Alerts and Events
Continuing the discussion from the last skill, we understand that ThousandEyes tests will create data that can be viewed in the form of Views and Dashboards. However, what if we want to be actively notified that a network issue has appeared? This is the function of Alerts, and Events will play a role as well.
Knowledge Check
When performing a scheduled network maintenance window, what should be done with ThousandEyes alerts to prevent notifications?
Labels
Labels are a powerful tool that equip admins to better manage a sprawling set of agents and tests. Let's see how labels can be used in the ThousandEyes interface.
Knowledge Check
What two types of labels exist within ThousandEyes?
Active and Passive Monitoring
Active and passive monitoring techniques can each be used to perform network tests. ThousandEyes is able to leverage each technique depending on the test, but it's important that we as admins understand the difference and when one might make sense over the other.
Knowledge Check
What is a benefit to Active monitoring?
Other Cisco Solutions
ThousandEyes isn't the first Cisco solution to address Network Assurance. In fact, Cisco has been developing Network Assurance solutions for well over a decade! Let's take a look at some of Cisco's other solutions, placing an emphasis on where in the network each solution can help.
Knowledge Check
Match the Cisco solution to where it can provide Network Assurance services.
This interactive assessment is available in the full learning experience.
ThousandEyes Big Picture Challenge
With our primary components in place, let's zoom out and ensure we understand how ThousandEyes brings it all together.
Take a moment to grab a pencil and paper to jot out your answers to the challenge presented above, and then we'll review the solution together below.
Solution
View Transcript
Alerts and Events
0:00Well, as we mentioned previously, we are going to configure tests, and these
0:05tests are going
0:06to leverage the agents that we specify, whether those are endpoint agents or
0:10enterprise or
0:11cloud agents.
0:13And this is going to produce a whole lot of information.
0:16So we're collecting a bunch of data, and that data gets placed into the
0:19thousandized
0:20platform for tracking.
0:22And we are going to be able to go and look at this data ourselves so we can
0:26pull up
0:27our views and click through there, we can pull up our dashboards.
0:36And from here we can go out and see when there might be some issues.
0:40Now that's great and all except as we pointed out, we might want to get pro
0:45actively notified.
0:46Let's say there's a big issue that happens.
0:51And I don't want to have to wait for me or somebody on my team to go out and
0:54check out
0:55a view or check out a dashboard in order to see that an issue has occurred.
0:59We would hope that we can use this data to create notifications.
1:05And there are two ways to create notifications, alerts and events.
1:09Primarily we are going to be using alerts, which is what we're going to start
1:14out talking
1:15about here.
1:17So an alert is going to create this type of notification.
1:21And the idea here is that it's something that we know we want to know.
1:27What we're saying essentially is that I know I want to know something specific
1:34about an
1:35environment.
1:36So for example, maybe I want to say that a particular site has a round trip
1:42time of
1:42100 milliseconds.
1:44So I'm going to make sure that it always stays below 100 milliseconds as soon
1:49as this resource,
1:50maybe it's a website, maybe it's a node on my network, but either way, as soon
1:55as the
1:56threshold drops before 100 milliseconds, I might want to know about that.
2:01And so alerts are explicitly configured.
2:05This is why I need to know exactly what I want to know.
2:10Now the reason I'm pointing out that this is something that I know I want to
2:13know is
2:14because there might just be issues on the network and I didn't know that I
2:17would care
2:18about that.
2:19And hopefully events are going to catch that for us.
2:22Events are configured automatically and they will just alert us when something
2:26goes south,
2:27as we like to say, as something has gone wrong and event is supposed to tell us
2:31with that.
2:32So I lay that foundation as we talk about alerts to really emphasize that
2:35alerts are
2:36things that I know that this is going to be a problem if a particular metric is
2:40met or
2:41maybe not met.
2:42And so I need to know when that occurs.
2:45So we can go out and we can configure these alerts and we can probably assume
2:51that as
2:51we continue to use the Thousand Eyes platform, that we're going to have more
2:55and more alerts
2:55that we configure in the environment.
2:58So again, alerts are going to create notifications and we have three different
3:04types of notifications
3:06that we're going to be able to take advantage of here.
3:08These notifications are emails, which are going to be a primary point of
3:13notification
3:14for us.
3:15We can also take advantage of webhooks.
3:18And specifically when Thousand Eyes takes advantage of a webhook, meaning that
3:23it's just going
3:24to use HTTP messaging, probably communicating with a web server on some level,
3:29we are going
3:30to be processing this via JSON.
3:33So we're going to wrap our notification up in JSON encoding, format that and
3:39send it
3:39off.
3:40And make sure we're expecting to receive JSON information and be able to
3:44interpret what
3:45exactly we're sending.
3:47And then we also have other integrations.
3:51So those integrations might be app dynamics.
3:56Cisco has made another acquisition called app dynamics.
4:00This is something that ties into our development of applications.
4:04So we might take advantage of that.
4:07But then we might take advantage of another alerting mechanism.
4:11Specifically, we think about applications such as pager duty and service now,
4:17both of
4:18which support integrations and a lot of help desks rely on these types of
4:23applications.
4:24And for that matter, we can actually integrate into Slack.
4:27So at the time of this video, these are the four main integrations that are
4:31available.
4:32I would expect that maybe over time, Cisco adds more integrations into Thousand
4:36Eyes.
4:37But these are the primary ways that we're going to go about creating these
4:41notifications.
4:42Now one thing that probably immediately jumps out at us is the concept of
4:47texting and the
4:48fact that it is missing.
4:50So why is there no texting option?
4:52And oftentimes we refer to texting as SMS notifications.
4:56Well, there are two primary reasons for this or maybe I should say two
5:00different workarounds
5:01that we have.
5:03And since we have workarounds, we haven't created native texting from Thousand
5:07Eyes, again, at
5:08the time of this video.
5:09The first reason is that there are some of these applications down here that
5:13will support
5:14texting.
5:15And so for using an existing service type of application, we probably have the
5:20capability
5:20of texting individuals on an as needed basis.
5:24But the other option here is simply to take advantage of emails.
5:28Most of our mobile providers or mobile service providers or mobile SPs will
5:34support an email
5:35address that basically converts the email into a texting to a phone number.
5:42So what we might find is that it's the phone number one, two, three, four, five
5:46, six, however
5:47long our phone number is.
5:48And then we put the @ sign and then whatever the mobile service provider has as
5:53a domain
5:54that will allow us to send a text.
5:57So I know that pretty much every mobile service provider I've ever used has had
6:01this as an
6:01option.
6:02It's one that we don't take advantage of too often in our day to day lives.
6:07But something like this would be perfect for this.
6:09I can send myself an email to my phone number at whatever domain my service
6:13provider supports.
6:15And as soon as Thousand Eyes sends that email, I will get a text on my phone.
6:20So we can absolutely take advantage of texting via one of these two mechanisms,
6:24which is
6:25why we don't see a native texting option listed here in our notifications.
6:30So from here, we might want to at least talk about the concept of quieting our
6:38alerts.
6:39How do we go about quieting alerts when they come in?
6:42Because we might actually have a couple of situations come up.
6:46For example, I might be about to perform network maintenance.
6:50And so if I have network maintenance that's about to pop up, I probably want to
6:55make sure
6:56that I'm not notifying everybody that a particular network resource has gone
7:00down.
7:01I know it's going down.
7:02We all know it's going down.
7:04And so that might be a situation.
7:06We might also have a known issue.
7:09If we have a known issue on the network, I don't need Thousand Eyes constantly
7:13telling
7:13me that this issue exists.
7:15Maybe I'm trying to fix it or maybe it's not fixable and we're waiting for
7:18hardware
7:19to show up.
7:20It's going to be four hours or it's going to be two days before we can actually
7:24fix this
7:25issue.
7:26So there's reasons for us to disable alerts, even though I configured the
7:30alerts myself.
7:30I don't necessarily want to go in and say, all right, let's just delete this
7:34alert because
7:36once these scenarios have passed, I probably want to return to the system
7:40creating alerts
7:41for these scenarios.
7:43So what do we do?
7:44Well, we've got two options for this.
7:46We have the concept of alert suppression and alert suppression is a proactive
7:54concept.
7:56This is going to apply to the scheduled maintenance window concept.
8:00So if I know that tonight at midnight, I'm going to be resetting a bunch of
8:03network switches.
8:05I could probably get into Thousand Eyes configuration, find the appropriate
8:10alerts and suppress those
8:11alerts for the next several hours, knowing that I'm going to reset these
8:16devices.
8:17And then after a few hours have passed, that suppression can end and we can go
8:21back to
8:21alerting if those systems go down.
8:24The other option we have is the snooze.
8:27So think about hitting the snooze after the alarm has gone off in the morning.
8:32Maybe we've all been guilty of doing that a number of times in our lives.
8:36Maybe it's something we do every week.
8:37But either way, this is reactive, the alarm has already gone off.
8:41I'm not trying to prevent the alarm from going off.
8:44I'm trying to say, I know about this issue.
8:46Please tell me about it again in the future.
8:49And so that would be that scenario where I know that this issue is going to
8:53persist for
8:53a little while.
8:56So that's an overview of alerts.
8:58And again, as mentioned at the start here, alerting is when I know what I want
9:03to know.
9:04What about when I don't know what I want to know?
9:06Maybe there is a scenario where I'm not actually monitoring a particular link
9:10or a particular
9:11device, but the fact that this went down means that we have an outage.
9:16And because I don't actually have an alert, we might say, well, this is no good
9:20.
9:20Do I really have to manually configure every single alert for every single
9:24scenario so
9:25that I'm aware when something happens on my network?
9:29And the answer, fortunately, is no.
9:31We don't have to worry about that specifically.
9:34Plus, Thousand Eyes has a backup plan of sorts.
9:37This is known as the event.
9:39So when we're talking about events, there is not going to be any configuration
9:45involved.
9:46I don't need to worry about creating event configuration because ultimately, we
9:50're not
9:51actually defining what it is that we want to be alerted on.
9:55Say, well, how can we then be alerted on it?
9:58Well, essentially what we're doing is we are running a baseline evaluation or
10:03status
10:04quo evaluation.
10:06I understand as the Thousand Eyes platform, Thousand Eyes itself is looking at
10:11this scenario
10:12and recognizing that normally this device is online.
10:16Now, a device going down is a little bit of an extreme example.
10:19Maybe it's more like we're used to seeing a 1% packet loss on this link.
10:26And now all of a sudden we have a 10% loss.
10:29Well, this is what's known as an anomaly.
10:33So an anomaly or anomaly detection when it comes to network assurance is saying
10:38that
10:38I know what's normal on my network.
10:41I've evaluated this network long enough to know what a normal amount of loss or
10:47latency
10:47looks like.
10:49Maybe I know about how long it normally takes for me to do a page load or
10:53something like
10:54that.
10:55And so I've established a baseline.
10:57Again, I know what's normal.
10:59And all of a sudden, there's an anomaly.
11:01So at this point, this can trigger an event.
11:06Now an event has exactly one notification option at this point in time.
11:13And that would be an email.
11:15So we don't have all of the same integrations.
11:17We can't use web hooks.
11:19But fortunately, we can not only send emails, but we can also send text alerts
11:24based on
11:24this type of event.
11:27Now there are a couple more details about events to be aware of.
11:30And this is just more information.
11:32We're just going to have to remember or memorize.
11:35But ultimately, events are going to assign an impact level.
11:40And this impact level is actually going to be based on our agent count.
11:45So let's just say the number of agents that are experiencing this particular
11:51issue.
11:52Now maybe we've got a bunch of agents, only half of them are seeing an issue.
11:56Well, that's still actually a lot.
11:58A lot of our agents are experiencing an issue, but maybe it's 1% of our agents
12:03or 5% of our
12:04agents.
12:06So based on that, we're going to assign either a low, medium, or high level of
12:14impact.
12:16Furthermore, we are going to see that there are five different types of events.
12:20These five different types are going to be a local network type where we're
12:25evaluating
12:26our own local network, a network outage, where something is actually
12:31experiencing an outage
12:33on the network.
12:34We also have a generic network type of event.
12:38And yes, we will see these in more detail later on.
12:41This is just for us to know what these different types are.
12:44We can also have a proxy issue and a server issue.
12:53So these are the five different types that we can expect to see.
12:56And once again, only email notifications are available for events.
13:01So one of our primary takeaways here should be making sure that we fully
13:04understand the
13:05difference between alerts and events, where events are based a little bit more
13:09on establishing
13:10a baseline and detecting anomalies.
13:13And fortunately, there's nothing I need to do to configure events and make sure
13:17that
13:17they happen.
13:18Now the focus of our conversation really ultimately is on alerts because we're
13:23going
13:24to spend a lot of time creating alerts in our environment, not just for
13:27practice for
13:28the exam, but in the real world production, thousandized deployments.
13:32Alerts are absolutely huge.
13:34They're a major part of this because again, we're collecting all of this data
13:38and it's
13:38great that I can see that data, but I need to create the notifications when
13:43there's a
13:43major issue.
13:45And so I define those thresholds myself.
13:47I create the different alert types and I get notified in whichever way I so
13:52choose based
13:53on the options available.
Labels
0:00When it comes to creating thousandize configuration, we have to manage a whole
0:05lot of things that
0:07we create in the configuration, especially a large number of endpoints and a
0:13large number
0:14of tests.
0:16So Cisco and Thousandize, they wanted to make it so that we could more easily
0:21manage
0:21all of these endpoints and tests.
0:23Because if we think about it, we might truly have tens of thousands of end
0:28points in our
0:29environment.
0:30If we're smaller infrastructure, smaller organization, then we probably won't
0:33have that many, but
0:35we could have tens of thousands, we could even go well above and beyond that
0:38for the
0:38right size organization.
0:40And even our tests here, we're probably going to have dozens, if not hundreds
0:45of different
0:45tests.
0:47And so how can we filter through all of these?
0:50Well this is the concept of the label.
0:53A label is truly an arbitrary designation.
0:59What I mean by that is that I'm going to assign a color to a label, I'm going
1:04to apply a name
1:05to a label, and the significance of the label is defined by, well, me, the
1:12person who is
1:14configuring this.
1:15So by the configurator, I'll just say the admin of this configured
1:21infrastructure.
1:23So basically, if I decide that a blue label named special gets to apply to a
1:31specific set
1:33of endpoints, maybe endpoints, 1, 100 and 10,322.
1:41These are my three favorite endpoints in the entire organization.
1:45I can create a label and put it on those three endpoints.
1:50And then at that point, I can maybe filter my endpoint list or otherwise apply
1:55tests
1:56just to that label.
1:58Now this is especially arbitrary.
2:01It doesn't actually provide much value.
2:03I guess I flagged my favorite endpoints.
2:06But maybe more likely what we'll do is we will flag different endpoints that
2:10have similar
2:11properties.
2:12So maybe these three are our executives in the organization.
2:18If there are executives, then we're going to care a whole lot about those user
2:22experiences
2:22because as soon as they hit problems with their user experience, we're all
2:27going to
2:28have to jump to fix it very, very quickly.
2:31That's just the way it works.
2:33So when we're looking at our different labels, there are two types of labels.
2:37We have endpoint labels.
2:41And we have labels for testing.
2:43So test labels.
2:48Now when we're talking about endpoint labels, this is pretty practical because
2:51what we might
2:52do is we might create a test.
2:56And for my test, what I want to do is I want to take a set of endpoints.
3:01And we're talking about ultimately endpoint agents.
3:06And I want to make a test that goes out to a particular website.
3:10So again, maybe I want to target these specific executives and I want to have a
3:14constant test
3:15to see how they are doing.
3:17So I can use my special label.
3:20I can say, all right, I want to apply this specific test.
3:23We're going to call it exec_experience.
3:27exp.
3:28And so that's the name of the test.
3:32And now I'm going to apply it to my label special.
3:35I'll just call it spec here.
3:38So at this point, that test is going to get applied to those agents.
3:42And I'm going to be able to look at the views and set up alarms or alerts
3:46rather.
3:47That are going to tell me what's happening with that group of endpoints.
3:51So that's the purpose of the endpoint labels.
3:53It's pretty practical.
3:54It allows us to apply tests to specific agents.
3:58When it comes to the test labels, this is a little bit more for ease of
4:03management,
4:04especially when it comes to filters.
4:07Because we might truly, again, have hundreds of tests configured.
4:11And so if I want to maybe just keep track of a specific set of tests, I can go
4:18through
4:18and maybe I can tag three of these tests or four of these tests as red, a red
4:25label.
4:26And so then I can go to my list of tests.
4:28It lists hundreds of tests.
4:30And I simply filter by the red label.
4:32And now I see the four tests that I care the most about.
4:36So these are the primary types of labels that we're going to see in our
4:39thousandized configuration.
4:41In fact, it probably makes it a little bit more clear if we just look at a
4:46demonstration.
4:47So let's flip over to our thousandized interface.
4:49And we're going to start by taking a look at our endpoint agents.
4:53So we're going to open up our endpoint agents option over here on the left.
4:57We're going to go to agent settings.
5:00And then up at the top, we see actually a bunch of tabs.
5:04So right here in the middle is this agent labels tab.
5:06We're going to click this.
5:08And now we see that I already have a label in here called CBT test.
5:13But let's go and ignore that.
5:14I'm just going to add a new label.
5:16By the way, you might notice that any time we're going to create a new anything
5:21in thousand
5:22ized that usually there's a blue button.
5:25I say usually, but really always there's a blue button.
5:27So if we ever just need to find how to create something, just sort of keep in
5:32mind there
5:33should be a blue button somewhere that allows me to create it.
5:35In this case, a new label.
5:36So I'm going to click the add new label creates this wonderful pop out.
5:41I can create whatever label I want.
5:43So let's just do a head or go ahead and to what I said before, we're going to
5:47call the
5:47label name special.
5:48I already used the color blue for a label.
5:51So let's just use purple this time.
5:53Use whatever of these colors that I want.
5:56And now what I want to do is figure out which agents and specifically which end
6:00points to
6:02give this label to.
6:04Now I could go to the trouble of just trying to find all of the endpoint agents
6:11which will
6:11show up down here.
6:13Now it's a little bit tricky because I only have a single endpoint in this lab
6:16environment.
6:17And so there's only one that shows up down here.
6:19But what's going to happen is this is going to list all of the agents that
6:24match this
6:25criteria up here.
6:27So long story short, let's do this.
6:30If I say filter all of these conditions.
6:33So first of all, I can create multiple filter conditions.
6:36So keep that in mind.
6:37Second, let's just go ahead and look at our options here.
6:39So we could stick with location.
6:42We could take a look at the agent or agent type.
6:45You can look at our gateways, VPNs, SSIDs.
6:48Maybe we would just want to target any agent or any endpoint that is connecting
6:54via a specific
6:55wireless SSID.
6:57We can search by IP addresses, host names, all kinds of things.
7:02Again, all I'm really looking for at this point is to create a batch of agents
7:07that
7:07can apply the label to.
7:09So if I say location is in and let's just say United here to find the United
7:16States,
7:16which is where this desktop of mine is.
7:20So I'll just check the United States box.
7:23And now we see that we have 361 locations selected and my agent, well, yeah, my
7:30endpoint agent
7:32does match this.
7:33Now notice this, if I use the dropdown, I say it's not in the United States at
7:37this
7:37point, notice that it goes away.
7:39So this is what we'd expect is we have hundreds of endpoints, then we're going
7:43to find different
7:44amounts of endpoints.
7:46And again, it's calling them agents here because we're talking about the
7:48endpoint agents, but
7:50a different amount of agents will show up based on our filter.
7:54So I might say it's in the United States, but then I could add another filter
7:59here and
7:59say that, I don't know, again, the SSID is going to match a specific, we're
8:06using a specific
8:08SSID.
8:09So that's the concept of adding a bunch of filters.
8:14And then again, using this dropdown, I can say any of these apply or all of
8:18these apply.
8:19So it's sort of that logical and or conversation.
8:22So do I want this and let's add another couple.
8:25So is it this and this and this or is it this or this or this?
8:31And again, ultimately, we see the results down here that we have all of the
8:35agents that
8:35are going to show up that get this label.
8:38So I'm just going to hit save changes.
8:40The ultimate result here is that the endpoint in question is going to be given
8:45the label
8:46that I give it.
8:48And so if I go back to my endpoint agents and I click on this, we're going to
8:52find the current
8:53label is CBT test.
8:58So let's go back and find out.
8:59Did it actually apply?
9:01Okay.
9:02Yeah, it did apply.
9:03So it just hasn't updated.
9:04This does actually sometimes take a moment to update.
9:07Let's go off of agent settings, go back to agent settings, go to agent label,
9:13no, click
9:14on this.
9:15Oh, it still says current labels.
9:18Well this one is not updating, but we can see from the other view, if I come
9:22over to
9:22agent labels, click on one of these and it shows that the desktop is part of
9:27this specific
9:29label.
9:30And we can see down here that we actually have both of those labels applied.
9:33So just every now and again, it takes a little bit to update, no worries.
9:38And we can click on any one of these labels to see all of the agents that are
9:41being matched
9:42to that specific label.
9:44So now what we can do is if we come over to test settings, I can first of all
9:52see that
9:53I can create some test labels.
9:56So I could create a label here, again blue button, test two, grab a green, let
10:02's grab
10:03an orange label, and then I can apply this to any number of tests.
10:07So let's say I want it to apply to Google suite meet.
10:11So we're tracking Google meet, and then I go back to tests.
10:16So here's my list of tests.
10:17Again I've got four in my test environment.
10:19We might have hundreds here.
10:20I can say add filter agent labels, not agent labels, test labels.
10:27There we go.
10:28And I can grab again, it hasn't updated.
10:31So this is why I say it does take a little bit sometimes to update, try to be
10:38gracious
10:39and patient.
10:40Let's try this again, test labels, there it is.
10:43So now I apply my test label here.
10:48And even this is a little bit out of sync.
10:52So, yeah, this got backwards.
10:54Oh well, it's applied here and we see that it's the only test.
10:57So this is where if I have hundreds of these and I want to look for a specific
11:00set of tests,
11:01I can filter by a label.
11:03Now lastly, let's just say that I want to, let's just say create a test here.
11:14All right.
11:17So when I come to agents, I can say specific agents, and then I can add,
11:23actually let's
11:24see here, agent labels, there we go.
11:26And now I can specify which label I want.
11:29So whatever domain I'm going to track and monitor, I can apply the set of
11:34labels here.
11:36So I can say the CBT test label.
11:38And then it's going to get applied to all of the agents that have that specific
11:43label.
11:43So this is how labels can make our lives easier.
11:46This is something that as we get practice with, we're going to see more and
11:50more how
11:50useful they are for again, management of the system, just filtering out
11:55different tests
11:56when we have a bunch of tests there, but also applying a test to a group of
12:02agents via these
12:04labels can be very useful to us as well.
Active and Passive Monitoring
0:00As we delve deeper into the conversations around network assurance, we're going
0:04to need to understand that there is a difference between what we call active
0:08monitoring and passive monitoring.
0:11And the good news is that both have a place in the modern network. We just need
0:15to understand the difference as much as anything because Cisco wants us to know
0:19this. It's on the exam blueprint.
0:21But we're also going to need to know and understand these concepts as we look
0:25at applying different thousandized tests into our environment.
0:29So what is the difference between active monitoring and passive monitoring?
0:35Well, as the name implies, we're going to see a little bit more involvement on
0:39the active monitoring side, but it doesn't necessarily make it better.
0:43So let's just set some groundwork here as far as what the difference is.
0:48When we're talking about active monitoring, what we're saying is that we are
0:55generating traffic.
0:57And that's usually the biggest flag to tell whether this is an active
1:01monitoring type of situation or not. But ultimately what we're doing is we are
1:07allowing some form of an outside influence onto the network.
1:13In other words, the question we might ask is what happens if I were to not
1:19actually apply or maybe I should say, if I were to apply this monitoring to a
1:23network and compare it to what the network traffic looks like.
1:26If I'm not actually monitoring, is the situation the exact same?
1:30If I'm generating traffic as part of my monitoring, then the scenario where I'm
1:33monitoring is going to look different from the scenario where I'm not
1:37monitoring because there's going to be traffic here that wouldn't be there if I
1:41wasn't monitoring
1:43versus passive monitoring, which says that there is no outside influence on the
1:49network.
1:51And so from a practical perspective, usually what we're saying is that there is
1:59no extra traffic being generated.
2:03In other words, let's say that I want to find out what the latency is for a
2:07site.
2:08So I've got users on my network.
2:14Here's my network. And so we've got a bunch of these users. And then I've got
2:22this site out here in maybe it's on the internet, maybe it's in my data center,
2:25whatever the situation is.
2:27So here's the question. I want to know the latency, the response time,
2:33potentially, round trip time, whatever I want to describe it, but we want to
2:38test the responsiveness of this site.
2:42So let's say that I put a network device out on the network. And the purpose of
2:47this device is to serve as a network sensor for the sake of monitoring.
2:52At this point, I'm going to configure this to be sending a constant stream of p
2:59ings back and forth to this site to try to track the latency.
3:04And so I'm going to track and see that it was 30 milliseconds and 60
3:07milliseconds and so on and so forth. But check out all of this traffic.
3:12This is an outside influence. I have deployed this device. It is generating all
3:17kinds of traffic on my network. This might well be creating a burden here on
3:22all of these network devices in the land.
3:26And it might be creating a burden on the site itself. We already had a bunch of
3:30users trying to use this site. Now I've got this other device that's just
3:35sending a bunch of traffic.
3:37As opposed to, let's say I have an agent on one of these users machines or
3:41maybe all of the user machines. And it's just passively listening.
3:45It listens to a request go out and it can tell when the request comes back. And
3:50so it logs that there was 30 milliseconds involved of latency.
3:55And so the end result is the same. But in this case, this traffic was happening
4:00anyways. We had no extra traffic generated and no outside influence.
4:05So this is the concept of active monitoring here. And this is the concept of
4:12passive monitoring up here.
4:15So there is a worthwhile conversation to have about the pros and cons of each
4:22solution. So we're looking at the pros and we're looking at the cons.
4:33And yes, there are pros and cons with each one. This is not again, not a
4:37situation where we look at this and say one of these is always better than the
4:40other.
4:41For example, with active monitoring, I might be sending these pings constantly,
4:46which could cause extra traffic. So we'll say that this is an increase in the
4:50burden on the network.
4:52We already said that that is certainly a downside. I'm going to add a burden to
4:57the network resources.
5:01Whether those are switches and routers or again servers or whatever the
5:05situation is. We've increased the burden to those resources.
5:09However, the upside is that we have also increased our ability to detect an
5:16issue. So this is going to actually create a situation where this is faster to
5:22detect.
5:30The reason why it's faster to detect is because this user here might have
5:34pointed themselves out to that website and then 10 minutes later, they point to
5:38the website again.
5:39And this is working great when they first send a request, but then the
5:43performance of the site goes way down for five whole minutes.
5:47And then it's back up. And then the next time this device tries to reach out to
5:52the website, the website is performing again.
5:55Whereas if we're sending this every one minute via the active monitoring, which
5:59is typically what we see, then we're going to notice that there was this outage
6:04here in the middle, or at least an increase in latency.
6:08And so we're more likely to detect issues. It's faster to detect issues with
6:12the downside being that we are constantly hitting that site with a bunch of
6:17traffic.
6:19Now, one other note in this is that we might also say that the downside to this
6:23is it could also be inaccurate.
6:26The reason why I say it might be inaccurate is because whatever we're doing
6:30with this active monitoring session, this is in some way supposed to be em
6:36ulating real traffic.
6:39Now, if we're just running pings, then there's not a whole lot of difference
6:42between the two.
6:43But what if we're running pings here to test latency, but up here we're testing
6:49actual HTTP sessions and actual HTTP exchanges?
6:55Well, this is probably a little bit more accurate to test latency of the server
7:00, which has to take the request in and process it and send information back
7:05versus a ping, which is relatively lightweight.
7:08So even though we're more likely to see the issue that occurs and we're likely
7:13to see it faster, it might not actually be as accurate as an actual or as a
7:17passive test, which is monitoring real traffic.
7:21Now, for passive monitoring, we basically flip these. The upside to this is
7:26that there is no additional burden, and it is extremely accurate.
7:34The problem with this, and by the way, it's accurate because again, it's
7:37looking at actual real traffic.
7:39The downside to this is that we are less likely to see an issue when it occurs,
7:47and it is going to be slower to detect it.
7:54So, which one is better? And as I said earlier, there isn't a better one. Both
7:59of these options, let's change color.
8:02Let's say the active monitoring and the passive monitoring, both of these are
8:07going to find purpose in the network.
8:10There might be a situation where what we really care about is just doing these
8:14lightweight pings to test latency or potentially even uptime and check in on
8:19the server regularly.
8:21And the users who are sporadically accessing the server, we might care a little
8:25bit more about how long it takes to load web pages.
8:29And so, we might do some form of network test via the active side, and on the
8:34passive side, we might look at actual HTTP page loads.
8:39And so, as we can tell, when it comes to thousand eyes, we are going to use
8:44both of these mechanisms.
8:47Our agents are going to allow for both active and passive monitoring, and it's
8:52going to depend on the test.
8:56As we saw earlier, when we talked about the different tests, we saw that there
9:00are real user tests that can be triggered.
9:03There are the dynamic tests that actually are monitoring real WebEx calls, for
9:08example.
9:09If I'm monitoring a real WebEx call, this is going to be a passive test.
9:15I don't need to generate additional traffic. I don't want to add burden to my
9:19WebEx servers.
9:21I just want to listen to the WebEx call, and at the end, evaluate whether it
9:24was a successful call, or if there's some issue on the network that might have
9:29caused a port call quality.
9:33Versus, if I just want to, again, test some form of uptime and do a network
9:38test, a lot of our network tests, are going to require constant pings and
9:43constant trace routes to be sent out.
9:45And so a lot of these are going to be active. And so, again, when we're looking
9:51at thousand eyes, when we're thinking about different tests to deploy, we
9:55should be thinking, is this an active test?
9:58Is this a passive test? Thousand eyes isn't going to call it this.
10:01But when we understand what the test is doing, we'll have a sense of whether
10:04this is active or passive, and from there, we're going to understand, is this
10:08going to be a problem when we evaluate the pros and cons?
10:12[BLANK_AUDIO]
Other Cisco Solutions
0:00Well, certainly the primary scope of this course and exam is to look at
0:04thousand eyes.
0:06But when it comes to network assurance, Cisco has quite a few other products
0:10out there that
0:11can help us out, especially if we have a very specific use case.
0:16Now the advantage of thousand eyes is it provides more of an end-to-end
0:19approach to network
0:20monitoring, but it is important for us to know what other products Cisco has
0:23available
0:24for us.
0:25Now, a few of these we've already mentioned.
0:27Cisco's DNA center, which is now known as Catalyst Center, this is going to
0:32help us,
0:33especially when we're deploying software-defined access fabrics.
0:37So we are talking about campus networking.
0:40This is an SDN architecture.
0:42When we're talking about DNA and Catalyst Center, what we're really saying is
0:47that this
0:48is a software-defined networking controller.
0:52One of the advantages to software-defined networking controllers is the
0:55aggregation of data.
0:58So this is a powerful engine because we can take the data, we can run analytics
1:03, and from
1:04there we can run some amount of network assurance that's focused on this scope.
1:11Now the upside and downside to this is that we are again focusing on this scope
1:15, which
1:16means that we could get very granular very quickly when it comes to SDA and the
1:20campus
1:21environment, which by the way does include wireless.
1:24The downside of course is that it only covers SDXs and our campus environments
1:30with a few
1:30exceptions.
1:32But as we look at Cisco's other product portfolios, we start to see that their
1:37solutions are
1:38great, but they are generally speaking locked down to a specific part of our
1:43network.
1:44For example, if I look at Cisco's application-centric infrastructure, which is
1:49known as ACI,
1:50application-centric infrastructure is built for our data center infrastructures
1:57.
1:57So this is going to be inside the data center and only inside the data center.
2:04It requires a spine and leaf architecture, and once again this is an SDN
2:09solution, and
2:10we have a controller called the APIC, the application policy infrastructure
2:15controller,
2:16and this is going to largely accomplish the same thing we just talked about.
2:21It's going to aggregate data and it's going to lead to analytics and assurance
2:25within
2:26this specific scope.
2:30Now from here we have other products as well we could talk about.
2:33For example, we have SDWAN analytics for the SDWAN space.
2:37We also have Meraki Insight.
2:40This is an important one for our Meraki environments and specifically for our
2:46Meraki environments
2:47of course.
2:48And then we should also be aware of Cisco's acquisition of AppDynamics, which
2:52at this
2:53point is probably isn't even fair to call it an acquisition because it's been
2:57so long
2:58and eventually it just becomes a Cisco product.
3:00AppDynamics is a monitoring tool that actually goes inside of our code within
3:08our applications.
3:10It's a very fascinating product and we're actually going to find that Cisco
3:141000Is
3:15has integration with AppDynamics as well.
3:20But be aware that AppDynamics is intended for our developers more so than our
3:24network
3:25admins.
3:26In a lot of ways the things that these products do for us for monitoring our
3:30networks, AppDynamics
3:31does for the developers who are developing code where they can very quickly
3:35identify
3:36where there are issues in their code and especially if there's any kind of
3:40impact on user experience
3:42caused by the way an application has been developed.
3:46That's something that AppDynamics can very powerfully deliver.
3:50So when it comes to the scope of this course we again are focusing in on 1000Is
3:56.
3:56Now 1000Is is great because once again it's end to end.
4:04It starts with our endpoint agents.
4:07It can go all the way to a site or a service.
4:11Again, a software is a service potentially.
4:14It can go into the cloud.
4:16It can start in the cloud and it can look at even our ISP monitoring BGP routes
4:22and
4:22all kinds of things.
4:24So it provides a very powerful end to end and global view of the network.
4:29But it's not to say that any of these other solutions are worthless if we have
4:341000Is.
4:35I might want to drill into the details of my campus environment or my data
4:39center environment
4:40or my SD-WAN and certainly 1000Is isn't going to provide the same services that
4:46AppDynamics
4:46provides.
4:48So what exactly do we need to be aware of here?
4:52Well, again, for the scope of this course and the scope of this exam we
4:55absolutely are
4:56going to need to know how to configure 1000Is.
5:02We're going to spend pretty much the whole rest of the course talking about it.
5:05As for the rest of these solutions we don't need to worry about configuring
5:08them but we
5:09do need to understand their purpose and again these scopes.
5:14Where do they play?
5:15The SD-WAN and Maraki, it's sort of right there in the name.
5:19But where does AppDynamics play?
5:21Where does Catalyst Center play?
5:23Where does ACI and the APIC play?
5:25If we understand all of these different solutions then we can speak to
5:29ultimately what Cisco
5:30wants us to understand which is that they have a powerful portfolio around
5:36network assurance.
5:38Network assurance is not new.
5:40With 1000Is it was not something Cisco was unaware of until they acquired 1000
5:45Is it's
5:45something they've been doing for a very long time with all of these other
5:49products.
5:50Now that we have 1000Is we have yet another network assurance product but one
5:54that is
5:55able to do something that none of these other products were able to do on their
5:58own which
5:59again is focusing in on this end to end global view of our networks.
ThousandEyes Big Picture Challenge
0:00All right, let's bring it all together based on what we know.
0:05Let's look at this type of scenario where we have a network that's been
0:10established and
0:11we want to perform some amount of monitoring using 1000Is.
0:15So number one, for example, what are these things that are out on our network?
0:20Number two here, what happens when we're selecting those things and generating
0:24some amount of
0:25traffic when we detect an issue, what happens?
0:28I mean, ultimately, we should be going back through our terminology in our voc
0:31ab and
0:32thinking through all of the components and for that matter, the types of
0:35monitoring that
0:36we talked about throughout the last couple of skills to make sure that we see
0:40the end
0:40to end big picture of how 1000Is comes together.
0:44Once you're done, click the video and we will review this together.
ThousandEyes Big Picture Challenge
0:00Well, hopefully you took the time with a piece of paper and a pencil to jot
0:04this all out,
0:04make sure we've got all of this terminology down because this is foundational
0:08knowledge.
0:09Now I do recognize that maybe my diagram is a little busy in places, but
0:13hopefully it
0:14was clear enough that we could figure out which components go where.
0:18So let's just go ahead and go through this.
0:19First of all, we have our agents.
0:22We absolutely need to know there are three different types of agents.
0:25We have the endpoint agents, the enterprise agents, and the cloud agents.
0:29If you didn't label the types, that's perfectly fine.
0:32Just recognizing that we have the agents out there on the network and we use
0:36tests to
0:37select agents and generate traffic.
0:40So that would be number two here.
0:42Number three, if we detect an issue, we are going to use our alerts in order to
0:47allow
0:48the admins to know that something is up.
0:50We might also, by the way, use events.
0:53Just keep in mind the difference there is that alerts are configured and events
0:57are
0:57more anomaly detection.
0:59We're not configuring events.
1:01Number four here is how do we filter all of these agents?
1:04How do we filter all of the tests?
1:06We can use labels for this.
1:08That's a very powerful tool that we're going to want to use when we're config
1:12uring thousand
1:12eyes.
1:13And then lastly, our two types of monitoring, we're just kind of going off of
1:16the color
1:17coating here.
1:18If we have generated traffic, we are creating that again, we have an outside
1:23impact or an
1:24outside influencer on our network, this would be active monitoring where we may
1:29be told
1:29this cloud agent to generate this traffic.
1:33That was the idea of this pointing in here is to say that this is generated
1:38traffic versus
1:39natural traffic or traffic that was occurring anyways.
1:43We're just going to listen to that.
1:44That would be passive monitoring.
1:46Again, there's no right or wrong answer objectively in every case between
1:51active and passive monitoring,
1:53but naturally thousand eyes with its many different testing types, some of them
1:57are
1:57active, some of them are passive.
1:59And once again, we need to understand the difference.
2:01So ultimately, this was a little bit of just hitting vocab hard, but it's more
2:06than just
2:07vocab.
2:08These are the fundamental building blocks of how thousand eyes operates.
2:11As we go into the configuration of thousand eyes, we must understand the
2:15different types
2:16of agents, the role of tests and alerts and all of this comes together.
2:21Ultimately, we'll also see views and dashboards.
2:25And without any of these components in place, we really can't have a successful
2:28thousand eyes
2:29deployment.
2:30I hope there's been informative for you and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year