Monitoring & NOC

Optional packaged Monitoring module with probe SNMP ingest, NOC dashboards, policy trees, and entitlement-aware gates-honest about sampling, retention settings, and SIEM connector backlog.

Monitoring & NOC

Visual summary before deep technical copy below.

NOC-style analytics display for monitoring module evaluations

Feature depth

Monitoring & NOC

Optional packaged Monitoring module with probe SNMP ingest, NOC dashboards, policy trees, and entitlement-aware gates-honest about sampling, retention settings, and SIEM connector backlog.

  • Packaged Monitoring module entitlement
  • NOC dashboards and policy trees
  • Probe collector ingest and rollups
Modularentitlement-aware module
Scroll to full details

Monitoring is a packaged module-not implicit in every SKU. Super Admins enable globally; tenant entitlements gate navigation and API routes. Disabled modules return clear errors instead of silent partial features.

Probe collector: SNMP and related ingest paths buffer locally with platform rollup settings controlling raw retention, catch-up windows, and maintenance ticks. Noisy tenants are bounded by sampling and retention configuration documented in platform settings.

NOC experience: Dashboards and lazy policy trees target operator speed at fleet scale-expand nodes on demand rather than loading entire policy forests client-side.

Telemetry discipline: Align with ingestion guidelines: compress payloads, avoid unbounded custom fields, and attribute per-tenant in logs for chargeback. Forward exports to your APM or SIEM per deployment architecture.

Module scope: Use Trustholm monitoring where probe rollup and script-adjacent NOC workflows align with your module entitlements.

Rollup and cost control: ProbeRollup settings govern raw retention, catch-up hours, and maintenance windows-tune for noisy SNMP estates. Document effective sampling in customer contracts where telemetry volume affects infrastructure cost.

Entitlement transparency: Disabled Monitoring module should hide navigation and return explicit API errors-prevents accidental reliance on features not in SKU. Super Admin global toggle plus tenant entitlement lines should appear in billing documentation.

NOC operator training: Lazy policy trees require expand-on-demand mental model-different from loading entire forests upfront. Train operators on quick filters and saved views for 1024×768 operator workstations.

SIEM honesty: Forward HTTP logs and audit exports via pipelines you operate. Native Sentinel DCR connector remains backlog-state in monitoring sections of security questionnaires to avoid overstated real-time detection claims.

Capacity planning notes

Probe ingest volume scales with device counts and poll intervals-tune ProbeRollup before onboarding SNMP-heavy clients. NOC dashboards target operator workstations at 1024×768 minimum; verify layouts during trial. Module-off states should be tested in navigation and API quarterly so SKU changes do not surprise technicians mid-incident.

Procurement note: Monitoring SKUs are separate entitlement lines-quote probe capacity explicitly for government buyers with telemetry retention requirements in contract schedules.

Operator ergonomics: Validate NOC layouts during incident simulation exercises-not only static UI review-so on-call engineers can acknowledge alerts within target MTTA during pilot week.

Cost transparency: Model probe ingest growth against ProbeRollup retention when quoting monitoring SKUs-surprise telemetry bills erode trust faster than feature gaps in regulated accounts.

Module boundary clarity: When Monitoring is off, document in customer architecture that NOC and probe paths are out of scope-prevents implied feature assumptions during IRAP or SOC 2 walkthroughs. Quote monitoring SKUs separately in proposals to align contractual scope with technical gates. Operators should validate module gates during trial so SKU changes do not surprise technicians mid-incident.

Alert fatigue governance: Define severity routing before enabling NOC dashboards for noisy SNMP estates. Pair ProbeRollup tuning with operator runbooks so alert volume remains actionable at 1024×768 operator workstations during overnight shifts.

Hybrid observability: Document which alerts originate from which system in customer architecture diagrams submitted to enterprise buyers.

Probe onboarding checklist: Before SNMP-heavy client cutover, validate poll interval, credential rotation, and ProbeRollup retention in trial tenant with representative device count. Document effective settings in customer contract appendix to align commercial SLAs with telemetry cost reality.

Incident bridge documentation: During sev-1 events, note which monitoring surface-Trustholm NOC versus incumbent RMM-owns each alert type in incident bridge template. Reduces operator confusion when both systems are active during migration years.

Run entitlement-off UX test after each billing migration. Capture screenshots of module-gated errors for customer architecture appendices when Monitoring is not purchased.

Document probe capacity assumptions in statements of work to align SNMP estate size with SKU entitlements. Validate rollup retention settings against customer contractual log retention before go-live sign-off.

Include Monitoring module off-state in architecture diagrams for customers who purchase agent and script entitlements only.

Frequently asked questions

Is monitoring included in every trial?

Depends on marketing bundle entitlements loaded from API. Agent Management can trial without Monitoring module enabled. Confirm SKU lines before promising NOC features in customer proposals.

What probes are supported?

Probe collector patterns document SNMP ingest; exact device coverage depends on collector configuration and modules enabled in your tenant. Pilot with representative customer SNMP estates before portfolio rollout.

How long is raw telemetry retained?

ProbeRollup platform settings define raw retention and rollup intervals. Document effective retention in your SSP-defaults are not universal compliance guarantees. Align retention with customer contract SLAs.

Does monitoring integrate with Sentinel?

HTTP log forwarding and audit export exist; native Sentinel DCR connector is backlog. Plan SIEM integration via export or log pipeline you operate and document interim architecture honestly.