Home

Real time metric monitoring solution

%3CLINGO-SUB%20id%3D%22lingo-sub-128423%22%20slang%3D%22en-US%22%3EReal%20time%20metric%20monitoring%20solution%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-128423%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Community%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20work%20in%20a%20team%20which%20manages%20monitoring%26nbsp%3Bfor%20our%20on-prem%20Linux%26nbsp%3Benvironment.%20We%20have%20been%20asked%20to%20manage%20the%20monitoring%20for%20the%20cloud-based%20solution%20that%20our%20internal%20BU's%20are%20progressing%20with.%20We%20have%20noticed%20a%20massive%20lag%20in%20the%20threshold%20being%20triggered%20to%20the%20time%20we%20receive%20an%20alert.%20In%20some%20cases%2C%20it%20took%20over%209%20hrs%20and%20that%20was%20just%20a%20basic%20heartbeat%20search%20query%20which%20was%20checking%20every%205min%20for%20the%20last%204hrs%20which%20should%20have%20generated%20an%20alert.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20question%20to%20the%20community%20is%20what%20other%20solutions%20have%20you%20turned%20to%20which%20have%20helped%20you%20overcome%20this%20latency%20issue%3F%20We%20are%20in%20an%20industry%20where%20real-time%20is%20a%20must%2C%20as%20we%20are%20in%20the%20financial%20sector%20where%20time%20lost%20is%20money%20lost%20money.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eany%20suggestions%20or%20feedback%20is%20welcomed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3CP%3EJ%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-128423%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOMS%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOMS%20Operations%20Management%20Suite%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-129524%22%20slang%3D%22en-US%22%3ERe%3A%20Real%20time%20metric%20monitoring%20solution%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-129524%22%20slang%3D%22en-US%22%3ENear%20real%20time%20alerts%20are%20not%20for%20OMS%20alerts.%20Correct%20me%20if%20I%20am%20wrong.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-128734%22%20slang%3D%22en-US%22%3ERe%3A%20Real%20time%20metric%20monitoring%20solution%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-128734%22%20slang%3D%22en-US%22%3E%3CP%3EFor%20near%20real%20time%20alerting%20scenarios%20on%20metrics%2C%20we%20have%20announced%20a%20public%20preview%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-au%2Fblog%2Fget-alerts-faster-with-near-real-time-alerting-for-azure-platform-metrics%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fazure.microsoft.com%2Fen-au%2Fblog%2Fget-alerts-faster-with-near-real-time-alerting-for-azure-platform-metrics%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EAdditionally%20we%20are%20currently%20reviewing%20this%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22caps%22%3ESLA%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Ein%20particular%20as%20it%20relates%20to%20warm%20path%20logging.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-128675%22%20slang%3D%22en-US%22%3ERe%3A%20Real%20time%20metric%20monitoring%20solution%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-128675%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20James%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECan%20you%20post%20your%20query%3F%20I%20think%20you%20may%20be%20doing%20something%20in%20the%20query%20that%20is%20causing%20that%20level%20of%20lag.%20I'd%20say%2020%20minutes%20is%20a%20pretty%20reliable%20level%20of%20lag%20from%20condition%20to%20alert%20in%20my%20experience%2C%20so%20this%20sounds%20like%20either%20something%20wrong%20with%20the%20query%20you're%20using%20or%20there%20is%20some%20latency%20elsewhere%20in%20the%20system.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20have%20this%20query%20for%20latency%20that%20runs%20as%20an%20alert%2C%20and%20it%20pretty%20reliably%20gives%20me%20an%20idea%20when%20things%20are%20slow%20in%20the%20system%3A%3C%2FP%3E%0A%3CP%3EHeartbeat%3C%2FP%3E%0A%3CP%3E%7C%20order%20by%20TimeGenerated%3C%2FP%3E%0A%3CP%3E%7C%20limit%201%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20alert%20on%20that%20when%20the%20number%20of%20entries%20is%20less%20than%201.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20for%20your%20cloud%20based%20solution%3A%20OMS%2FAzure%20Log%20Analytics%20isn't%20very%20suited%20to%20endpoint%20monitoring%20(such%20as%20URLs%20and%20DNS%20responses).%20I've%20turned%20to%20Anturis%20for%20endpoint%20monitoring%20in%20the%20past%26nbsp%3Bas%20it%20is%20very%20low%20cost%20and%20can%20monitor%20anything%20with%20a%20URL%20attached%20to%20it.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOut%20of%20curiosity%2C%20how%20real%20time%20are%20you%20looking%20for%3F%20The%20last%20time%20I%20checked%20the%20SLA%20from%20OMS%2C%20latency%20of%20up%20to%202%20hours%20was%20within%20the%20SLA%2C%20but%20we've%20recently%20moved%20over%20to%20Azure%20Log%20Analytics%20and%20I%20haven't%20seen%20the%20SLAs%20within%20Azure%20Log%20Analytics.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-128518%22%20slang%3D%22en-US%22%3ERe%3A%20Real%20time%20metric%20monitoring%20solution%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-128518%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Kasun%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20responding%2C%20currently%20we%20use%20OMS%20but%20have%20noticed%20the%20lag%20in%20alerting%20vs%20threshold%20being%20breached.%20Even%20though%20its%20set%20to%205min%20polling%20for%20Alerting%20it%20takes%20far%20long%20for%20the%20alert%20to%20be%20triggered.%20I%20verify%20this%20by%20typing%20in%20Alert%20in%20Log%20Analytics%20which%20returns%20nothing%20for%20the%20past%201hr.%20Which%20is%20why%20I%20was%20wondering%20if%20people%20use%20anything%20else%20other%20than%20OMS%20to%20do%20metric%20monitoring.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJ%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-128467%22%20slang%3D%22en-US%22%3ERe%3A%20Real%20time%20metric%20monitoring%20solution%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-128467%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can%20use%20OMS%20for%20monitoring%20and%20give%20near%20real%20time%20monitoring%20for%20metrics.%20OMS%20also%20can%20generate%20alerts.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
James B
New Contributor

Hello Community,

 

I work in a team which manages monitoring for our on-prem Linux environment. We have been asked to manage the monitoring for the cloud-based solution that our internal BU's are progressing with. We have noticed a massive lag in the threshold being triggered to the time we receive an alert. In some cases, it took over 9 hrs and that was just a basic heartbeat search query which was checking every 5min for the last 4hrs which should have generated an alert. 

 

My question to the community is what other solutions have you turned to which have helped you overcome this latency issue? We are in an industry where real-time is a must, as we are in the financial sector where time lost is money lost money.

 

any suggestions or feedback is welcomed.

 

thanks

J

5 Replies

You can use OMS for monitoring and give near real time monitoring for metrics. OMS also can generate alerts.

 

Highlighted

Hi Kasun,

 

Thank you for responding, currently we use OMS but have noticed the lag in alerting vs threshold being breached. Even though its set to 5min polling for Alerting it takes far long for the alert to be triggered. I verify this by typing in Alert in Log Analytics which returns nothing for the past 1hr. Which is why I was wondering if people use anything else other than OMS to do metric monitoring.

 

J

Hi James,

 

Can you post your query? I think you may be doing something in the query that is causing that level of lag. I'd say 20 minutes is a pretty reliable level of lag from condition to alert in my experience, so this sounds like either something wrong with the query you're using or there is some latency elsewhere in the system.

 

I have this query for latency that runs as an alert, and it pretty reliably gives me an idea when things are slow in the system:

Heartbeat

| order by TimeGenerated

| limit 1

 

I alert on that when the number of entries is less than 1.

 

As for your cloud based solution: OMS/Azure Log Analytics isn't very suited to endpoint monitoring (such as URLs and DNS responses). I've turned to Anturis for endpoint monitoring in the past as it is very low cost and can monitor anything with a URL attached to it.

 

Out of curiosity, how real time are you looking for? The last time I checked the SLA from OMS, latency of up to 2 hours was within the SLA, but we've recently moved over to Azure Log Analytics and I haven't seen the SLAs within Azure Log Analytics.

For near real time alerting scenarios on metrics, we have announced a public preview https://azure.microsoft.com/en-au/blog/get-alerts-faster-with-near-real-time-alerting-for-azure-plat...

Additionally we are currently reviewing this SLA in particular as it relates to warm path logging. 

Near real time alerts are not for OMS alerts. Correct me if I am wrong.
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies