---
title: "What is network observability?"
description: "Network observability is the ability to answer new questions about network behaviour after the fact, without having decided in advance which questions to ask."
source: https://www.pico.net/kb/what-is-network-observability/
markdown_url: https://www.pico.net/kb/what-is-network-observability.md
---

# What is network observability?
Network observability is the ability to answer new questions about network behaviour after the fact, without having decided in advance which questions to ask. Monitoring tells you that a threshold was crossed. Observability lets you establish why, using evidence that was recorded before anyone knew it would be needed.

## Observability versus monitoring

The practical difference is when the question is formed. Monitoring requires you to know the question in advance: you choose a metric, set a threshold and receive an alert. That works well for conditions you have seen before, and not at all for the ones you have not.

Observability inverts this. Enough detail is retained that a question formed on Tuesday can be answered about Monday. The cost is storage and the discipline of recording continuously rather than on demand.

## Why the usual three pillars miss the network

Observability is commonly described as metrics, logs and traces. All three are emitted by hosts and applications. The network between them emits nothing by itself: it is the one part of the path that cannot be instrumented by adding a library to a service.

This matters because a large share of difficult faults live precisely there, in queuing, retransmission, path changes and congestion. A distributed trace will show that a call took 40 milliseconds. It will not show that 38 of them were a TCP retransmission timeout.

## Packets as the missing source

Capturing traffic supplies the missing pillar, and it has a property the others lack: it is independent of the systems being measured. An application cannot reliably time its own delay, and a device under stress is the least trustworthy reporter of its own condition.

In trading infrastructure that independence is the point. Where a venue and a trading system disagree, packet evidence is the arbiter. See [Corvil network analytics](https://www.pico.net/products/corvil-analytics/network-analytics/) for how continuous capture becomes queryable measurement rather than an archive nobody can search.