Network Observability

Network Observability is the ability to continuously make visible and evaluate data traffic, communication relationships and the behavior of devices, users and services in a network. The basis is telemetry data such as flow information, packet metadata, logs and protocol analyses, which are brought together into an ongoing overall picture of the network.

Unlike classic network monitoring, which primarily monitors the availability and utilization of defined components, network observability aims to also detect unknown devices, shadow IT and unusual communication patterns. This includes in particular east-west traffic between internal systems, which bypasses classic perimeter controls. In hybrid environments, the field of visibility covers not only the local network but also cloud workloads, remote access and encrypted connections, which are analyzed via metadata.

Network observability is a prerequisite for automated attack detection: only visible data traffic can be examined for anomalies and attack patterns. Methods such as Network Detection and Response (NDR) build directly on this visibility and complement it with detection and response.