SDWSCS Part 13: Monitoring with vManage & vAnalytics
Twelve parts of deployment need a final part about living with it. The syllabus closes on monitoring, and rightly: the security and cloud features are exactly the ones that fail quietly — a UTD container that stopped inspecting, a SIG tunnel pair down to one leg, an OnRamp path decision masking a rotting circuit. This part is the operational view: what vManage shows, what vAnalytics adds, and what deserves an alert rather than a dashboard.
vManage: the real-time layer
The security dashboard (Monitor → Security) aggregates what Parts 2–5 deployed: firewall enforcement counts, IPS signature hits by severity, URL filtering blocks by category, AMP file verdicts and — the one to watch — retrospective verdict changes, where a file that passed as unknown was later condemned by the sandbox. Each panel pivots to per-device, per-rule detail; this is where you confirm the embedded stack is doing something, not just running.
Per-feature operational state lives where you’d expect and rewards being scripted against rather than eyeballed:
Edge# show utd engine standard status ! container green?
Edge# show sdwan zonebfwdp sessions ! firewall state
Edge# show sdwan secure-internet-gateway tunnels ! SIG legs up?
Edge# show endpoint-tracker ! and actually healthy?
Edge# show sdwan cloudexpress applications ! OnRamp choices
Edge# show app-hosting list ! TE agent running?
Cloud OnRamp dashboards (SaaS and Multicloud) show per-application path scores and per-gateway health respectively — the SaaS one answering “which exit is each app using and why”, the Multicloud one carrying attachment and BFD state for the cloud gateways from Part 11.
Alarms and events wire the above into notification: severity-graded, correlated (a tunnel-down alarm suppresses its BFD child events), and exportable — webhook to whatever your NOC watches, or the REST API for the automation-inclined. The security- and cloud-specific alarms worth promoting to pages rather than emails: UTD engine not green, security virtual image/IOS XE mismatch after upgrade, SIG tracker red, cloud gateway BFD loss, and OnRamp gateway-exit changes at unusual frequency (path flapping being a symptom, not a feature).
vAnalytics: the trends layer
vManage answers “what is happening”; vAnalytics (Cisco SD-WAN Analytics — cloud-hosted, fed by telemetry from your overlay) answers “what has been happening and what will”: application experience scoring over weeks, per-site and per-circuit benchmarking against anonymised aggregate baselines (“your loss on this carrier is worse than typical”), bandwidth trending and forecasting for capacity planning, and best-path/policy insight showing what fraction of traffic actually met its SLA class. Its value in this course’s context is specifically the before/after evidence: enable OnRamp for SaaS at a pilot site, and vAnalytics’ application-experience trend is the artefact you show whoever pays for the feature licence. Same for SIG migrations — latency and loss to key SaaS before and after the tunnel cutover, on one chart.
The operational split that keeps both tools honest: vManage for state and incidents; vAnalytics for trends and decisions; ThousandEyes (Part 9) for the paths you don’t own. Three layers, three questions, no overlap worth arguing about.
The day-2 runbook
The recurring operations this estate actually needs, at honest frequencies:
| Cadence | Task |
|---|---|
| Continuous (alerted) | UTD health, SIG tracker state, cloud gateway BFD, TE alert rules |
| Weekly | Security dashboard review: IPS top talkers, URLF anomalies, AMP retrospectives; OnRamp path-change log |
| Monthly | Signature/allow-list tuning from the IPS review; DLP monitor-mode incident triage; vAnalytics circuit benchmark pass |
| Quarterly | Security virtual image vs IOS XE version audit across the estate; SIG tunnel capacity vs per-tunnel ceilings; decrypt-policy exception list re-justification; cloud gateway sizing vs vAnalytics forecast |
| Per change | The Part 4 rule: any decryption-scope change gets a pilot ring and a week of logs first |
Series wrap
That’s the syllabus walked: the security model and unified policy (Part 2), the embedded stack (3–4), dedicated options (5), the SASE turn (6), Umbrella from DNS to CASB (7–8), visibility (9), and the cloud arc from SaaS steering to multicloud, interconnect and colo (10–12). Paired with ENSDWI you now have the full platform: fabric first, then everything the fabric carries and touches. The official course adds instructor-led labs and 24 CE credits; if recertification is due, it’s a genuinely useful way to earn it — and if you’ve labbed along with these thirteen parts, you’ll find the class comfortable.
What’s next on the site: back to shorter, opinionated pieces for a while — starting with a look at what the last two months of daily posting did to my drafts folder.