User Guide Functional Overview Requirements Architecture System Installation NetEye Additional Components Installation Setup The neteye Command Director NetEye Self Monitoring Tornado Business Service Monitoring IT Operation Analytics - Telemetry Geo Maps NagVis Audit Log Shutdown Manager Reporting ntopng Visual Monitoring with Alyvix Elastic Stack IT Operations (Command Orchestrator) Asset Management Service Level Management Cyber Threat Intelligence - SATAYO NetEye.Cloud Solution Monitoring Business Service Monitoring Asset Management SOC System Administrator SOC Attacker Centric Cyber Threat Intelligence - SATAYO NetEye Update & Upgrade Backup and Restore How To NetEye Extension Packs Troubleshooting Security Policy Glossary
module icon Monitoring
Monitoring with NetEye.Cloud Monitored Objects Finding and Filtering Hosts Exporting Monitoring Data Viewing Host and Service Details Organizing with Groups Tactical Overview Problems View Dashboard Typical Daily Interactions Scheduled Downtime Notifications and Alerts VMD
NetEye.Cloud Solution Monitoring Business Service Monitoring Asset Management SOC System Administrator SOC Attacker Centric Cyber Threat Intelligence - SATAYO Introduction to NetEye Monitoring Business Service Monitoring IT Operation Analytics Visualization Network Visibility Log Management & Security Orchestrated Datacenter Shutdown Application Performance Monitoring User Experience Service Management Service Level Management & Reporting Requirements for a Node Cluster Requirements and Best Practices Kubernetes Networking NetEye Satellite Requirements TCP and UDP Ports Requirements Additional Software Installation Introduction Single Node Cluster Kubernetes NetEye Master Master-Satellite Architecture Underlying Operating System Acquiring NetEye ISO Image Installing ISO Image Single Nodes and Satellites Cluster Nodes Configuration of Tenants Satellite Nodes Only Nodes behind a Proxy Additional NetEye Components Satellites Nodes only Verify if a module is running correctly Accessing the New Module Cluster Satellite Security Backup and Restore Identity and Access Management External Identity Providers Configure federated LDAP/AD Emergency Reset of Keycloak Configuration Keycloak Hostname Configuration Advanced Configuration Roles Single Page Application in NetEye Module Permissions and Single Sign On Within NetEye Importing User Federation Groups inside another Group Importing OIDC IdP Groups inside another Group Resource Tuning Advanced Topics Basic Concepts & Usage Advanced Topics Monitoring Environment Templates Monitored Objects Import Monitored Objects Data Fields Deployment Icinga 2 Agents Configuration Baskets Dashboard Monitoring Status Integration with Elasticsearch VMD Permissions Notifications Jobs API Configuring Icinga Monitoring Retention Policy NetEye Self Monitoring Concepts Collecting Events Add a Filter Node WHERE Conditions Iterating over Event fields Retrieving Payload of an Event Extract Variables Create a Rule Tornado Actions Test your Configuration Export and Import Configuration Example Under the hood Development Retry Strategy Configuration Thread Pool Configuration API Reference Configure a new Business Process Create your first Business Process Node Importing Processes Operators The ITOA Module Configuring User Permissions Telegraf Metrics in NetEye Telegraf Configuration Telegraf on Monitored Hosts Visualizing Dashboards Customizing Grafana The NetEye Geo Map Visualizer Map Viewer Configuring Geo Maps NagVis Audit Log Overview Shutdown Manager user Shutdown Manager GUI Shutdown Commands Advanced Topics Overview User Role Management Cube Use Cases ntopng and NetEye Integration Permissions Retention Advanced Topics Overview User Roles Install Alyvix Core Install Alyvix Service Nodes RDP Client Building Tools Editor: Interface Overview Editor: Script Building Editor: Managing Scripts Designer: Interface Overview Designer: Interface Options Designer: Component Tree Selector: Interface Overview Test Case Management Dashboard Use Cases Overview Architecture Authorization Kibana Elasticsearch Cluster Elasticsearch Configuration Replicas on a Single Node Elasticsearch Performance tuning Overview Enabling El Proxy Sending custom logs to El Proxy Configuration files Commands Elasticsearch Templates and Retentions El Proxy DLQ Blockchain Verification Handling Blockchain Corruptions El Proxy Metrics El Proxy Security El Proxy REST Endpoints Agents Logstash Rsyslog Elastic APM Elastic RUM Multitenant OpenTelemetry Collector Elastic XDR Overview Authorization in the Command Orchestrator Module Configuring CLI Commands Executing Commands Overview Permissions Installation Plugins Single Tenancy Multitenancy Communication through a Satellite Asset collection methods Display asset information in monitoring host page Overview Customers Availability Event Adjustment Outages Resource Advanced Topics Introduction The Intelligence We Produce Mitre Attack Coverage Getting Started Settings SATAYO Items Intelligence Requirements Managed Service Request Form FAQ Changelog SATAYO Community NetEye.Cloud as a SaaS solution NetEye.Cloud Subscription Base Concepts Authentication Options Authentication via IdP Group Claims for Authorization Management Authentication via Microsoft Entra ID Authorization Navigating the UI Monitoring with NetEye.Cloud Monitored Objects Finding and Filtering Hosts Exporting Monitoring Data Viewing Host and Service Details Organizing with Groups Tactical Overview Problems View Dashboard Typical Daily Interactions Scheduled Downtime Notifications and Alerts VMD Business Service Monitoring Business Process Logic Business Process View Asset Management in NetEye.Cloud Automatic Inventory Collection Software & License Management Contract & Supplier Management Change & Lifecycle Management SOC System Administrator (AdS) Access to NetEye and Elastic Elastic Dashboards Elastic Discover Elastic Alerts Elastic Rules Introduction to SOC Attacker Centric Service Description NetEye SIEM About SATAYO Threat Intelligence and Security Operations How SATAYO works MITRE ATT&CK Coverage Dashboard SATAYO Findings SATAYO REST API SaaS & Managed Mode Before you start Update Procedure Single Node Upgrade from 4.49 to 4.50 Cluster Upgrade from 4.49 to 4.50 Satellite Upgrade from 4.49 to 4.50 DPO machine Upgrade from 4.49 to 4.50 Create a mirror of the RPM repository Sprint Releases Feature Troubleshooting Backup and Restore Tornado Networking Service Management - Incident Response IT Operation Analytics - Telemetry Identity Provider (IdP) Configuration NetEye Cluster on Microsoft Azure NetEye Cluster on AWS Introduction to NEP Getting Started with NEPs Online Resources Obtaining NEP Insights Available Packages Advanced Topics NEP Updates & Upgrades Setup Configure swappiness Restarting Stopped Services Enable stack traces in web UI How to access standard logs Director does not deploy when services assigned to a host have the same name How to enable/disable debug logging Activate Debug Logging for Tornado Modules/Services do not start Sync Rule fails when trying to recreate Icinga object How to disable InfluxDB query logging Managing an Elasticsearch Cluster with a Full Disk Some logs are not indexed in Elasticsearch Elasticsearch is not functioning properly Reporting: Error when opening a report Debugging Logstash file input filter Bugfix Policy Reporting Vulnerabilities Cyber Resilience Act Compliance Glossary

Typical Daily Interactions

After the NetEye.Cloud Support staff has completed your system configuration and monitoring has begun, you will most likely use NetEye.Cloud when:

  • You need to make a configuration change, like adding or removing hosts, services or contacts, in which case you’ll use the Support Portal

  • You receive a notification, so you’ll want to quickly find out which host or service is down and begin remediation

  • You want to proactively find problems before they happen by studying trends in Operations Analytics

NetEye.Cloud provides you with a number of tools to make these latter two tasks both more efficient and more effective.

Spotting Problems with the Problem View

The Problems View collects in a single place all problems of a particular type, to help you solve multiple cases with a triage approach. Within each view, each host and service shown links to its Details panel.

  • Host Problems: This view shows a list of all hosts in the Down state. Each row shows the host’s name, state, time in down state, and the check result that lead to that state:

    Screenshot of the host problems view

    Fig. 202 The Host Problems view

    The hosts are sorted by severity by default, but can also be sorted by current and last state change.

  • Service Problems: This view is similar to the Host Problems view, but shows services and their more detailed states and check results. In addition to the sorting options for hosts, services can also be sorted by the host they run on.

  • Service Grid: This view displays a matrix representation with hosts on one side and services on the other. By default, it lists all hosts with at least one impacted service, and all services on a host with at least one impacted service. The boxes in the grid are color coded for state, everything is linkable. The grid can be rotated using the box at the top left.

  • Current Downtimes: Lists all hosts that are currently under preventative maintenance. Shows the amount of time remaining before the specified restoration date for the host, and who scheduled the downtime.

    Screenshot of the downtime problems view

    Fig. 203 The Downtime Problems view

For each view type you can adjust the filters to select a subset of the monitored objects to be displayed.

Adding Comments to a Monitored Object

As you work with hosts and services, you may want to annotate them with short comments, which will remain visible every time you view the host or service again, and which you can delete later when they’re no longer relevant.

Some types of comments you may find helpful are:

  • Reminders to yourself to do something the next time you see this monitored object

  • Creating a record when a problem repeats, to help you diagnose it later

  • Messages to fellow sysadmins about plans for specific hosts or services

  • Notes describing thoughts hard to capture in numbers, like relative importance

You can add comments directly from a monitored object view as shown here:

Adding a comment directly to a monitored object

Fig. 204 Adding a comment directly to a monitored object

Note

The NetEye.Cloud Support team can also add or delete comments in bulk for you using filterable conditions with the Icinga 2 add-comment API action.

Once added, a comment can be viewed by going to the details panel for that host. To see all comments and be able to filter them according to your own criteria, go to dedicated view at Overview > Comments. Comments remain until deleted.

Acknowledging an Alert

When you’ve received a notification, you may want to quickly let others know that you’re aware of the alerted incident and are working on a fix. You can explicitly do this for a monitored object with an acknowledgement, which will send a notification message to other users or admins.

By default an acknowledgement will be removed if the host/service recovers (OK/Up) or a state change occurs. To keep an acknowledgement there until an issue moves from partially recovered to completely recovered, you can use the sticky parameter.

Like comments, the NetEye.Cloud Support team can also add or delete comments in bulk for you using filterable conditions with the Icinga 2 acknowledge-problem command.

Investigating Past Monitoring Events

If you haven’t arrived at NetEye because of a notification (for instance you do a daily morning check) the first step is almost always to look at the Dashboard to see if anything important is going on.

But suppose you’ve just come back from a day or two off and you want to see what’s happened in that time. The History section contains views that show you what important events have occurred, with a customizable filter:

  • Event Overview: All the state transitions of monitored objects, showing the new state type, when it occurred, and the object affected

    Viewing the Event Overview in the History module

    Fig. 205 Viewing the Event Overview in History

  • Notifications: All the notifications that were sent in a given time range, beginning with the most recent

    Viewing the Notification log in the History module

    Fig. 206 Viewing the Notification log in History

Investigating More Deeply

When NetEye receives the results of performance-based monitoring checks, it stores them in a database in order to display that historical data for your hosts and services.

Over extended periods of time, or for the results of very frequent checks, it’s not enough to see just the raw data in text form that’s then displayed by Icinga 2. Similarly, the graphs displayed in the Host and Service Details panels is in graph form, which is very helpful to quickly see simple patterns in recent data.

IT Operations Analytics on the other hand is like a set of supercharged graphs: it allows for interactivity in multiple ways, such as in setting the time range of what’s visible, choosing a subset of data streams that are visible at any given moment, and computing functions involving one or more data streams.

NetEye uses Grafana to store and display interactive graphs using time-series data, with highly customizable features that can be either added from pre-existing dashboard templates, or that you yourself can create using Grafana’s built-in graphing language.

Screenshot of an interactive ITOA graph on time-series data

Fig. 207 An interactive ITOA graph showing time-series data