View resources and metrics

This document describes how to view resources such as Google Kubernetes Engine services and their associated metrics in Network Services Monitoring.

Before you begin

To view resources and metrics in Network Services Monitoring, complete the following steps.

Enable ambient metrics in GKE

To generate and collect ambient metrics, enable ambient networking and enable metrics generation (ambient-network-metrics=enabled) by following steps in Prepare GKE ambient networking.

Grant required roles and permissions

To get the permissions that you need to view resources and resource details in Network Services Monitoring, ask your administrator to grant you the following IAM roles on your project:

For more information about granting roles, see Manage access to projects, folders, and organizations.

These predefined roles contain the permissions required to view resources and resource details in Network Services Monitoring. To see the exact permissions that are required, expand the Required permissions section:

Required permissions

The following permissions are required to view resources and resource details in Network Services Monitoring:

  • View discovered resources:
    • resourcemanager.projects.get
    • monitoring.timeSeries.list
  • View App Hub details and GKE details:
    • apphub.discoveredServices.get
    • apphub.services.list
    • container.clusters.get
    • container.services.get
    • container.deployments.list

You might also be able to get these permissions with custom roles or other predefined roles.

View resources and metrics

In Network Services Monitoring, you can view resources such as GKE services and analyze them by using their associated network metrics.

View resources

To view all discovered resources, do the following:

  1. In the Google Cloud console, go to the Network Services Monitoring page.

    Go to Network Services Monitoring

  2. View active and inactive resources:

    1. To view active resources, on the Active Discovered Resources tab, select a time interval. This tab lists resources that generated traffic within the selected interval.
    2. To view inactive resources, on the Inactive Discovered Resources tab, select a region and a time interval. This tab lists resources that are discovered by the App Hub API but didn't generate traffic within the selected interval.

View resource details

To view metrics and metadata for a specific resource, do the following:

  1. On the Active Discovered Resources tab, click a resource name.

  2. On the Overview tab of the resource details page, view any of the following sections:

    • Service dependency map: view the visual mapping of inbound and outbound connections for the selected resource. To view traffic, click Traffic, and to view errors, click Errors.
    • Inbound and Outbound: click the Inbound or Outbound tab in the Connections table to inspect the specific sources or destinations for all of the resource's connections.
    • Resource Details: view resource metadata.
    • Additional Diagnostics: use links to Access logs, Application Monitoring, App Hub, Flow Analyzer, and VPC Flow Logs.
  3. To view time-series charts for inbound and outbound traffic, open connection count, and connection health, click the Dashboard tab and select a time interval. You can view additional time-series charts by clicking Show more in the Connections table or clicking the connection lines in the topology graph.

What's next