Tuesday, February 2, 2021

SIEM continued ...

 The integration of tools also depends on cloud support. Most event processing automation such as IT process automation, service desks for trouble ticketing, and CMDB require or support some form of cloud computing. These are predominantly hybrid cloud or virtualized infrastructure, microservices/containers, AWS, Azure, and Google cloud, usually in that order. This is a growth area for all event processing platforms and cloud vendors are increasingly providing an altruistic toolset for the integration of applications and monitoring of resources. The landscape for advanced IT Operations analytics shows a need for discovery, dependency mapping, and automation of applications with their integrations. These dependencies are discovered via a mix of both agent-based and agentless techniques. Native discovery contributors are primarily containers in a private cloud, layer 3 logical layer, data center elements, and component detail, virtualized environments in a private cloud, and microservices in a private cloud. 

These challenges from the variety of data types and integrations indicate that the data is not always collected in the form that it can usually be analyzed for insights. While preparation of data is the predominant time-consuming factor, the discovery of data and the investment in automation to keep it coming are more so. On the bright side, the analysis may take much lesser time and platforms are best suited to define the automation for data collection, the preparation for the data, and the heuristics to help with the analysis phase. 

AIOps deals with the following requirements on triage: Isolate whether the problem is within the  application, server, network, or database, investigate across virtualized systems, isolate infrastructure issues internal to systems, those within the database, those within the storage,  investigate across application tiers, isolate middleware issues, isolate infrastructure issues in the network, isolate infrastructure issues within the public cloud, visibility from the branch into issues such as QoS and such others. 

No comments:

Post a Comment