Network Monitoring — Transcript
Full transcript
- 0:04hello there
- 0:05good day on this video lecture
- 0:09i'm going to discuss network monitoring
- 0:15okay so for
- 0:16the topic outline so on this video i'll
- 0:19be covering the introduction about
- 0:21network monitoring the monitor
- 0:25types of information
- 0:28network monitoring configurations
- 0:31network monitoring methods performance
- 0:35monitoring
- 0:36this includes performance indicators
- 0:39performance monitoring functions
- 0:42fault monitoring problems
- 0:45of fault monitoring and fault monitoring
- 0:49functions
- 0:50and the accounting monitoring so this is
- 0:54part
- 0:54and continuation of the f-cups that we
- 0:57have
- 0:58discussed on the previous video on the
- 1:00network management overview
- 1:03so let's start so
- 1:07network monitoring is basically
- 1:09concerned
- 1:10with observing and
- 1:14analyzing the status and behavior of the
- 1:16end systems
- 1:18so when you say and systems this
- 1:20pertains to computers
- 1:21servers printers right
- 1:25um voip these are the components that
- 1:28can be found on the end segment of the
- 1:30network
- 1:31okay so also intermediate systems
- 1:35so intermediate systems pertains to
- 1:38the devices that is located are situated
- 1:40between
- 1:41the end systems or end devices so this
- 1:44includes
- 1:45uh routers switches firewalls
- 1:48okay so those are intermediate systems
- 1:51layer two or layer three switches
- 1:54okay and sub networks so pertaining to
- 1:57the vlans
- 1:58that make up the network to be managed
- 2:01okay so what are the issues in
- 2:05network monitoring okay so first
- 2:08is what to monitor so a systems
- 2:11administrator
- 2:13so one of our duties and responsibility
- 2:16of course is to monitor the network
- 2:20okay but what do we have to monitor in
- 2:23the network
- 2:24so define what is to be monitored okay
- 2:28so next would be how do we how do we
- 2:31monitor it
- 2:32how to obtain information from the
- 2:34managed resources
- 2:36when you say managed resources this
- 2:38pertains to the managed objects
- 2:40okay and this managed objects are
- 2:43the ant systems intermediate systems and
- 2:45the subnets
- 2:47okay and
- 2:51what to do with the monitor information
- 2:52so how the monitor information is used
- 2:55in various management functional levels
- 2:58so basically
- 2:59on what to monitor being a systems
- 3:01administrator so what do we want to
- 3:03monitor on the network
- 3:04so basically we want to monitor the
- 3:06performance of the network
- 3:08the behavior of the network right the
- 3:12activities on the network okay
- 3:16so we are not monitoring
- 3:19the persons or the personal involved
- 3:22within the organizations but their
- 3:23activities over the infrastructure
- 3:26okay and how do we monitor it so
- 3:29basically we are using a third party
- 3:30software
- 3:31okay so we have a lot of applications
- 3:33that we can use
- 3:35for monitoring monitoring the network
- 3:36monitoring the
- 3:38bandwidth monitoring the throughput so
- 3:41basically in here
- 3:43we are using mostly application software
- 3:45or programs
- 3:47okay and what do we do with the monitor
- 3:50information so after gathering all those
- 3:52information
- 3:53after the observation and analysis so
- 3:57what do we do with this information okay
- 4:00so basically this information can be
- 4:02used
- 4:04for future planning okay so maybe
- 4:08at the current situation you are
- 4:09encountering some difficulties or
- 4:11problems regarding your network
- 4:13and the result of your observation and
- 4:15analysis
- 4:16might help you improve the performance
- 4:18of the network in the future
- 4:21okay so basically what to do with the
- 4:23monitor information is
- 4:24that would help you the team and
- 4:27organization
- 4:28to improve the service provided on the
- 4:31infrastructure
- 4:33okay next
- 4:36monitor types of information okay so
- 4:39this talks about
- 4:40the static information so when you say
- 4:43static information
- 4:44these are the information that could be
- 4:46hardly changes
- 4:47okay so current configuration
- 4:50information so example if we're talking
- 4:52about the router
- 4:53so the number and identification of
- 4:55ports on the router is considered to be
- 4:56static information
- 4:58okay so the number of lan or the
- 5:01internet interfaces on the router
- 5:04is considered to be static information
- 5:07also if we're talking about these
- 5:09switches the number of ports available
- 5:11on the switch
- 5:12is considered to be static information
- 5:15all right so next would be dynamic
- 5:19information
- 5:20so dynamic information changes
- 5:23frequently
- 5:24okay so information related to events in
- 5:27the network
- 5:28so the change of state of a device
- 5:32for instance the router serial 0 0
- 5:350 goes down and then after a second it
- 5:38went up
- 5:39okay so this our dynamic information the
- 5:41change of state from
- 5:42on to off or from up down
- 5:45these are considered to be dynamic
- 5:47information okay
- 5:49so the transition or transmission and
- 5:51reception of packets
- 5:53are considered to be dynamic information
- 5:56okay so this would
- 5:57uh basically depend on the number of
- 6:00packet that traverses over the
- 6:02network so this is considered to be
- 6:04dynamic
- 6:05or ever changing information okay so
- 6:08this would depend
- 6:09on the number of packet reverses over
- 6:12the
- 6:13infrastructure okay so the next one
- 6:16would be
- 6:17statistical the statistical information
- 6:21was derived from
- 6:23dynamic information okay so example are
- 6:26the and
- 6:26the average number of packets
- 6:28transmitted per unit time
- 6:30so the number of packets dropped
- 6:33from the network the number of packets
- 6:36um
- 6:37prohibited and denied by the access
- 6:40lists
- 6:41okay so configured on the router so
- 6:43these are all
- 6:44statistical information okay
- 6:48so next would be the organization of the
- 6:51management information base
- 6:53so when you say mib or the management
- 6:56information base
- 6:57this is basically the database
- 6:59containing the information
- 7:01pertinent to network management
- 7:04and organic organization of the mib
- 7:08includes of course the statistical
- 7:11database
- 7:12the dynamic database and this the
- 7:14statistical or the static sorry static
- 7:16database in here
- 7:18okay so again when we say statistical
- 7:21these are
- 7:22information derived from dynamic
- 7:25okay and static database these are the
- 7:28configurations
- 7:29fixed on the devices okay
- 7:33so this includes
- 7:36this components here okay the
- 7:39configuration database the sensor
- 7:41database
- 7:42for the dynamic databases so you've got
- 7:45the event the state
- 7:46okay like what we have mentioned earlier
- 7:49and the statistical database are of
- 7:50course
- 7:52the the statistics or the data derived
- 7:55from
- 7:55dynamic databases all right
- 7:58so the mib is basically the storage
- 8:02of the configured information on the
- 8:05device
- 8:08okay so let's talk about monitoring
- 8:10system components
- 8:11so the first one would be monitoring
- 8:13application
- 8:15we have mentioned earlier on how do we
- 8:17monitor or how do we come up
- 8:19with the information okay so derived
- 8:23from the
- 8:23infrastructure okay so
- 8:26or what tools are we gonna use to
- 8:29capture the information or the data
- 8:32or the packet that we need during the
- 8:34monitoring so of course
- 8:36we will be using the monitoring
- 8:38application
- 8:39so monitoring application includes the
- 8:42functions of monitoring
- 8:44that are visible to the user okay
- 8:47example performance
- 8:49fault accounting so these are all
- 8:52functions of monitoring that is or that
- 8:55are visible to the end users
- 8:58okay so basically performance you'll see
- 9:00it and you feel it
- 9:02okay so by by using tools
- 9:06like um the speed test
- 9:09okay so for the internet connectivity so
- 9:11we can see and compare
- 9:13okay so having a benchmark the
- 9:15performance of the network
- 9:18all right so aside from monitoring
- 9:20application we also have the
- 9:22manager function so manager function
- 9:25performs the basic monitoring function
- 9:28of retrieving information
- 9:32okay so from the previous discussion on
- 9:34the management
- 9:36overview or the network management
- 9:38overview we've talked about
- 9:40the manager agent paradigm
- 9:43all right so on the manager agent
- 9:47paradigm so we've talked about the
- 9:49duties and responsibilities or the
- 9:51function of
- 9:51each okay where in the manager is
- 9:54basically the application residing on
- 9:57the server where the administrator is in
- 10:00okay
- 10:01and the agent is basically
- 10:05uh the operating systems or the software
- 10:09residing on the managed object that
- 10:12captures
- 10:12information locally and for word data
- 10:16on the manager okay so the
- 10:20manager function you also have the agent
- 10:22function
- 10:23okay so which captures data or gathers
- 10:26records
- 10:27okay so from the managed object or mos
- 10:30so every managed devices on the
- 10:32infrastructure has an agent
- 10:35and the agent function is of course to
- 10:37fetch data from
- 10:39the local device and forward it to the
- 10:41manager
- 10:42so the manager function is to perform
- 10:44basic monitoring function of retrieving
- 10:46information
- 10:47so it receives data from the agent
- 10:51all right so also we kept on mentioning
- 10:55managed object
- 10:56or managed objects so what are this so
- 10:59managed objects
- 11:00pertains to a management information
- 11:04that represents resources and their
- 11:07activities
- 11:08so managed objects or mo's are
- 11:11routers switches firewalls workstations
- 11:14servers
- 11:15these are all managed objects okay so
- 11:18the device that we are monitoring and
- 11:20controlling
- 11:21are said to be managed object all right
- 11:24next would be a monitoring agent so the
- 11:27monitoring agent generates
- 11:29summaries and statistical analysis of
- 11:31this management information
- 11:34okay and we use it for
- 11:38future planning that's what i've said on
- 11:40the introduction
- 11:41all right so next would be the
- 11:44functional architecture
- 11:45of network monitoring the manager agent
- 11:49paradigm or model that we have presented
- 11:51on the network management overview
- 11:53now let's have some recap in here okay
- 11:56so the manager agent model
- 11:57is basically the relationship between
- 12:01the manager and the agent okay
- 12:04so the monitoring application is
- 12:07basically a manager function okay
- 12:11and on a managed object there is an
- 12:13agent
- 12:14and of course an agent function so the
- 12:17communications between the server
- 12:20having the management application or the
- 12:22manager
- 12:24to the agent so basically this is
- 12:27true or via the use of the simple
- 12:30network management protocol or snmp
- 12:32so we'll be talking about snmp in the
- 12:35next and upcoming videos
- 12:38all right so for the model of
- 12:41summarization
- 12:42okay so again in here is the server this
- 12:45is where the systems administrator is
- 12:47seated
- 12:47okay monitoring the performance of the
- 12:49network via the application
- 12:52and we have here the monitoring agent
- 12:55whose primary
- 12:57purpose is to summarize okay
- 13:00so the information forwarded by these
- 13:02agents
- 13:03so there might be two or more devices
- 13:07or a lot of mo's connected to the
- 13:10um to the monitoring agent okay
- 13:14so that's it next
- 13:17how about the network monitoring
- 13:19configuration
- 13:21okay so letter a here
- 13:24manage resources in a manager system
- 13:27okay so there is a possibility that we
- 13:30are actually monitoring
- 13:32okay so a device where the application
- 13:35where the manager
- 13:37is also installed for example
- 13:40you want to monitor the performance of
- 13:42your server
- 13:43so as a systems administrator you are
- 13:46seated in front of the server and you
- 13:48are using definitely
- 13:49a monitoring application okay now this
- 13:52monitoring application performs a
- 13:54manager function
- 13:55which is to receive information from
- 13:59the agent okay so the agent is on the
- 14:02managed object
- 14:03now if it happens that you are
- 14:05monitoring itself or monitoring the
- 14:08the server okay so where the application
- 14:10and the agent is stored
- 14:12so that is this model here okay
- 14:16so that would be possible okay so you
- 14:18are monitoring your own device
- 14:20okay so the agent is installed on the
- 14:22server the manager is also installed on
- 14:25the server
- 14:26all right next
- 14:29resources in the agent system so
- 14:32with this type of model the monitoring
- 14:34application or the manager function
- 14:37or simply say manager is
- 14:40stored or installed in a computer
- 14:44okay different from where the agent is
- 14:48installed
- 14:49so for example this is a server here and
- 14:51i have here a router
- 14:53okay and i manage the router
- 14:56using the subnet or the internet okay
- 15:00so that is this resources in the agent
- 15:02system
- 15:03okay or also it is also possible to
- 15:08monitor okay or to control
- 15:11any devices are managed object outside
- 15:15the network or it could be over the
- 15:16internet
- 15:18and we have here an agent function
- 15:21which is to summarize all the
- 15:23information gathered from demos
- 15:27okay and the fourth one would be a proxy
- 15:30monitor agent so again when say proxy
- 15:33this is the software that we use so that
- 15:36this
- 15:37proprietary software can communicate
- 15:39with an open systems and vice versa
- 15:42all right next
- 15:46network monitoring methods so how do we
- 15:49monitor
- 15:50the network so one is via
- 15:53polling okay so when you say polling
- 15:56this is a request response interaction
- 15:59between the manager and the agent
- 16:01so polling is basically initiated by the
- 16:05manager
- 16:06going to the agent okay so
- 16:09a manager sends a request to an agent
- 16:12which processes the request and responds
- 16:14with information from hmib
- 16:18all right so for example if i am the
- 16:20systems administrator and i
- 16:22am seated in a computer where i control
- 16:26and configure for instance a router okay
- 16:29so i am using puti puti is basically
- 16:33my manager okay and on the router
- 16:37this router uses an ios so basically the
- 16:40ios
- 16:41captures data okay from its mib
- 16:45okay or from its virtual database and
- 16:48that data will be forwarded to the puti
- 16:51to present it to the administrator so
- 16:53that is an example of polling
- 16:55okay for instance the administrator
- 16:58wishes to display or to know the routing
- 17:01table of the router
- 17:03so we simply execute the command show ip
- 17:05route
- 17:06on the putsy application okay
- 17:09so that is an example of polling where
- 17:12in the manager
- 17:14send a request to the agent and the
- 17:16agent will respond
- 17:18with the request of the manager so
- 17:20that's polling
- 17:21okay so all the show commands that we
- 17:24use
- 17:24in cisco routers or cisco switches
- 17:28or in firewall are all examples of
- 17:32polling all right so
- 17:35a manager may use polling to learn about
- 17:38the configuration it is managing
- 17:40to obtain periodically an update or
- 17:44or an update of conditions or
- 17:46investigate an
- 17:47area in detail after being altered
- 17:51to a problem so if the action is
- 17:55initiated by
- 17:56the manager we call it polling
- 17:59all right okay
- 18:02so how about if for instance the router
- 18:06interface serial zero zero goes down and
- 18:10the router sends a notification
- 18:13onto the manager okay so is it polling
- 18:17again with this example okay
- 18:20so the agent initiated the action and we
- 18:24call it event reporting
- 18:26all right so event reporting the
- 18:29information flow is initiated from the
- 18:31agent to the manager
- 18:32when you say polling it is from the
- 18:34manager
- 18:35to agent all right so the counterpart of
- 18:38polling is event reporting
- 18:41so an agent may generate report
- 18:43periodically
- 18:44to give the manager its current status
- 18:47or
- 18:47whenever a significant event happens
- 18:50okay so like for inside for instance
- 18:54due to intermittent uh interfaces
- 18:58okay so your serial zeros like zero zero
- 19:01goes down after a second it went up
- 19:05okay so there is a notification from
- 19:07your screen
- 19:08okay so about the status of the
- 19:10interface and we call it event reporting
- 19:14okay so when you're printing something
- 19:16okay for instance
- 19:18and the printer runs out of paper so
- 19:20there is a notification in your screen
- 19:23be a sort of a message informing you
- 19:26that
- 19:27the printer is running out of paper so
- 19:30that is an example of reporting
- 19:32okay or event reporting all right
- 19:36so this is good for detecting problem as
- 19:39soon as they occur
- 19:40okay so because this is real time
- 19:43all right you could even configure your
- 19:45device to have some event reporting by
- 19:48your your cell phone or via a mobile app
- 19:51on your gadgets all right so that
- 19:55would ease the troubleshooting
- 20:01okay so next would be performance
- 20:04monitoring
- 20:06okay so performance monitoring is
- 20:09measuring the performance of the network
- 20:12or performance monitoring
- 20:15that's absolutely required in network
- 20:17management
- 20:19okay so the objective
- 20:22is to detect and fix problems that cause
- 20:26performance degradation so you've got
- 20:28slowing performance
- 20:30okay the performance is worse than
- 20:34the usual all right so you've got
- 20:38performance monitoring in there okay and
- 20:41what do we do with that well the
- 20:43performance monitoring
- 20:46can be used to better plan network
- 20:48upgrades
- 20:50okay so basically if you're going to
- 20:52implement a network
- 20:54so on its first run or initial run the
- 20:57network is doing good
- 20:58okay and then after some time okay so of
- 21:01course the network
- 21:03ages down okay you've got the number of
- 21:06um
- 21:07connections also increases okay so what
- 21:10will happen is
- 21:11basically there would be performance
- 21:13degradation due to
- 21:14aging technology okay or due to an
- 21:18increase
- 21:19in the number of users okay
- 21:22so to to better upgrade
- 21:26or to better plan and do some network
- 21:28upgrades
- 21:29that would help okay via performance
- 21:32monitoring
- 21:33okay or we could address the problem via
- 21:35performance monitoring
- 21:37so what are the problems in selecting
- 21:39and using appropriate indicators or
- 21:40metrics
- 21:42okay so basically the first one would be
- 21:46too many indicators and use okay
- 21:49so it's just like you enabled all the
- 21:52features that you have
- 21:54on the application okay so for instance
- 21:59when you installed microsoft office okay
- 22:02so you have
- 22:02or you are given these options what
- 22:05specific
- 22:06feature okay needs to be installed
- 22:09on your microsoft office package so you
- 22:12have the option to choose let's say
- 22:15word powerpoint excel okay but you also
- 22:18have this
- 22:19choose all or select all and then you
- 22:21install it
- 22:22okay now the thing is you have a lot of
- 22:25applications
- 22:26installed on your computer but you are
- 22:28not actually using them all
- 22:30right so that is similar with having
- 22:34too many indicators in use or by having
- 22:39too many components that we want to
- 22:42monitor
- 22:43and yet some of it we are we are not
- 22:46using it
- 22:47okay the meaning of most indicators
- 22:52are not yet clearly understood okay so
- 22:55we simply
- 22:56choose to enable them all but we don't
- 22:59know
- 23:00where to use it or how what's the
- 23:02significance of it
- 23:03or what's the importance of it on your
- 23:05organization
- 23:06okay so be careful when you install
- 23:09performance
- 23:10monitoring applications because some of
- 23:12it might not be needed in the
- 23:14organization
- 23:15okay so take note that whenever we check
- 23:18the features
- 23:19on the applications so that would cause
- 23:22traffic
- 23:23and that traffic would cause performance
- 23:25degradation
- 23:26so you choose only indicators which
- 23:30the organization might need most
- 23:34all right next would be some indicators
- 23:36are supported by
- 23:38some manufacturers only okay so
- 23:41why there is too many indicators in use
- 23:44because
- 23:44of the bullet number three so if i am
- 23:47using apple then i'll be using
- 23:50monitoring applications for apple so
- 23:53i'll
- 23:53if i'm using linux i'll be using
- 23:55monitoring application for you
- 23:57for linux okay so
- 24:00that would lead to many indicators
- 24:03in use okay next would be
- 24:07frequently the indicators are accurately
- 24:11measured but incorrectly interpreted by
- 24:13human
- 24:13or the management application there's a
- 24:15problem here okay
- 24:17so we've gathered the data
- 24:20accurately and correctly but when we
- 24:23interpreted it
- 24:24well problem arises all right
- 24:28so we've got an incorrect interpretation
- 24:30of the results
- 24:32okay next would be
- 24:36the calculation of indicators takes too
- 24:38much time
- 24:40why performance aggregation okay
- 24:43so that is because of traffic
- 24:47why there is too much traffic because
- 24:49you have too many indicators
- 24:51checked on your monitoring application
- 24:54okay so it's a chain reaction
- 25:01okay so next is how do we measure
- 25:04performance indicators
- 25:06okay so it's either service oriented
- 25:09okay so when say service oriented we've
- 25:12talked about
- 25:13availability so availability pertains to
- 25:16the percentage of time that the network
- 25:18system or
- 25:19component or an application is available
- 25:22for a user
- 25:23okay so we measured service oriented
- 25:27via the availability of the device
- 25:30the availability of the resources okay
- 25:34next would be the response time so how
- 25:37long it takes for a response to appear
- 25:39at a user's terminal after the user's
- 25:42accident calls for it okay response time
- 25:46for example you have encountered an
- 25:48error on your system or on your computer
- 25:51and you seek help from the help desk
- 25:54how long would it take for the help test
- 25:56to address your problem
- 25:57response time okay
- 26:01or how fast are they to resolve the
- 26:04issues that you have
- 26:05response time next would be accuracy
- 26:08the percentage of time that no errors in
- 26:11the transmission
- 26:12and delivery of information because if
- 26:16there is an
- 26:16error there is a tendency to retransmit
- 26:19the data
- 26:20okay so again service oriented
- 26:24network performance indicators are
- 26:27measured using availability
- 26:29response time and accuracy
- 26:32so the second is efficiency oriented
- 26:37okay so efficient efficiency oriented
- 26:41we talked about throughput okay
- 26:45throughput is the rate at which
- 26:46application oriented events
- 26:48file transfers occur okay so throughput
- 26:52is related to bandwidth okay
- 26:55but if we are after the efficiency we're
- 26:58not talking about bandwidth
- 27:00but we measure it instead using
- 27:02throughput
- 27:03now what's the difference between
- 27:04throughput and bandwidth
- 27:06bandwidth is basically the
- 27:09frequency is the difference between the
- 27:11highest and the lowest frequency
- 27:13so in say bandwidth we're talking about
- 27:15the capacity
- 27:16okay the capacity of the internet what
- 27:18is your maximum speed
- 27:20all right what is your minimum speed
- 27:22minimum is zero maximum is 100 for
- 27:25instance
- 27:25so that range from 0 to 100 is said to
- 27:29be the bandwidth
- 27:30all right when you say throughput this
- 27:32is the actual transfer of data
- 27:35so if you have 0 to 100 mb and
- 27:38you're getting 90 mb then that is the
- 27:41throughput
- 27:42all right next would be utilization
- 27:46so the percentage of the theoretical
- 27:49capacity of a resource
- 27:50example transmission line switch cpu
- 27:54that is being used
- 27:56okay so we can
- 27:59monitor this via an application or
- 28:02if you are using your your pc you can
- 28:05monitor the cpu utilization the ram
- 28:07utilization
- 28:08okay via the task manager and that is an
- 28:11efficiency oriented
- 28:12performance indicator okay
- 28:16so we measure the performance either
- 28:19via efficiency oriented or service
- 28:22oriented so of course that would depend
- 28:25okay next
- 28:28now from the figure here okay
- 28:31so what is or what are the elements of
- 28:34response time
- 28:36okay so how long would it take for a
- 28:39device to respond
- 28:40on your inquiry okay is it real time
- 28:44no there's no such thing as real time in
- 28:46the network
- 28:47the mere fact that your data traverses
- 28:49on the cable
- 28:51on this interfaces it causes delay
- 28:55okay so the truth is for
- 28:58every response that we're getting okay
- 29:00so there
- 29:01is an integration of delays on it all
- 29:04right
- 29:05so the elements of response time these
- 29:07are delays
- 29:08okay so if you observe here now from the
- 29:12equation
- 29:13okay so that's what i'm saying earlier
- 29:14when your data traverses on the cable
- 29:17there is delay and it gets into the
- 29:19hardware there is delay
- 29:21okay so going back again to the cable
- 29:23another delay and so on
- 29:25okay so therefore response time
- 29:28is equals to the inbound terminal delay
- 29:32plus the inbound queueing time all right
- 29:36plus the inbound service time and so on
- 29:39so basically
- 29:40there is always delay for every response
- 29:43time
- 29:44right so it's just that as systems
- 29:47administrator how do we minimize
- 29:50delays okay
- 29:53next performance monitoring functions
- 29:57okay so this includes performance
- 29:59measurement
- 30:00and performance analysis now let's talk
- 30:04about performance measurement
- 30:06so this is the actual gathering of
- 30:08statistics
- 30:09about network traffic and timing okay
- 30:13so we do it via observation
- 30:16okay and of course with the help of
- 30:18tools we get it
- 30:20okay so typically performed by agents
- 30:23within network devices and
- 30:26we these agents forward the data
- 30:29to the manager okay so by uh snmp
- 30:34and of course the systems administrator
- 30:37can view and analyze okay so that data
- 30:42okay so example includes the amount of
- 30:46data in and out of the node
- 30:47or the number of connections traffic per
- 30:50connection
- 30:51so that's performance measurement okay
- 30:54next would be performance analysis so
- 30:57analyzing the guard data
- 30:59and presenting it so example you've got
- 31:02the total the average the min max
- 31:04histogram
- 31:05something like the statistical
- 31:06information about the gathered data
- 31:09we call it performance analysis okay
- 31:12and usually we compare it or we do a
- 31:15benchmark of it on the previous records
- 31:17that we have
- 31:18okay and we are expecting
- 31:22okay so we've got the improvement
- 31:25or better service provided to the end
- 31:27users
- 31:29all right next is
- 31:33synthetic traffic generation so what is
- 31:35this so generating artificial traffic
- 31:38load
- 31:38to test okay your network so for
- 31:41instance
- 31:42if i'm going to design a network that is
- 31:44good for for
- 31:46100 workstations and i only have 10 here
- 31:49so i could use the synthetic traffic
- 31:51generator to test
- 31:53whether the network is capable of having
- 31:56100 workstations though i only have 10.
- 31:59okay so something like doing a
- 32:01simulation test
- 32:03okay it permits the network to be
- 32:05observed under controlled
- 32:07load okay
- 32:11all right so next would be a typical
- 32:14performance related questions
- 32:16okay so performance measurements can be
- 32:19used
- 32:20to answer a number of questions so these
- 32:23questions could help us
- 32:25improve the performance okay so
- 32:29if we are asked or invited okay so to
- 32:32ask questions
- 32:33on how to improve the performance
- 32:36of the network well these questions
- 32:39could help you
- 32:40okay number one why is the response so
- 32:43slow
- 32:45so if you are the i.t personal and i am
- 32:48the
- 32:48end users and they ask you this question
- 32:50how would you answer it
- 32:52why is the response so slow are you
- 32:55going
- 32:56to give me answers like because the
- 32:57internet is low
- 32:59or maybe we have um increased the number
- 33:03of users on the network
- 33:04on the network that is why the response
- 33:06is so slow
- 33:08okay and you ask the same question okay
- 33:11same questions
- 33:12were asked after a year
- 33:15and how would you address it are you
- 33:17going to give us the same answer
- 33:20okay so this is a very loaded question
- 33:22so why is the response so slow
- 33:24okay next would be why is the
- 33:27transmission rate so high so this is
- 33:29somehow technical
- 33:31okay retransmission happens because
- 33:34the data or there is a drop on the
- 33:36transmission of packets
- 33:38okay so if there is a drop in the
- 33:40transmission of packet the tendency is
- 33:42the devices will retransmit it
- 33:44especially if you are transmitting a tcp
- 33:47packets
- 33:48okay so that requires an acknowledgement
- 33:51all right
- 33:53next is traffic evenly distributed among
- 33:56network users
- 33:58or are there source destination pairs
- 34:01with unusually heavy traffic
- 34:04okay so for instance in an organization
- 34:07basically
- 34:08we give um traffic or we give bandwidth
- 34:12okay to every department depending on
- 34:16their
- 34:16functions and the organization okay so
- 34:20allowing or assigning bandwidth to
- 34:24marketing
- 34:25is different compared to assigning
- 34:28bandwidth to accounting personnel
- 34:31all right so you you assign bandwidth
- 34:35depending on its function okay
- 34:38in the organization all right
- 34:42next what is the percentage for its type
- 34:45of packet transmitted
- 34:47so there should be a higher percent
- 34:50of a successful transmission than
- 34:52failure
- 34:53okay next what is the channel
- 34:56utilization and throughput
- 34:58so we discussed throughput and defined
- 35:00throughput earlier
- 35:02and the channel utilization okay so
- 35:05we're talking about the ratio here okay
- 35:07so out of
- 35:08say you'll have 30 mbps
- 35:12okay for instance okay so that's your
- 35:16your bandwidth what are you getting from
- 35:18it
- 35:19are you getting 30 also are you getting
- 35:22just 20
- 35:23okay so utilization
- 35:27is it should be higher okay
- 35:30and the throughput should also be higher
- 35:32it should be close to
- 35:33the bandwidth all right
- 35:36next what is the effect of traffic load
- 35:38on utilization
- 35:40throughput and time delays okay
- 35:44so basically with this
- 35:47with every traffic on the network
- 35:50your performance has the tendency to
- 35:52decrease
- 35:53okay so if you want to address really
- 35:56the performance you have to improve
- 35:58the bandwidth you have to improve the
- 36:00throughput
- 36:02the utilization and that would diminish
- 36:05delays
- 36:07okay next when does traffic load start
- 36:10to degrade system performance
- 36:13okay so for example in school okay
- 36:16so if you have a class at 7 30 in the
- 36:18morning okay so
- 36:19when you came in there early at six
- 36:21o'clock okay so basically you're gonna
- 36:23have a good
- 36:25internet access a better internet access
- 36:28but as the number of students increases
- 36:31in the campus
- 36:32so you will experience some degradation
- 36:36in terms of internet access that is
- 36:38because
- 36:39a number of users okay a bulk of users
- 36:43are trying to access the same resource
- 36:45that you are accessing
- 36:47okay so you should be able to know
- 36:50the time when the performance
- 36:53aggregation
- 36:54happens on the network and also you
- 36:56should be able to identify
- 36:58okay the the peak okay i mean
- 37:02during what time would be the
- 37:05a very good or excellent internet access
- 37:08every sunday
- 37:09all right or maybe 4 30 to 9 we've got
- 37:12a better internet access that is because
- 37:15less users
- 37:16are in the campus during that time okay
- 37:19so a systems administrator
- 37:21you should know okay the time
- 37:25when to start the
- 37:28allocation of the resources okay so to
- 37:31anticipate the
- 37:32[Music]
- 37:33volume of users in the network to avoid
- 37:36performance degradation okay so we have
- 37:39some sort of reallocation of resources
- 37:41maybe
- 37:42right and the last one would be
- 37:46what is the maximum capacity of the
- 37:48channel under normal operating
- 37:49conditions
- 37:50and how many active users are necessary
- 37:53to reach this
- 37:54maximum okay so again as network
- 37:57administrator
- 37:58or a systems administrator you should
- 37:59know that
- 38:01this channel or that this network
- 38:04or that this internet could only
- 38:08allow 100 people to access okay
- 38:11so if you have more than 100 then
- 38:15performance duplication starts or begins
- 38:19okay and a systems administrator you
- 38:21should have
- 38:23the solution to that okay so again the
- 38:26possible solution is
- 38:27there might be a need for reallocation
- 38:30of resources all right
- 38:35okay so next would be fault monitoring
- 38:39okay so to detect faults as quickly as
- 38:42possible
- 38:43after they occur and to identify the
- 38:45cause of the fault so that correctional
- 38:47action may be taken
- 38:49so a systems administrator well it's our
- 38:51duty to
- 38:52[Music]
- 38:54maintain okay a fault free
- 38:57network okay so
- 39:00problems on fault monitoring so this
- 39:03includes fault detection problem
- 39:05so there is an observable fault example
- 39:07deadlock
- 39:08okay so device not monitorable deadlock
- 39:12is unobservable i mean you don't know
- 39:15when it will be coming
- 39:16okay so we all know that that luck
- 39:18happens only if
- 39:20the resources requested by the
- 39:22application cannot be granted
- 39:24okay so there is also partial or
- 39:27partially observable faults
- 39:29inefficient to pinpoint what a problem
- 39:31is
- 39:32okay or uncertainty in observation
- 39:35so not clear what really the problem is
- 39:39okay so that's a fault detection problem
- 39:42you don't know the source of the problem
- 39:44so how can we solve it
- 39:46next would be fault isolation problems
- 39:49so multiple potential causes
- 39:52too many related observations sometimes
- 39:55this is our
- 39:56problem we have a lot of information we
- 39:58have a lot of
- 39:59a lot of inputs and we have a hard time
- 40:02to
- 40:02digest okay so we have too many related
- 40:06observations that is why
- 40:08so that takes a slow in solving the
- 40:11problem
- 40:12okay interferences between diagnosis
- 40:15and local recovery procedures and
- 40:18absence of automated testing tools so we
- 40:20do it manually
- 40:21so you've got fault isolation problem
- 40:25all right now considering this diagram
- 40:28here
- 40:29okay we only have one link
- 40:32okay connecting to the server now what
- 40:35will happen if this t1 link fails
- 40:39okay so it's dc or disconnected
- 40:44okay so what it says here is that
- 40:48whenever you you create connections to
- 40:51the server for
- 40:52instance there might be a sort of
- 40:54redundancy
- 40:55okay so that when the primary link goes
- 40:57down so there is an alternate or backup
- 40:59link
- 41:00okay so that will capture
- 41:03okay so the the connections
- 41:08with the server or with the devices
- 41:11all right so if the
- 41:15primary link goes up so there is also a
- 41:18chance that
- 41:19it will go back to the original state i
- 41:22mean
- 41:22so the backup will go on the backup
- 41:25state
- 41:26and the primary will go on the primary
- 41:29duty
- 41:30all right
- 41:34okay so propagation of failures to a
- 41:36higher layers so basically
- 41:38being a systems administrator you should
- 41:40know where each component
- 41:43of a network device works okay so for
- 41:45instance router router basically works
- 41:47on the layer three
- 41:48okay so it just works in the layer two
- 41:50okay so if there would be a problem for
- 41:53instance
- 41:54okay so on the connections on the router
- 41:57so basically that would be propagated
- 41:59onto the application layer okay so if
- 42:02there would be problem with the
- 42:03connections here
- 42:04that can be visualized on the
- 42:06application layer so we could have
- 42:07something like
- 42:08if we can initially ping the connection
- 42:10then after some time we've got request
- 42:12timeout
- 42:13all right or if there would be a problem
- 42:17on the lower layer
- 42:18so that would be propagating up to the
- 42:20highest layer
- 42:22all right so that would aid
- 42:25troubleshooting
- 42:26okay so how would you start
- 42:27troubleshooting in here so are you going
- 42:29to use
- 42:31a bottom up approach or a top down
- 42:33approach
- 42:35okay so usually if there will be a
- 42:36problem on the hardware
- 42:38that propagates onto the higher layers
- 42:43so you should know okay the techniques
- 42:46okay that is being used on
- 42:49troubleshooting
- 42:50network troubleshooting specifically
- 42:55okay so next would be default monitoring
- 42:58functions
- 43:00so let's start with logs or lagging
- 43:02facilities so record important events
- 43:04and errors so lag should be accessible
- 43:09by managers via polling so we have
- 43:12introduced and defined
- 43:13polling okay from the previous slides
- 43:16okay
- 43:16so there should be a lagging facilities
- 43:19okay
- 43:20event reporting sending events error to
- 43:24managers
- 43:25sending alarms to manager
- 43:28to warm possible problems so we're
- 43:30talking we're talking about
- 43:31notifications here okay so notifications
- 43:36that would be initiated by the agent to
- 43:38the manager
- 43:40you could also use diagnosis uh
- 43:42diagnostic function like the
- 43:44connectivity test
- 43:46so traceroute okay or tracer
- 43:50right trace route on the routers and
- 43:52tracer on
- 43:54the computers you can also use the
- 43:56response time
- 43:57test okay
- 44:00the live nest test or the ping
- 44:04okay the protocol integrity test
- 44:08you bring one two seven zero zero one so
- 44:11that is the test where your protocol
- 44:12stack is
- 44:14properly working okay you could also
- 44:17use the loopback test okay or
- 44:20same with the protocol integrity test
- 44:22something like one two seven zero zero
- 44:24one
- 44:24it's a look back all right
- 44:28next how about accounting so accounting
- 44:31monitoring
- 44:32keeping track of the users usage of
- 44:35network resources
- 44:38so communication facilities
- 44:41computer hardware software and systems
- 44:44and
- 44:45services okay so how do you monitor the
- 44:48utilization for instance
- 44:50of an employee okay so
- 44:53we use application okay so as always
- 44:56for every monitoring activities so we
- 44:59use
- 44:59applications so you we don't want this
- 45:02to
- 45:03perform manually all right so
- 45:06usage may be
- 45:08[Music]
- 45:09need to be broken down by account by
- 45:13project
- 45:13or by individual user for appropriate
- 45:16accounting purposes
- 45:19okay so before we end up let's wrap up
- 45:23so let's summarize what we have
- 45:25discussed and learned from this
- 45:27video so first we talked about network
- 45:29monitoring
- 45:31okay and it is the most basic aspect
- 45:34of network management okay
- 45:37or part of the system's administration
- 45:41or systems administrators duty and
- 45:43responsibility
- 45:45okay we also talked about the purpose of
- 45:48network monitoring
- 45:50that is to gather information about the
- 45:51status and behavior of the network
- 45:53elements
- 45:54okay so information to be gathered
- 45:58includes
- 45:58static okay dynamic and statistical
- 46:01information
- 46:03monitoring methods we've talked about
- 46:05polling and event reporting
- 46:06okay polling initiated by the manager
- 46:10and event reporting initiated by the
- 46:12agent
- 46:13also we've talked about the monitoring
- 46:15functions performance monitoring
- 46:18fault monitoring and accounting
- 46:20monitoring
- 46:22okay so if you will observe okay so
- 46:25network monitoring is more on the
- 46:27performance
- 46:28fault and accounting where is security
- 46:32and configuration we've got f cops right
- 46:35fcaps fault is there configuration is
- 46:39missing
- 46:40all right so accounting is there
- 46:44you've got performance is there and
- 46:47security is not in there
- 46:49okay so the configuration
- 46:52and security will be covered on the next
- 46:55video
- 46:56okay so that is network control all
- 46:58right
- 46:59so that ends up the video so thank you
- 47:02for sticking around and thanks for
- 47:04watching have a great day
- 47:10[Music]
- 47:17you
About this transcript
This page contains the full transcript of Network Monitoring by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 5,938 words across 1,174 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.