Files
diagramme/monitoring-datenfluss.md

4.8 KiB

CK Monitoring — Messpunkte, Methoden & Darstellung

Übersicht: was wird wo wie gemessen und wo dargestellt. Stand 2026-06-23 (NAS-CRK-02 Ruhrstr. mit blackbox + smokeping).

1. Datenfluss — vom Messpunkt zur Anzeige

Kurze Kantenbeschriftungen bewusst gehalten (Details siehe Matrix unten), damit es in der Gitea-Web-Ansicht sauber rendert.

%%{init: {'flowchart': {'curve': 'step'}}}%%
flowchart LR
    subgraph A["Standort A · Pferdebachstr (40er)"]
        XGS40["XGS-40"]
        rpp1["rpp1 · Probe + Relay"]
    end
    subgraph B["Standort B · Ruhrstr (30er)"]
        XGS30["XGS-30"]
        NAS["NAS-CRK-02 · Probe<br/>blackbox + smokeping"]
    end
    subgraph H["Heimnetz · Referenz"]
        Pi5["raspip5 · Probe"]
    end

    Prom[("Prometheus")]
    Loki[("Loki")]
    Graf["Grafana"]
    AM["Alertmanager"]
    Push["ntfy + E-Mail"]

    rpp1 -->|Metriken| Prom
    NAS -->|Metriken| Prom
    Pi5 -->|Metriken| Prom
    XGS40 -. SNMP .-> rpp1
    XGS30 -. SNMP .-> rpp1
    XGS40 -->|Syslog| rpp1
    rpp1 -->|Syslog| Loki
    XGS30 -->|Syslog| Loki
    Prom --> Graf
    Loki --> Graf
    Prom --> AM
    AM --> Push

Bezug der beiden Standorte zueinander (wichtig, weil nicht symmetrisch):

  • Lokal je Standort: blackbox-Probes (Internet/MS/DNS/APs), beim 30er zusätzlich smokeping.
  • Cross-Site: Die Firewall-SNMP beider XGS (auch die des 30er) holt rpp1 am Standort A — der NAS macht kein SNMP.
  • Syslog: 40er läuft über rpp1 zum VPS, 30er geht direkt zum VPS.

2. Messmatrix — was / wo / wie / Darstellung

Messung Wo (Messpunkt) Wie (Methode / Job) Ziele Dargestellt in
Internet erreichbar Std A (rpp1) · Std B (NAS) · Heim (Pi5) blackbox icmp_ping 8.8.8.8, 1.1.1.1 KLV (beide Zeilen), Latenz-Dashboard
Microsoft Cloud erreichbar Std A · Std B · Heim blackbox http_2xx login.microsoftonline, Business Central, CRM, Outlook KLV, „Microsoft Cloud Services"
DNS-Auflösung Std A · Std B · Heim blackbox dns_resolve / dns_ms_* XGS-40/30 :53, Google, FritzBox KLV, DNS-Panels
Internet-Tempo Std A · Std B · Heim blackbox HTTP-Dauer www.google.com KLV (Gauge)
WAN-Auslastung XGS-40 · XGS-30 SNMP von rpp1 (:9116) ifHCInOctets Port1 beide Firewalls KLV, „Sophos XGS Firewall"
WLAN-APs online 40er: von rpp1 · 30er: lokal vom NAS blackbox icmp_ping 5 APs (40er) · 8 APs (30er) KLV, „Sophos WLAN Access Points"
WAN-Stabilität / VoIP-Microcuts Std B (NAS) smokeping_prober (Dauer-Ping 1/s, Hop-Leiter) 10.128.30.1 → 192.168.178.1 → 8.8.8.8/1.1.1.1/9.9.9.9 „Ruhrstr WAN-Stabilität" + ntfy ruhrstr_wan
Host-Metriken rpp1 · Pi5 · VPS node-exporter :9100 CPU/RAM/Disk/Temp „Server-Übersicht", System
Firewall-Logs XGS-40→rpp1→VPS · XGS-30→VPS rsyslog → Promtail → Loki Syslog (Information) „Sophos XGS Syslog"
Externe Erreichbarkeit VPS Gatus (14 Endpunkte) öffentliche Dienste Homepage / Gatus

3. Welche Sonde speist welche KLV-Zeile

Die beiden KLV-Standort-Zeilen werden lokal je Standort gemessen — außer der WAN-Auslastung (SNMP), die für beide Standorte von rpp1 kommt:

%%{init: {'flowchart': {'curve': 'step'}}}%%
flowchart LR
    rpp1["rpp1 · Std A"]
    NAS["NAS-CRK-02 · Std B"]

    rpp1 --> bb40["blackbox 40er"]
    rpp1 --> snmp40["SNMP XGS-40"]
    rpp1 --> snmp30["SNMP XGS-30"]
    NAS --> bb30["blackbox 30er"]
    NAS --> smoke["smokeping 30er"]

    bb40 --> R40["KLV-Zeile 40er"]
    snmp40 --> R40
    snmp30 --> R30["KLV-Zeile 30er"]
    bb30 --> R30
    smoke --> R30

snmp30 hängt am rpp1 (Standort A), speist aber die 30er-Zeile — das ist die einzige Cross-Site-Abhängigkeit.

Hinweise

  • Prober-Adressen: rpp1 10.128.40.10:9115 (+SNMP :9116) · NAS-CRK-02 10.128.30.3:9115 (blackbox) + :9374 (smokeping) · Pi5 10.100.0.2:9115. Scrape vom VPS-Prometheus (Std A/B über VPN).
  • „VPS extern" ist keine Blackbox-Perspektive: Der blackbox-Container auf dem VPS läuft (127.0.0.1:9115), ist aber nicht verdrahtet. Externe Sicht = Gatus. (Offen: verdrahten oder Container entfernen.)
  • Rendering / Layout: Gitea rendert Mermaid clientseitig ohne Layout-Einstellung — saubere Darstellung kommt nur über render-freundliches Mermaid: kurze Kantenlabels, wenige mehrzeilige Knoten, flowchart LR (Quellen stapeln links untereinander) und curve: step (rechtwinklige statt geschwungene Linien). Grenze: exakt gleich große Boxen / pixelgenaue Positionen kann Mermaids Auto-Layout nicht — dafür wäre draw.io nötig (.drawio im selben Repo).
  • Quellen: prometheus.yml, alerts.yml; dokumentation/15_systeme/68_nas_crk02_ruhrstr.md; dokumentation/10_monitoring/06_klv_dashboard_beschreibung.md.