Evidence may come from device counters, logs, flow records, packet captures, streaming telemetry, management protocols, synthetic probes, wireless sensors, and cloud control planes.
A monitoring design starts with important services and communication paths, then selects observation points, measures, baselines, and alert thresholds. Teams need synchronized time, known asset ownership, tested data pipelines, and response procedures so a graph change can lead to a useful decision.
Key points
Coverage designMap critical links, devices, virtual networks, cloud services, dependencies, and alternate paths. Monitor both user-facing service outcomes and the infrastructure that supports them.
Signal qualityDocument sampling, polling intervals, retention, expected delay, clock accuracy, sensor health, and collection loss. Test that important events arrive with enough context for diagnosis.
Operations and privacyTune alerts against expected behavior, protect monitoring credentials and platforms, and minimize access to packet content and metadata that can reveal communications, location, or user activity. Authorize and rate-limit active tests, especially on operational technology networks.
Important limitationNo monitoring point provides complete truth. Encryption, asymmetric routing, short-lived resources, unsupported protocols, sampling, overload, and collection failure create blind spots; normal-looking measurements do not prove that a network or application is secure.