A drive failed at 03:14 and the operations team found out at the next polling cycle, close to an hour later. The customer's standard claims 'monitoring sees everything'. Why the delay, and how should a platform like this be watched?
Select an answer to reveal the explanation.
Short Explanation
Polling is a schedule; failure isn't. Your hour-long gap is just the distance between two polls - set up SNMP traps and the appliance tells you about the dead drive the second it dies, while polling keeps doing the trend work it's actually good at. Don't poll your way toward a push design; that's just expensive lateness.
Full Explanation
Polling is question-time: the manager asks on schedule and learns only what changed since the last ask, so an event at 03:14 waits for the next poll - exactly the gap the customer is living with. Push monitoring inverts it: the appliance emits SNMP traps the moment an event fires, so failures arrive in seconds, not an interval later. The design answer: both coexist with different jobs - traps for failures that demand a reaction, hardware faults first, and polling for trends and capacity, which have no single moment to announce. Blaming SNMPv3 authentication overhead misdiagnoses the arithmetic: an hour is a polling interval, not an authentication delay, and the real culprits are unconfigured trap targets or missing subscriptions - neither is fixed by stripping authentication from the channel. Shortening the poll interval narrows the worst-case gap but pays device and network overhead for every increment, and no practical interval matches event-time delivery - a faster poll remains a poll. 'Always been that way' concedes a solved problem: trap generation and manager subscription are standard capabilities here, and configuring them was deployment work that got skipped. Exam caveat: traps need targets, credentials and alert mapping configured on both ends - a trap sent nowhere is just as late in practice. Operational check: simulate a drive fault and confirm the trap arrives in seconds while the next poll is minutes away, with the alert mapped to a named runbook step.