ADAM PULSE Knowledge Base
Buying Guide · Procurement · Network Monitoring

How to choose a network monitoring solution: 25 questions to ask before you buy

The market is full of network monitoring platforms.

Almost every product promises:

The problem is that businesses frequently start by comparing features before defining the operational problem they actually need to solve.

A better purchasing process begins with a different question:

What Do We Need to Know and What Do We Need Someone to Do When Something Goes Wrong?

A monitoring platform can identify a problem.

An observability platform may provide deeper context.

A managed Network Operations Center can add people and processes around the technology.

Understanding which combination your organization needs is more important than simply choosing the dashboard with the longest feature list.

This buyer's guide provides 25 questions to ask before selecting network monitoring software, an observability platform, managed monitoring, or a Network Operations Center service.

1. What Problem Are We Actually Trying to Solve?

Start here.

Do not begin with:

Which network monitoring platform should we buy?

Define the pain.

Examples:

Different problems require different solutions.

2. What Do We Need to Monitor?

Create an inventory.

Potential requirements include:

Do not purchase a platform until you know what matters to the business.

3. How Many Locations Do We Need to Monitor?

Five locations and 500 locations present very different operational challenges.

Determine:

Multi location businesses should pay particular attention to how the monitoring platform organizes and compares sites.

4. How Many Internet Circuits Do We Manage?

Count:

Every critical circuit should be independently visible.

5. Can the Solution Monitor Both Primary and Backup Internet?

This is essential.

If the primary circuit works, the backup connection may remain unnoticed for months.

Then the primary fails.

Only then does IT discover:

The backup has also been down.

A monitoring solution should help verify redundancy continuously.

6. Does It Monitor More Than Up or Down?

Availability is important.

But network health also includes:

A circuit can remain online while providing terrible service.

7. Can It Establish a Network Performance Baseline?

Ask:

What does normal look like for this location?

A static alert saying:

Latency above 100 ms

may miss a major deterioration at a location that normally operates at 15 ms.

Historical baselines provide context.

8. Can It Identify Performance Trends?

You want to see more than today's value.

Can it identify:

Trend visibility allows teams to investigate deterioration before a complete outage.

9. How Much Historical Data Is Retained?

Ask exactly how long monitoring data remains available.

You may need history for:

Different platforms retain different types of data for different periods.

Cisco ThousandEyes, for example, currently defines different retention periods depending on product and license tier, reinforcing why buyers should validate retention before purchase.

10. Can We See What Happened During an Incident After It Has Recovered?

This is one of the most important questions.

Suppose users experienced packet loss at:

2:14 PM

The network recovered at:

2:27 PM

IT starts troubleshooting at:

2:45 PM

Can the monitoring system tell you what was happening at 2:14 PM?

If not, intermittent troubleshooting will remain difficult.

11. Can It Help Distinguish the LAN, Firewall, ISP and Application?

Monitoring should help narrow the failure domain.

A strong diagnostic model asks:

Is the gateway healthy?

Is the firewall healthy?

Is the carrier reachable?

Can external destinations be reached?

Is DNS working?

Is the application available?

That is more useful than one generic:

Site Down

alert.

12. Does It Provide Internet Path Visibility?

Modern applications travel across infrastructure the business does not own.

Cisco ThousandEyes emphasizes exactly this problem by providing visibility across LAN, WAN, internet, cloud, SaaS, ISP and endpoint paths.

Ask whether your environment needs:

Not every business requires that depth.

But some absolutely do.

13. Does It Monitor the User Experience?

Infrastructure can look healthy while users still have problems.

Consider whether you need visibility into:

ThousandEyes Endpoint Experience, for example, is designed to follow the user experience from WiFi through ISP, VPN and the destination application.

14. How Are Alerts Generated?

Ask:

An alert should not simply say:

Something changed.

It should provide enough context to determine whether action is required.

15. How Does the Solution Prevent Alert Fatigue?

Ask how the platform handles:

If one branch outage generates 40 unrelated alerts, the monitoring system may create more work instead of less.

16. Does It Correlate Related Events?

Suppose:

WAN fails.

Firewall becomes unreachable.

VPN drops.

Cloud application fails.

These may represent one incident.

A strong monitoring architecture should help operators see the relationship.

17. Who Validates the Alert?

This question separates software from managed operations.

When an alert fires at 2:00 AM:

Who looks at it?

If the answer is:

Our internal team

then account for that operational responsibility.

If you need someone else to validate it, you are no longer evaluating only software.

You are evaluating a managed monitoring service.

18. Who Performs the Initial Troubleshooting?

Ask specifically.

Does the provider:

Or does the provider simply send:

Site Down

to your inbox?

Those are dramatically different services.

19. Who Contacts the ISP?

Carrier escalation can consume significant IT time.

Ask whether the service includes:

Do not assume "managed monitoring" automatically includes carrier management.

20. Is Monitoring 24/7 or Is Human Response 24/7?

This distinction is critical.

Almost every cloud monitoring platform operates 24/7.

That does not mean someone is reviewing incidents 24/7.

Ask:

Is the technology operating 24/7?

and separately:

Are people available 24/7?

21. What Reporting Is Included?

Ask about:

Raw monitoring data and useful management reporting are not the same thing.

22. How Does the Solution Scale?

Cisco ThousandEyes, for example, currently provides multiple consumption, endpoint and site based licensing approaches, illustrating how monitoring costs and architectures can change significantly as environments grow.

Ask:

Understand the economics before deployment.

23. What Is the Total Cost of Ownership?

Do not calculate only:

Software license.

Include:

The cheapest software may not create the lowest operating cost.

24. What Happens After the Alert?

This may be the most important question in the entire buyer's guide.

Ask the vendor to describe the actual workflow.

For example:

  1. Network condition detected
  2. Alert generated
  3. Condition validated
  4. Gateway tested
  5. Firewall tested
  6. ISP path tested
  7. Failure domain identified
  8. Carrier contacted
  9. Ticket tracked
  10. Restoration confirmed
  11. Incident documented

Which steps does the product perform?

Which steps does the service provider perform?

Which steps remain your responsibility?

25. Are We Buying a Tool or an Outcome?

Ultimately, decide what the organization wants.

Do you want:

Network monitoring software?

Network observability?

Managed network monitoring?

Managed NOC operations?

A co managed model?

These can all be valid answers.

The correct choice depends on how much operational responsibility the business wants to keep internally.

Network Monitoring Software vs Managed Monitoring

A simple way to compare the models:

| Requirement | Software | Managed Monitoring | | —- | —- | —- | | Collect metrics | Yes | Yes | | Show dashboards | Yes | Yes | | Generate alerts | Yes | Yes | | Maintain platform | Customer | Provider can manage | | Validate alerts | Customer | Provider | | Initial troubleshooting | Customer | Provider within scope | | Carrier escalation | Customer | Can be included | | After hours response | Customer | Can be included | | Incident tracking | Customer | Can be included |

When Is Monitoring Software the Right Choice?

Software may be ideal when:

In this case, a platform such as PRTG, SolarWinds or a more sophisticated observability solution may be appropriate.

When Does a Platform Like Cisco ThousandEyes Make Sense?

ThousandEyes is particularly relevant when visibility needs extend beyond equipment the organization owns.

Cisco currently positions ThousandEyes around visibility across:

Its platform specifically aims to expose service delivery across owned and unowned infrastructure.

That can be extremely valuable in complex enterprise environments.

When Does Managed Network Monitoring Make Sense?

Managed monitoring becomes compelling when:

The ADAM Pulse Buyer Framework

ADAM Pulse recommends evaluating network monitoring across five dimensions:

Visibility

What can you see?

History

Can you understand what happened before?

Isolation

Can you identify the probable failure domain?

Operations

Who acts when something goes wrong?

Economics

What does the entire operating model cost?

That is a better buying framework than comparing feature checkboxes alone.

Before You Buy, Answer These Five Questions

If you remember nothing else from this guide, answer:

What must we monitor?

What history do we need?

Who investigates the alert?

Who owns carrier escalation?

What will all of this cost to operate?

Those answers will eliminate many inappropriate solutions quickly.

Download the ADAM Pulse Network Monitoring Buyer's Checklist

Turn these 25 questions into a standard evaluation worksheet.

Use the same checklist when reviewing:

That creates a more objective purchasing process.

Need Help Evaluating Your Network Monitoring Strategy?

USA Telecom and ADAM Pulse can help organizations evaluate whether they need:

The goal is not to sell every organization the same architecture.

The goal is to build the right operating model for the network you actually have.

Choose the monitoring strategy before choosing the monitoring product.

Talk with USA Telecom about evaluating your network monitoring requirements.

Frequently asked questions

What Do We Need to Know and What Do We Need Someone to Do When Something Goes Wrong?

A monitoring platform can identify a problem. An observability platform may provide deeper context. A managed Network Operations Center can add people and processes around the technology.

2. What Do We Need to Monitor?

Create an inventory. Potential requirements include: Do not purchase a platform until you know what matters to the business.

3. How Many Locations Do We Need to Monitor?

Five locations and 500 locations present very different operational challenges. Determine: Multi location businesses should pay particular attention to how the monitoring platform organizes and compares sites.

5. Can the Solution Monitor Both Primary and Backup Internet?

This is essential. If the primary circuit works, the backup connection may remain unnoticed for months. Then the primary fails.

6. Does It Monitor More Than Up or Down?

Availability is important. But network health also includes: A circuit can remain online while providing terrible service.

7. Can It Establish a Network Performance Baseline?

Ask: A static alert saying: may miss a major deterioration at a location that normally operates at 15 ms.

8. Can It Identify Performance Trends?

You want to see more than today's value. Can it identify: Trend visibility allows teams to investigate deterioration before a complete outage.

9. How Much Historical Data Is Retained?

Ask exactly how long monitoring data remains available. You may need history for: Different platforms retain different types of data for different periods.

10. Can We See What Happened During an Incident After It Has Recovered?

This is one of the most important questions. Suppose users experienced packet loss at: The network recovered at:

11. Can It Help Distinguish the LAN, Firewall, ISP and Application?

Monitoring should help narrow the failure domain. A strong diagnostic model asks: That is more useful than one generic:

Sources

Editorial note

Monitoring requirements, tooling and staffing models vary by organization. Evaluate these recommendations against your own environment, the number of sites you operate, your internal capacity, and the business impact of an outage before deciding what to build or buy.

ADAM Pulse is a managed NOC, not a dashboard licence. We will tell you honestly whether you need software, a staffed operation, or both.

← More from the ADAM Pulse Knowledge Base