Chapter 20Cloud Monitoring, Logging, and Detection
Effective cloud security hinges on the ability to observe, understand, and respond to events as they unfold within complex, distributed environments. Modern cloud ecosystems introduce ephemeral workloads, decentralized identities, and multiregional deployments that challenge traditional monitoring models. Understanding telemetry—through logs, metrics, and traces—is crucial for maintaining situational awareness and exercising control over assets that are constantly evolving. Mature detection capabilities must not only surface anomalous activity but do so with speed, context, and relevance to the business’s risk posture.
Principles of Observability in Cloud Infrastructure
Observability in cloud infrastructure is fundamentally about achieving a coherent understanding of system state through telemetry data—specifically logs, metrics, and traces. This triad of signals provides the raw input needed to assess the internal behavior of cloud systems without direct interaction. In contrast to traditional monitoring, which targets known failure states, observability supports broader detection, interpretation, and resolution of unknown and emergent issues. It is not merely about collecting data, but about engineering systems so that their operations can be inferred from the telemetry they emit.
In modern cloud-native environments, observability must extend beyond the infrastructure layer and penetrate into services, containers, and ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access