Escolar Documentos
Profissional Documentos
Cultura Documentos
• DAY 1
Introduction
Insight and Analytics
• DAY 2
Automation and Control
Security and Compliance
Straddling two worlds
Challenges for modern management
PRIVATE CLOUDS
Cloud
Era
Enterprise
Era
LAN
Era
MaaS for Hybrid and Open Systems
Why OMS?
Simplicity Time to Value Easy to Integrate Optimized for
System Center
Microsoft
Operations
Management Suite
WINDOWS WINDOWS
WINDOWS WINDOWS
WINDOWS
HYPER-V
WINDOWS
VMWare
WINDOWS
Ability to define recovery plans Maximum uptime with resource Unified solution for protecting data
and easy-to-manage recovery health assessment on-premises and in the cloud
points
Help secure your workloads, servers, and users.
Comprehensive updates Detection of breaches and threats Perform forensic, audit and breach
assessment across datacenters and with malware assessment analysis
public clouds
Any cloud
Security Visibility
Microsoft
Key Scenarios
• Insight and Analytics
• Configuration and Automation
Hybrid
• Application Management
• Security
• Backup
Protection Control
Management
• Disaster Recovery
System
Center
Any platform
On-premises
Sign Up for OMS in just 3 Clicks
Go to Microsoft.com/OMS and click the
“Try for Free” button. Sign in with a
Microsoft Account.
Individual
monitoring
Platform and
Application
monitoring tool
Network
monitoring tool Individual
monitoring
Security
analysis tool
Individual
monitoring
On premises Application data
datacenter
Platform data
Network data
Security data
Individual Hosters
monitoring
Simple and unified experience
Solution
Individual
monitoring
Platform and
Platform and
Application
monitoring tool Application IT
monitoring Operational
Network excellence
monitoring tool Individual
monitoring
Security
analysis tool
Individual
Application data Security Network monitoring
Security data
Individual Hosters
monitoring
Simple and unified experience UNIFIED
EXPERIENCE
Expand your enterprise management with a consistent experience
• Single pane of control • Integrate with existing systems • Control from anywhere
• Unified experience • Connect with isolated resources • Consistent user interface
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Windows agents
• Log Analytics
SCOM
• Automation
• Site Recovery
Linux / FluentD • Backup
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Windows agents
Connect to Windows computers in your on-premises infrastructure directly to OMS workspaces by using a
customized version of the Microsoft Monitoring Agent (MMA).
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-windows-agents/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
SCOM
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Linux / FluentD
Collect and act on data generated from Linux computers. Adding data collected from Linux to OMS allows you to
manage Linux systems and container solutions like Docker regardless of where your computers are located—virtually
anywhere.
Upload data
(HTTPS)
syslog
Firewall/proxy
Nagios
OMS Service
Zabbix
Providers
Docker
Pull configuration
(https)
Linux Computer
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Linux / FluentD
5.x 32/64-bit
2013.09 – 2015.09 6.x 32/64-bit
7.x 64-bit
12.x 32/64-bit alpha
14.x 32/64-bit beta
15.x 32/64-bit stable
16.x 32/64-bit
10.x 32/64-bit
5.x 32/64-bit
11.x 32/64-bit
6.x 32/64-bit
12.x 64-bit
7.x 64-bit
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Leverage REST collection API to ingest custom data to Operations Management Suite
API
Log Search API
Ensure json is flattened and not nested • Create, manage and run searches
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Leverage existing
management platform
Do not rip and replace by Operations Management Suite
leveraging your management Gateway to connect with isolated
platform such as System Center, environment
Zabbix or Nagios
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
1. On the Operations
Management Suite
Onboarding Wizard:
associate with your OMS
subscription
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-om-agents/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
2. Modify the
omsagent.confconfiguration file
(/etc/opt/microsoft/omsagent/conf
/omsagent.conf).
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-linux-agents/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Business
Platform and owners?
Application
monitoring
Application
owners?
Security Network
analysis monitoring
Infrastructure
owners?
Gain immediate insight
Solution
Business
owners
Application
owners
Infrastructure
owners
Intelligence
Engine
Gain immediate insight UNIFIED
on trusted sources.
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Quick data
collection
Automatic end point data selection Custom log collection including
and collection Windows and Linux
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-data-sources/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-data-sources-custom-logs/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Experienced
sources of insight
Single source of truth, gathering Correlate and analyze through
data from public cloud, private Knowledge obtained by the trusted
cloud, traditional datacenters source such as product team, support
team, MSIT, Digital Crime Unit
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Solutions
Log Analytics solutions are a collection of logic, visualization and data acquisition rules that provide
metrics pivoted around a particular problem area.
https://azure.microsoft.com/en-us/documentation/articles/log-analytics-add-solutions/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Solutions
Data collection details for OMS features and solutions
Alerts (Operations
Windows 3 minutes
Manager)
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Solutions
Data collection details for OMS features and solutions
SCOM agent data sent
Data type Platform Direct Agent SCOM agent Azure Storage SCOM required? Collection frequency
via management group
Network Application
Windows 10 minutes
Gateways
Network Security
Windows 10 minutes
Groups
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
https://blogs.technet.microsoft.com/msoms/2016/08/24/announcing-public-preview-oms-container-solution-for-linux/
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Two types of installation methods to support different operating system types, such as CoreOS.
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
SCSI/Disk
VM ESXi ESXi
Status and
…
Activities Events Failure
Error
https://docs.microsoft.com/en-us/azure/log-analytics/log-analytics-vmware
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
On Premises
Multiple Sites
Hybrid Networks
Multiple VNETs
3rd Party Cloud
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Detect Faults
NPM Service
Active Probes
OMS Agents
Agents can be placed
across DC/Cloud
Determine E2E Loss
& Latency
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Network
Performance
Monitor (NPM):
OMS
How it Works
1. Add the NPM Solution to your
OMS Workspace
2. Download and install OMS
agents. OMS agent downloads
NPM Intelligence Pack (IP)
3. NPM IP: Detect subnets and
upload to OMS
NPM Service 4. NPM IP: Pull peer config
information from OMS
5. Start active probes, periodically
upload data to OMS
6. NPM OMS logic aggregates and
shows comprehensive perf data
OMS Agents OMS Agents Active Probes OMS Agents
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
The Protocol choice affects the accuracy of the results. It also determines whether you must take any
manual steps after you deploy the NPM solution:
• NPM offers you the choice between ICMP and TCP protocols.
• If ICMP, the NPM agents use ICMP ECHO messages to calculate the network latency and packet loss.
• If TCP, the NPM agents send TCP SYN packet over the network.
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Service
dependencies for any
Windows or Linux system
Application Email SharePoint Active
Web sites Web sites Directory
and historical
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
On-premises IT
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
• NetworkSecurityGroupEvent
• NetworkSecurityGroupRuleCounter
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
On the Azure Network Security Group Analytics dashboard, review the summary information in one of
the blades, and then click one to view detailed information on the log search page
On any of the log search pages, you can view results by time, detailed results, and your log search history.
You can also filter by facets to narrow the results
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
OMS Gateway
The OMS Gateway allows data collected on server machines to be pushed to a proxy
machine for upload. This allows Production Servers to stay off the Internet
• If computers that are behind a DMZ, can be configured with the OMS agent to directly
connect to an OMS workspace.
• All computers will instead communicate with the OMS Gateway.
• The gateway transfers data from the agents to OMS directly, it does not analyze any of
the data in transit.
When an Operations Manager Management group is integrated with OMS, the Management
servers can be configured to connect to the OMS Gateway to receive configuration
information and send collected data.
• Operations Manager Agents send some data such as Alerts, Configuration Assessment,
Instance Space, and Capacity Data to the Management Server.
• IIS Logs, Performance, and Security events are sent directly to the OMS Gateway.
• If Operations Manager Gateway server is deployed in a DMZ, it cannot communicate
with an OMS Gateway.
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
OMS Gateway
• Configure SCOM Management
Server Proxy
• Install Microsoft Monitoring
Agent on Proxy
• Install OMS Gateway on Proxy
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Analyze petabytes of
data from the cloud
Infrastructure free, On the fly metrics PowerBI integration
management as a aggregation
service
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
View designer
Create visual tiles based on searches
Assemble tiles on a dashboard
View Designer editing Overview Tile to show custom service’s front-end custom events and performance data
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
View designer
Create visual tiles based on searches
Assemble tiles on a dashboard
Complete with metrics visualized in line charts, distributions of event levels for my service, and the amount of data getting
for both types of events. Each visualization can drill down into OMS Log search.
Simple and Gain Fast
unified immediate troubleshoot
experience insight and auto
remediate
Fast troubleshoot and auto remediate
Challenges
Platform and
Application
monitoring
Security Network
analysis monitoring
Platform and
Application
monitoring
Filter alerts Professional knowledge
Automated
Problem
process
solved
Fast troubleshoot and auto remediate UNIFIED
Solve issues as quickly as possible in an automated fashion to improve EXPERIENCE
your SLA
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Alert management
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Community based
automation
Leverage PowerShell community for automating via PowerShell based runbooks
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Auto remediate
Leverage automation Connect existing alerts
from the cloud to auto remediate
UNIFIED EXPERIENCE
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
COLLECT AND INDEX DATA SEARCH AND INVESTIGATE CORRELATE AND ANALYZE VISUALIZE AND REPORT MONITOR AND ALERT
Fast
Simple and Gain
troubleshoot
unified immediate
and auto
experience insight
remediate