Using Statistics and Sensors to Ensure Network Availability

CompTIA Network+ • Chapter 14

Using Statistics and Sensors to Ensure Network Availability

Turn device health, traffic statistics, logs, and alerts into early warning signals. Learn to establish normal performance, recognize anomalies, and select the right monitoring evidence before users experience an outage.

BaselinesCPU & MemoryLatency & JitterSNMPNetFlow & SPANSyslog & SIEM
DEVICE HEALTHTRAFFIC METRICSLOG EVENTS
14.1 • Introduction

Availability Begins Before the Failure

Network availability is the ability of systems and services to remain reachable and usable when required. Downtime interrupts operations, weakens user trust, and can damage revenue and reputation. Effective operations therefore emphasize proactive monitoring: observing health and performance continuously so warning signs are discovered before they become outages.

◉

Observe

Collect metrics, events, logs, and traffic summaries from devices and services.

⌁

Compare

Compare current behavior with a baseline, threshold, SLA, or expected configuration.

⚑

Act

Alert the right team with enough context to investigate and correct the condition.

Monitoring is essentially listening to what the network is reporting. A useful system helps administrators detect early failure indicators, recognize degradation, establish normal behavior, and respond using actionable evidence.

Exam distinction: Monitoring detects and explains conditions. High availability design reduces the effect of a failure. Both contribute to reliable service.
14.2 • Performance Sensors

Device and Chassis Health

Hardware and operating systems expose counters much like a vehicle dashboard. A single high reading may be temporary; a sustained or correlated pattern is more significant.

Temperature

Heat rises with blocked airflow, dust, fan failure, or high load. Excessive temperature can cause throttling, shutdowns, reboot loops, and permanent damage.

CPU utilization

Sustained processor use above roughly 85% suggests overload. High user time points to application work; high interrupt time may indicate hardware or driver trouble.

Memory utilization

Committed memory above roughly 80%, available memory below 5%, or heavy paging indicates pressure. Expanding memory pools can reveal leaks.

Counter or sensorWhat it revealsWarning clue from source
% Processor TimeTime executing non-idle workSustained above 85%
% Interrupt TimeTime servicing hardware interruptsUnexpectedly high values
Processor Queue LengthThreads waiting for CPUMore than twice the CPU count
Committed Bytes in UseCommitted virtual memory pressureAbove 80%
Available MemoryUnused physical RAMBelow 5% is critical
Paging activityDisk use caused by insufficient RAMPersistent or excessive activity
Threshold caution: These values are study indicators, not universal laws. Device role, vendor guidance, workload, duration, and baseline determine whether a reading is truly abnormal.
14.3 • Network Metrics

How Well Data Moves

Bandwidth vs throughput

Bandwidth is a link's theoretical capacity in bits per second. Throughput is the actual rate successfully transferred. Sustained use near 70% may suggest saturation depending on the technology and traffic pattern.

Output queue

An output queue forms when frames wait to leave an interface. A persistent queue length above 2 in the source's example indicates backlog and possible congestion.

Latency

The end-to-end delay, often measured as round-trip time with ping. Long routes, overloaded links, inspection devices, and processing delays can increase it.

Jitter

Variation in latency from packet to packet. Voice, video, and streaming need predictable arrival times, so jitter may hurt quality even when average latency seems acceptable.

SENDERRECEIVERconsistent spacingdelayed arrival = latencymissing packet = lossuneven spacing = jitter

Packet loss should be near zero on a healthy internal network; real-time traffic may not retransmit what disappears.

14.4 • Baselines

Normal First, Anomaly Second

A baseline records normal performance under representative conditions. Without one, a value such as 65% link utilization lacks context: it may be routine for that link or a serious deviation.

1

Measure during normal operation, including relevant busy and quiet periods.

2

Collect over enough time to reveal daily, weekly, seasonal, and workload patterns.

3

Update the baseline after upgrades, migrations, topology changes, or major workload shifts.

4

Alert when current behavior deviates materially from the expected range.

An anomaly is behavior that differs from what is standard, normal, or expected. Automated anomaly alerts reduce manual inspection and shorten response time, but poorly tuned thresholds create alert fatigue.

Diagnostic question: “How was this system performing before the problem?” Historical baseline data supplies the evidence.
14.5 • Monitoring Solutions

Discovery, Performance, Availability, and Configuration

Monitoring functionPrimary questionTypical outcome
Network discoveryWhat devices exist and how are they related?Inventory, topology, rogue-device detection
PerformanceHow are resources and traffic behaving?Trends, bottlenecks, capacity planning
AvailabilityIs the device or service responding?Uptime, downtime, SLA evidence, outage alert
ConfigurationDoes the device match approved settings?Drift detection, compliance, change evidence

Ad hoc discovery is manual and on demand. Scheduled discovery runs repeatedly and is better suited to finding new, missing, or unauthorized devices. Performance platforms store historical counters for forecasting, while availability checks measure service responsiveness rather than simply whether a device has power.

Configuration drift is the gradual or unauthorized divergence of a device from its approved configuration.
14.6 • SNMP

Polling Devices and Receiving Traps

Simple Network Management Protocol (SNMP) allows a central platform to retrieve and organize management data from network devices.

NMScentral managerSNMP AGENTmanaged deviceGET / SET • UDP 161TRAP • UDP 162

Agent and NMS

The agent runs on the managed device. The Network Management Station polls agents, stores results, displays status, and receives alerts.

OID and MIB

An Object Identifier uniquely addresses a managed object or counter. The Management Information Base defines and organizes those OIDs hierarchically.

Get, Set, and Trap

Get retrieves data; Set changes a parameter and is used cautiously; a Trap is an unsolicited agent alert.

Ports

UDP 161 carries Get/Set exchanges. UDP 162 carries traps and informs toward the NMS.

VersionSecurity and capabilityUse
SNMPv1Legacy and insecureAvoid where possible
SNMPv2cImproved counters and GetBulk; community strings remain plaintextCommon legacy monitoring
SNMPv3User-based authentication, integrity, encryption, and access controlPreferred secure version
Secure deployment: Prefer SNMPv3, restrict management sources with ACLs, use read-only access where possible, and do not rely on default community strings.
14.7 • Traffic Analysis

Packets, Mirrors, and Flows

Packet capture

Wireshark and similar analyzers capture raw frames and decode protocols across layers. Packet detail is excellent for deep troubleshooting but creates large datasets.

Port mirroring

A switch copies selected traffic to a monitoring port. SPAN is local, RSPAN extends mirroring remotely at Layer 2, and ERSPAN transports mirrored traffic across a routed network.

Flow data

NetFlow summarizes conversations instead of storing every packet. It identifies top talkers, common destinations, protocols, usage patterns, and anomalies.

EvidenceDetail levelTypical fields or requirementBest suited to
Packet captureFull frame/packet detailPromiscuous NIC and visibility through TAP or mirrorProtocol errors and exact payload/sequence behavior
NetFlowConversation summarySource/destination IP, ports, protocol, interface, ToSTop talkers, trends, capacity, anomaly hunting
SNMP countersDevice/interface statisticsOIDs from agentHealth, utilization, errors, status
Choose by question: “Exactly what happened in this exchange?” favors packet capture. “Who used the link most?” favors flow data.
14.8 • Log Aggregation

Centralizing Events with Syslog

Application, system, security, traffic, and audit logs record what systems observed or did. A central collector preserves evidence even if a source device fails or an attacker alters local history, and it allows events from many systems to be correlated.

Syslog commonly sends messages using UDP 514. Traditional UDP delivery is fire-and-forget, so delivery is not guaranteed. Implementations may support more reliable or protected transports, but remember UDP 514 for the exam.

LevelNameMeaning
0EmergencySystem unusable
1AlertImmediate action required
2CriticalCritical condition
3ErrorComponent or operation failure
4WarningWarning condition
5NoticeNormal but significant event
6InformationalInformational message
7DebugDetailed troubleshooting output
Memory aid: Lower Syslog numbers indicate greater severity: 0 is the most urgent; 7 is debugging detail.
14.9 • SIEM

From Collected Logs to Security Intelligence

A Security Information and Event Management (SIEM) platform extends log aggregation with parsing, normalization, correlation, dashboards, detection rules, alerts, investigation, retention, and compliance reporting.

SEM

Security Event Management emphasizes real-time monitoring, correlation, and response to current events.

SIM

Security Information Management emphasizes storage, search, reporting, and historical analysis.

A SIEM can connect an authentication failure on one server, firewall traffic from the same address, and an endpoint alert into a single incident. It does not guarantee correct conclusions: useful detections still require reliable time synchronization, normalized data, tuned rules, context, and human investigation.

14.10 • Interactive Practice

Choose the Best Monitoring Evidence

Select a scenario to reveal the most useful starting metric or monitoring source.

Select a scenario.
The recommended evidence will appear here.
14.11 • Knowledge Check

Test Your Understanding

1. Which metric best explains uneven packet arrival that causes choppy voice?
2. Which SNMP version is preferred when confidentiality and strong authentication are required?
3. What does an SNMP agent send when it reports an interface-down event without first being polled?
4. Which data source most efficiently identifies the hosts consuming the most WAN bandwidth?
5. What must be established to decide whether current performance is anomalous?
14.12 • Chapter Summary

Essential Takeaways

Proactive monitoring identifies warning signs before they become visible outages.
Temperature, CPU, queues, memory, paging, and pools expose device health.
Bandwidth is capacity; throughput is actual transfer rate.
Latency is delay; jitter is delay variation; packet loss is missing traffic.
A baseline defines normal performance and gives anomalies context.
Discovery, performance, availability, and configuration monitoring answer different questions.
SNMP uses agents, an NMS, OIDs, and MIB definitions.
Get/Set normally use UDP 161; traps/informs use UDP 162.
SNMPv3 is preferred for authentication, integrity, and encryption.
SPAN mirrors packets; NetFlow summarizes conversations and reveals top talkers.
Syslog commonly uses UDP 514 and severity levels 0 through 7.
SIEM correlates security events and supports alerting, investigations, reporting, and retention.