution is licensed under open source licenses, with the GPLv3 Open Source License being the most used. Continuous improvements, coming from both the community and from Würth Phoenix, are integrated into NetEye to provide added business value to widely-used open source projects.

Real-time dashboards built with the data collected over time, reporting solutions, a powerful tool for complex event management and log analysis, and network traffic analysis complement NetEye’s monitoring features. A deeper description of the NetEye features can be found in the upcoming sections.

NetEye builds around Icinga and Icinga Web 2. Most concepts and set ups valid for the latter are also valid in NetEye. Icinga’s modular architecture allows to reuse all of its modules within NetEye, while NetEye’s team continuously develops new modules and seamlessly integrates them within the existent infrastructure.

Intended Use

NetEye is a platform designed to perform a wide range of monitoring activities by means of the software natively developed by the NetEye team, or software integrated with the system. A set of modules available within NetEye allows to provide a full spectrum of monitoring service, depending on your business need.

Below you will find a list of NetEye’s core functionalities, grouped in categories, that will help you construct your monitoring solution with NetEye based on your needs.

You can learn more about the capabilities of NetEye in dedicated chapters of NetEye’s Functional Overview below.

Releases and Latest News

NetEye development cycle lasts two months and at the beginning of the even months, a new NetEye release is published and available for installation. After the release has taken place, it is referred to as Current NetEye release, i.e. the latest stable release of a product available to be installed by a customer.

In the NetEye Guide, ‘current’ label indicates the version of the userguide which respectively corresponds the current NetEye release.

Next version, in its turn, corresponds the next coming version of NetEye, which is currently in development. The development cycle ends up with a feature freeze two weeks prior to the official NetEye release, which gives us the opportunity to test out the scope.

Within this two-week period of time the development of an even newer NetEye version starts, which can be referred to as Alpha. Hence, appearance of an ‘Alpha’ version in the userguide indicates that the development cycle for a new NetEye version has started.

A list of the new and changed functionalities in NetEye is compiled for each new public release; it can be found on NetEye’s blog, in the release notes category.

Moreover, the NetEye’s blog features also a series of posts about bug fixes, released as soon as a bug has been corrected and the fix has been released. Each post contains an explanation of the bug and, most important, the list of package(s) that contain the fix.

NetEye Core & Components

All the funtionality provided by NetEye is delivered to the users within NetEye Modules.

The Modules that are shipped with the standard NetEye image build NetEye Core. All other Modules are called NetEye Components and can be installed on demand. More information can be found in section Additional NetEye Components.

NetEye Core

NetEye is a flexible solution which allows you to build your own monitoring experience based on the preferred functionality from the scope the product has to offer.

Since all the NetEye functionality is delivered to the users within NetEye Modules, you can choose between acquiring standard NetEye image or customize your experience with extended functionalities.

The Modules that are shipped with the standard NetEye image build NetEye Core.

NetEye Core is the set of most commonly used functionalities offered by the platform, including monitoring, visualization (with dashboards and maps), configuration, reporting, and event handling.

Follow NetEye installation guide to start exploring NetEye Core functionality. You can also learn more about the modules that build the Core in the Core Modules chapters.

Additional Feature Modules

In order to customize your monitoring experience with NetEye, you can go beyond the feature scope the NetEye Core has to offer as a basis.

The NetEye modular architecture supports the installation of additional Feature Modules that extend the NetEye Core functionalities. This separation allows to customize NetEye in order to address specific customer needs.

Each NetEye Feature Module can be purchased separately from NetEye Core and adds a specific set of features. In some cases, the Feature Module contains Open Source, GPL-licensed software. In cases like these the software can be used even after the paid subscription has expired or can even be installed independently.

However, the software is considered as a customisation and is entirely not supported.

You can learn more about installing additional NetEye Feature Modules in our installation guide.