Purpose
The Monitoring Pattern defines the approved reference architecture for monitoring, logging, auditing, alerting, reporting, and operational visibility within University-managed technology environments.
This pattern describes how workloads, platforms, enterprise services, shared services, and operational teams interact with monitoring capabilities to support operations, investigations, governance, auditing, and service management.
The pattern provides a common monitoring architecture that supports operational awareness, platform management, troubleshooting, investigation, and enterprise visibility.
Applicable standards, workload classifications, data classifications, and obligations determine the monitoring controls implemented within this architecture.
Use Cases
This pattern applies when:
- Monitoring applications
- Monitoring databases
- Monitoring platform services
- Monitoring infrastructure services
- Monitoring integrations
- Monitoring shared services
- Providing operational visibility
- Providing security visibility
- Providing audit visibility
- Providing enterprise operational reporting
This pattern does not define:
- Logging requirements
- Retention requirements
- Specific alerts
- Specific telemetry requirements
- Audit requirements
- Compliance reporting requirements
- Investigation procedures
- Operational response procedures
Pattern Application
The Monitoring Pattern provides a common monitoring architecture for University-managed workloads.
Innovation Workloads
Innovation workloads may implement simplified monitoring architectures appropriate for experimentation, evaluation, pilot initiatives, and research activities.
Enterprise Workloads
Enterprise workloads implement the Monitoring Pattern using the standard enterprise monitoring architecture.
Regulated Workloads
Regulated workloads implement the Monitoring Pattern using additional monitoring integrations, visibility capabilities, and obligation-specific architecture extensions.
Design Principles
Centralized Monitoring
Monitoring services provide common visibility capabilities that may support multiple workloads, platforms, and hosting environments.
Operational Visibility
Monitoring architectures provide visibility into workload, platform, infrastructure, operational, and service health.
Security Visibility
Monitoring architectures support observation of activities relevant to security operations, investigations, and governance functions.
Auditability
Monitoring architectures support auditing, investigations, accountability, and operational reviews through observable telemetry and activity records.
Composable Architecture
Monitoring capabilities are assembled from reusable architecture components supporting multiple hosting architectures and workload classifications.
Shared-Service Integration
Monitoring services may operate as shared enterprise capabilities supporting multiple workloads and hosting environments.
Logical Architecture
Workload
|
+-- Applications
+-- Databases
+-- Platform Services
+-- Infrastructure Services
+-- Integration Services
|
v
Telemetry Collection
|
+-- Operational Activity
+-- Service Activity
+-- Identity Activity
+-- Platform Activity
|
v
Monitoring Platform
|
+-- Dashboards
+-- Reporting
+-- Alerting
+-- Investigation Support
+-- Audit Support
|
v
Operations
Security
Governance
Audit
Workload Teams
Monitoring Architecture Components
Telemetry Collection Component
Provides the collection architecture used to gather telemetry from workloads, platforms, services, and supporting infrastructure.
Monitoring Platform Component
Provides centralized monitoring capabilities supporting operational visibility, reporting, alerting, investigations, and auditing.
Operational Monitoring Component
Provides visibility into platform health, workload health, service health, capacity, availability, and operational status.
Application Monitoring Component
Provides visibility into application behaviors, service interactions, integration activity, and workload operations.
Identity Monitoring Component
Provides visibility into authentication, authorization, administrative activity, workload identities, and related identity events.
Security Monitoring Component
Provides visibility supporting investigations, incident analysis, security operations, and governance activities.
Audit Visibility Component
Provides monitoring capabilities supporting auditing, accountability, governance reviews, and operational reporting.
Reporting Component
Provides dashboards, operational reporting, governance reporting, investigation support, and visibility services.
Monitoring Domains
Workload Monitoring
Provides visibility into applications, data platforms, integrations, services, and workload operations.
Platform Monitoring
Provides visibility into platform services, infrastructure services, cloud resources, and hosting services.
Identity Monitoring
Provides visibility into enterprise identity services, authentication activity, authorization activity, and administrative operations.
Shared-Service Monitoring
Provides visibility into enterprise services supporting multiple workloads.
Operational Monitoring
Provides visibility supporting service management, operational support, troubleshooting, and service reliability.
Security Monitoring
Provides visibility supporting investigations, security operations, governance activities, and incident response.
Monitoring Boundaries
Workload Monitoring Boundary
The workload monitoring boundary contains telemetry and visibility associated with a workload and its supporting services.
Platform Monitoring Boundary
The platform monitoring boundary contains telemetry and visibility associated with hosting platforms, infrastructure, and enterprise services.
Enterprise Monitoring Boundary
The enterprise monitoring boundary contains centralized monitoring services supporting multiple workloads and hosting environments.
Audit Boundary
The audit boundary contains monitoring information used by governance, audit, operational review, and accountability functions.
Monitoring Integration
Identity Integration
The Monitoring Pattern integrates with the Identity Pattern to provide visibility into authentication, authorization, administrative activity, and workload identities.
Network Integration
The Monitoring Pattern integrates with the Network Pattern to provide visibility into connectivity, communication paths, network operations, and related activities.
Data Protection Integration
The Monitoring Pattern integrates with data-protection capabilities to provide visibility into protection activities, recovery activities, and data operations.
Resilience and Recovery Integration
The Monitoring Pattern integrates with resilience and recovery capabilities to provide visibility into failures, restoration activities, recovery operations, and service health.
Shared-Service Integration
The Monitoring Pattern integrates with approved enterprise shared services to provide centralized visibility capabilities.
Landing Zone Integration
Landing Zones implement this pattern through approved monitoring architectures and reusable monitoring components.
Operational Responsibilities
Enterprise Service Providers
Enterprise service providers own monitoring platforms, monitoring architecture, monitoring services, and enterprise visibility capabilities.
Platform Engineering
Platform Engineering owns reusable monitoring integration components, onboarding automation, and Landing Zone monitoring integration.
Information Security
Information Security consumes monitoring capabilities for governance, security operations, investigations, and architecture review activities.
Operations Teams
Operations teams use monitoring capabilities to support operational management, troubleshooting, service health visibility, and service support.
Workload Teams
Workload teams own workload telemetry, workload monitoring integration, application instrumentation, and workload operational visibility.
Automation Pattern
Monitoring architectures should be implemented through approved platform automation whenever practical.
Automation may support:
- Monitoring enrollment
- Telemetry integration
- Platform integration
- Identity integration
- Network integration
- Landing Zone integration
- Reporting integration
- Workload onboarding
Monitoring Definition
|
+-- Telemetry Collection
+-- Monitoring Integration
+-- Reporting Integration
+-- Visibility Services
|
v
Reusable Monitoring Components
|
v
Landing Zone or Workload Deployment
|
v
Integrated Monitoring Architecture
Monitoring automation components should be reusable across supported workload classifications, hosting architectures, and platform products.
Reference Architecture Outcomes
A workload implementing this pattern should provide:
- Operational visibility
- Security visibility
- Audit visibility
- Identity visibility
- Platform visibility
- Workload visibility
- Investigation support
- Operational supportability
- Centralized monitoring integration
- Reusable monitoring architecture
- Repeatable onboarding
- Support for workload and obligation-specific extensions
Exceptions
Exceptions to this pattern must follow approved architecture governance and information security exception processes.
Approved exceptions must be periodically reviewed and must not be treated as permanent architecture patterns.