DRAFT: Monitoring Pattern

Tags azure Pattern

Purpose

The Monitoring Pattern defines the approved reference architecture for monitoring, logging, auditing, alerting, reporting, and operational visibility within University-managed technology environments.

This pattern describes how workloads, platforms, enterprise services, shared services, and operational teams interact with monitoring capabilities to support operations, investigations, governance, auditing, and service management.

The pattern provides a common monitoring architecture that supports operational awareness, platform management, troubleshooting, investigation, and enterprise visibility.

Applicable standards, workload classifications, data classifications, and obligations determine the monitoring controls implemented within this architecture.

Use Cases

This pattern applies when:

  • Monitoring applications
  • Monitoring databases
  • Monitoring platform services
  • Monitoring infrastructure services
  • Monitoring integrations
  • Monitoring shared services
  • Providing operational visibility
  • Providing security visibility
  • Providing audit visibility
  • Providing enterprise operational reporting

This pattern does not define:

  • Logging requirements
  • Retention requirements
  • Specific alerts
  • Specific telemetry requirements
  • Audit requirements
  • Compliance reporting requirements
  • Investigation procedures
  • Operational response procedures

Pattern Application

The Monitoring Pattern provides a common monitoring architecture for University-managed workloads.

Innovation Workloads

Innovation workloads may implement simplified monitoring architectures appropriate for experimentation, evaluation, pilot initiatives, and research activities.

Enterprise Workloads

Enterprise workloads implement the Monitoring Pattern using the standard enterprise monitoring architecture.

Regulated Workloads

Regulated workloads implement the Monitoring Pattern using additional monitoring integrations, visibility capabilities, and obligation-specific architecture extensions.

Design Principles

Centralized Monitoring

Monitoring services provide common visibility capabilities that may support multiple workloads, platforms, and hosting environments.

Operational Visibility

Monitoring architectures provide visibility into workload, platform, infrastructure, operational, and service health.

Security Visibility

Monitoring architectures support observation of activities relevant to security operations, investigations, and governance functions.

Auditability

Monitoring architectures support auditing, investigations, accountability, and operational reviews through observable telemetry and activity records.

Composable Architecture

Monitoring capabilities are assembled from reusable architecture components supporting multiple hosting architectures and workload classifications.

Shared-Service Integration

Monitoring services may operate as shared enterprise capabilities supporting multiple workloads and hosting environments.

Logical Architecture

Workload
        |
        +-- Applications
        +-- Databases
        +-- Platform Services
        +-- Infrastructure Services
        +-- Integration Services
        |
        v

Telemetry Collection
        |
        +-- Operational Activity
        +-- Service Activity
        +-- Identity Activity
        +-- Platform Activity
        |
        v

Monitoring Platform
        |
        +-- Dashboards
        +-- Reporting
        +-- Alerting
        +-- Investigation Support
        +-- Audit Support
        |
        v

Operations
Security
Governance
Audit
Workload Teams

Monitoring Architecture Components

Telemetry Collection Component

Provides the collection architecture used to gather telemetry from workloads, platforms, services, and supporting infrastructure.

Monitoring Platform Component

Provides centralized monitoring capabilities supporting operational visibility, reporting, alerting, investigations, and auditing.

Operational Monitoring Component

Provides visibility into platform health, workload health, service health, capacity, availability, and operational status.

Application Monitoring Component

Provides visibility into application behaviors, service interactions, integration activity, and workload operations.

Identity Monitoring Component

Provides visibility into authentication, authorization, administrative activity, workload identities, and related identity events.

Security Monitoring Component

Provides visibility supporting investigations, incident analysis, security operations, and governance activities.

Audit Visibility Component

Provides monitoring capabilities supporting auditing, accountability, governance reviews, and operational reporting.

Reporting Component

Provides dashboards, operational reporting, governance reporting, investigation support, and visibility services.

Monitoring Domains

Workload Monitoring

Provides visibility into applications, data platforms, integrations, services, and workload operations.

Platform Monitoring

Provides visibility into platform services, infrastructure services, cloud resources, and hosting services.

Identity Monitoring

Provides visibility into enterprise identity services, authentication activity, authorization activity, and administrative operations.

Shared-Service Monitoring

Provides visibility into enterprise services supporting multiple workloads.

Operational Monitoring

Provides visibility supporting service management, operational support, troubleshooting, and service reliability.

Security Monitoring

Provides visibility supporting investigations, security operations, governance activities, and incident response.

Monitoring Boundaries

Workload Monitoring Boundary

The workload monitoring boundary contains telemetry and visibility associated with a workload and its supporting services.

Platform Monitoring Boundary

The platform monitoring boundary contains telemetry and visibility associated with hosting platforms, infrastructure, and enterprise services.

Enterprise Monitoring Boundary

The enterprise monitoring boundary contains centralized monitoring services supporting multiple workloads and hosting environments.

Audit Boundary

The audit boundary contains monitoring information used by governance, audit, operational review, and accountability functions.

Monitoring Integration

Identity Integration

The Monitoring Pattern integrates with the Identity Pattern to provide visibility into authentication, authorization, administrative activity, and workload identities.

Network Integration

The Monitoring Pattern integrates with the Network Pattern to provide visibility into connectivity, communication paths, network operations, and related activities.

Data Protection Integration

The Monitoring Pattern integrates with data-protection capabilities to provide visibility into protection activities, recovery activities, and data operations.

Resilience and Recovery Integration

The Monitoring Pattern integrates with resilience and recovery capabilities to provide visibility into failures, restoration activities, recovery operations, and service health.

Shared-Service Integration

The Monitoring Pattern integrates with approved enterprise shared services to provide centralized visibility capabilities.

Landing Zone Integration

Landing Zones implement this pattern through approved monitoring architectures and reusable monitoring components.

Operational Responsibilities

Enterprise Service Providers

Enterprise service providers own monitoring platforms, monitoring architecture, monitoring services, and enterprise visibility capabilities.

Platform Engineering

Platform Engineering owns reusable monitoring integration components, onboarding automation, and Landing Zone monitoring integration.

Information Security

Information Security consumes monitoring capabilities for governance, security operations, investigations, and architecture review activities.

Operations Teams

Operations teams use monitoring capabilities to support operational management, troubleshooting, service health visibility, and service support.

Workload Teams

Workload teams own workload telemetry, workload monitoring integration, application instrumentation, and workload operational visibility.

Automation Pattern

Monitoring architectures should be implemented through approved platform automation whenever practical.

Automation may support:

  • Monitoring enrollment
  • Telemetry integration
  • Platform integration
  • Identity integration
  • Network integration
  • Landing Zone integration
  • Reporting integration
  • Workload onboarding
Monitoring Definition
        |
        +-- Telemetry Collection
        +-- Monitoring Integration
        +-- Reporting Integration
        +-- Visibility Services
        |
        v

Reusable Monitoring Components
        |
        v

Landing Zone or Workload Deployment
        |
        v

Integrated Monitoring Architecture

Monitoring automation components should be reusable across supported workload classifications, hosting architectures, and platform products.

Reference Architecture Outcomes

A workload implementing this pattern should provide:

  • Operational visibility
  • Security visibility
  • Audit visibility
  • Identity visibility
  • Platform visibility
  • Workload visibility
  • Investigation support
  • Operational supportability
  • Centralized monitoring integration
  • Reusable monitoring architecture
  • Repeatable onboarding
  • Support for workload and obligation-specific extensions

Exceptions

Exceptions to this pattern must follow approved architecture governance and information security exception processes.

Approved exceptions must be periodically reviewed and must not be treated as permanent architecture patterns.