pierre roman| senior cloud ops advocate

25
Protecting Your Cloud Investment Part 1 – Monitoring your Azure Resources Pierre Roman| Senior Cloud Ops Advocate

Upload: others

Post on 25-May-2022

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Pierre Roman| Senior Cloud Ops Advocate

Protecting Your Cloud Investment

Part 1 – Monitoring your Azure Resources

Pierre Roman| Senior Cloud Ops Advocate

Page 2: Pierre Roman| Senior Cloud Ops Advocate
Page 3: Pierre Roman| Senior Cloud Ops Advocate

Azure Monitor – Key Points

Page 4: Pierre Roman| Senior Cloud Ops Advocate

Azure Monitor – Continuous Monitoring across app, infra and network

Changes in monitoring

Infrastructure

Apps

Network

Developers

IT Ops

Network Admins

Traditional monitoring

DevOps/SRE culture

Developers

IT Ops

Network Admins

App

Infra

Analytics and AI

Azure Monitor

Network

Page 5: Pierre Roman| Senior Cloud Ops Advocate

Building a modern monitoring solution

Investigative experiences powered by machine learning capabilities to

help identify and solve problems

Works well with third party products and has a rich ecosystem of partner

integrations

Native, near-real time, seamless experience for monitoring

Azure resources

Integrated Intelligent Interoperable

Page 6: Pierre Roman| Senior Cloud Ops Advocate

Azure Monitor Modern Solution

Detect & diagnose issues across apps and dependencies with application insights

Page 7: Pierre Roman| Senior Cloud Ops Advocate

Azure Monitor Modern Solution

Correlate issues at infra level with insights for VMs, containers, SQL, network, etc.

Page 8: Pierre Roman| Senior Cloud Ops Advocate

Azure Monitor Modern Solution

Operationalize at scale with smart alerts and automated actions

Page 9: Pierre Roman| Senior Cloud Ops Advocate

Azure Monitor Modern Solution

Drill down with log analytics for troubleshooting & deeper diagnostics

Page 10: Pierre Roman| Senior Cloud Ops Advocate

Azure Monitor Modern Solution

Create visualizations with Azure dashboards & workbooks

Page 11: Pierre Roman| Senior Cloud Ops Advocate

Azure Monitor

Metrics

Logs

Application Container VM Network

Insights

Dashboards Power BI Workbooks

Visualize

Metrics Explorer Log Analytics

Analyze

Alerts Autoscale

Respond

Event Hubs Ingest & Export APIsLogic Apps

Integrate

Custom Sources

Application

Infrastructure

Network

Collect

End to End Monitoring

Page 12: Pierre Roman| Senior Cloud Ops Advocate

Collect

Azure Monitor

Custom Sources

Application

Operating System

Azure Resources

Azure Subscription

Azure Tenant

Zero instrumentationLogs & Metrics

AgentsWindows + Linux SupportWorkload Agnostic

Application Insights SDK/AgentMulti-Language Support

API

Metrics

Logs

Page 13: Pierre Roman| Senior Cloud Ops Advocate

Insights for Networks Traffic View & Diagnostics Toolkit for Networks ExpressRoute & Perf Monitoring in Connection Monitor v2

Insights for Containers Recommended metric alerts with default thresholds (Preview)

Kube-state & Network Policy Manager Metrics

Container Logs from AKS Clusters running Windows Server

Insights for Azure Resources Azure Monitor for Key Vault

Azure Monitor for Azure Cache for Redis

Azure Monitor for SAP Solutions (Preview)

Log Analytics for ARM based Windows Virtual Desktop

Out-of-the-Box Insights

* Some of those capabilities are still in preview

Page 14: Pierre Roman| Senior Cloud Ops Advocate

Alerts & Workflows

Azure Monitor Connectors Logs Connector for Azure Logic Apps & Power Automate

Actions

ITSM Connector for BMC Helix with Secure Export

Upgraded Experience for Log Alerts Support for Resource Centric Log Alerts

New API & Portal UX with guidance on optimized queries

Upgraded Experience for Metric Alerts Alert rules on Custom Metrics even before they are emitted

Multiple AND conditions for a single alert rule

Exclusion for dimension values

* Some of those capabilities are still in preview

Page 15: Pierre Roman| Senior Cloud Ops Advocate

Analyze• Built-in central analytics platform that is used

across Monitoring, Management, Security

• Scale to petabytes of data per day

• Easy access to your resource logs

• Run interactive queries for investigations, statistics & root cause/trend analytics

* Some of those capabilities are still in preview

Page 16: Pierre Roman| Senior Cloud Ops Advocate

Respond – Alerts• Unified and real-time alerting platform that

works across all monitoring capabilities

• Use machine learning to automatically detect right thresholds

• Automate alert creation with policies

• Take multiple actions and integrate with ITSM, DevOps and other tools

* Some of those capabilities are still in preview

Page 17: Pierre Roman| Senior Cloud Ops Advocate

Integrate – SIEM & incident management tools

• Integrate with popular DevOps, issue management, IT service management, and security information and event management tools

• Open and extensible so you build your own custom integration

Page 18: Pierre Roman| Senior Cloud Ops Advocate

Integrate – DevOps tools• Native IDE integrations in VS (.NET) and VS Code

(Node.js)

• Onboard with Azure Pipelines Release Management & DevOps Projects

• Configure Pre- or Post-Deployment Quality Gates in Azure Pipelines

• Run Load Test or Multi-Step Web Test for Synthetic Perf Monitoring

• Work Item Management with Azure Boards for filing bugs and tracking

• Alerts & Notifications with automated actions & ITSM integrations

Page 19: Pierre Roman| Senior Cloud Ops Advocate

Onboarding at Scale with Hybrid Support

Azure Monitor Agent & Data Collection Rules (Preview)• Replacing Log Analytics agent, Diagnostics extension &

Telegraf agent

• Centralized data collection rules for multiple VMs

• Linux multi-homing to different workspaces

• Windows event filtering with XPATH queries

Support for Azure Arc• Onboarding Arc enabled Servers (Preview)

• Onboarding Arc enabled Kubernetes Clusters (Preview)

Page 20: Pierre Roman| Senior Cloud Ops Advocate

Enterprise ReadinessDedicated Clusters for Log Analytics• Capacity Reservation across workspaces with discounted

pricing

• Data Encryption at Rest with Customer Managed Keys (CMK)

• Data Access Control during Support with LockBox

Workspace-based Application Insights• Converge App Logs with Platform/Infra Logs in One

Workspace

• Continuous Export to Storage/Event Hub via Diagnostic Settings

• Support for CMK Encryption & Private Link

• Capacity Reservation for application logs with discounted pricing

Log Analytics Query Auditing • Diagnostic Logs from Log Analytics Workspaces (Preview)

Page 21: Pierre Roman| Senior Cloud Ops Advocate

Demo: End to end Monitoring

Page 22: Pierre Roman| Senior Cloud Ops Advocate

Helping with your planMicrosoft Cloud Adoption Framework for Azure is a great starting place: http://aka.ms/Adopt

• Azure Cloud Monitoring Strategy defines a recommended approach to monitor each layer of the stack

• Guidance to develop configuration for Data Collection

• Guidance to develop an alerting strategy: Does it matter? Is it urgent? Who is affected? What else is affected?

Leverage Azure Architecture Center for architectural guidance, frameworks & best practices: http://aka.ms/AzureArchitecture

Page 23: Pierre Roman| Senior Cloud Ops Advocate

Next steps & resources

• Azure Monitor Updates:• https://aka.ms/AzrMonitorUpdates

• Documentation:• https://aka.ms/AzrMonitorDocs

• Useful Skills & Courses:• https://aka.ms/AzrMonitorSkills

• Case Studies:• https://aka.ms/AzrMonitorStories

• Repositories• Best practices for monitoring Azure

resources in addition to sample alerts, queries & workbooks.

• https://github.com/microsoft/AzureMonitorCommunity

Page 24: Pierre Roman| Senior Cloud Ops Advocate

Stay in touch!You can continue the conversation with my team and I.

Join our IT/Ops focused Discord serverhttps://aka.ms/itopstalk-discord

Subscribe to our bloghttps://www.itopstalk.com

Watch more of our contenthttps://www.youtube.com/c/ITOpsTalk

Send us your [email protected]

Page 25: Pierre Roman| Senior Cloud Ops Advocate

THANK YOU!