Knowledge Base

What is network visibility?

Network visibility is the ability to see what is actually happening on a network, measured from the traffic itself rather than inferred from device counters or application logs. It is the difference between knowing that a link is busy and knowing which conversations are on it, how long each one took, and which of them failed.

Why counters and logs are not enough

Interface counters report volume, not experience. A switch showing 40 percent utilisation says nothing about whether one particular order acknowledgement arrived late, because an average over a second hides a microburst that lasted a millisecond.

Application logs have the opposite problem: they record what the application believed happened. A retransmission, a reset or a queued burst is frequently invisible to the process that suffered it, which sees only a slow response and no explanation. Both sources are useful; neither is independent of the thing being measured.

What visibility actually requires

Three things have to be true at once. Traffic must be observed without loss, because a dropped packet in the measurement path is indistinguishable from a dropped packet on the network. Protocols must be decoded, so that a TCP stream becomes an identifiable transaction rather than bytes. And the result has to be measured continuously, because faults that matter are usually transient and will not survive until someone starts looking.

Visibility, monitoring and observability

These terms overlap and are often used loosely. Monitoring watches known signals against thresholds. Observability is the broader property of being able to ask new questions after the fact. Visibility is the input both depend on: without an accurate record of the traffic, monitoring alerts on proxies and observability has nothing to query.

Visibility in trading infrastructure

In electronic trading the tolerances are small enough that inference stops working. A venue and a trading system can disagree about when an order was sent, and only an independent, timestamped record of the wire settles it. That is the role of network visibility and analytics, built on a lossless record from packet capture. The same evidence that explains a latency outlier also answers the compliance question about what was sent and when.