ARCHITECTURE

Central control. Distributed collection. Asynchronous by design.

Core owns policy, identity, topology, incidents and intelligence. Sensors execute collection close to the monitored estate so every poll does not depend on a healthy WAN path to Core.

NOC / AdminAPIs / Integrations
↓ HTTPS / API
AmrudAi CoreIdentity · Policy · Topology · Incidents · RCA · SLA
↓ mTLS control & ingestion
Network SensorSNMP · Flow · SyslogInfrastructure SensorSSH · WinRM · APIsAgentsEndpoint-local evidence
Users & Enterprise SystemsNOC / AdminREST APIsITSM / CMDBSSO / Identity
↓ HTTPS / authenticated API
AMRUDAI CORECentral control, intelligence and governance
Identity / RBACInventory / PolicyAlerts / IncidentsTopology / RCAReporting / SLANCM / IPAMIntegrationsAI Gateway
↓ mTLS control / telemetry ingestion / durable buffering
NETWORK SENSORSNMP · ICMP · Flow · Syslog · PathINFRASTRUCTURE SENSORSSH · WinRM · APIs · SyntheticsAGENTSEndpoint-local metrics · service/process · diagnostics
↓ monitored-resource protocols
NetworkServersVirtualizationStorageCloud / K8sDatabasesServices
ARCHITECTURAL INVARIANTS

Designed around failure, trust and operational correctness.

No Data ≠ Device Down

Collection-path failure is modeled separately from target state.

One canonical entity graph

SNMP, flow, syslog, NCM and API observations converge on governed identity and relationships.

Evidence before AI

Deterministic/protocol/topology evidence remains authoritative; AI augments it.

Preserve evidence

Correlation can compress workflow noise without destroying underlying event evidence.

Protect live monitoring

Historical storage can be reclaimed before storage pressure is allowed to stop live monitoring.

Security by default

HTTPS/mTLS, least privilege, auditing, secret protection and signed artifacts are baseline directions.

HA MODEL

Exactly two full Core nodes for Active / Standby.

  • One Core for standalone deployments
  • Exactly two full Core nodes for HA
  • Less-than-60-second Core service restoration is an architecture target, not a current production guarantee
  • Sensors continue collecting during Core failover while local capacity permits
  • Ambiguous states must not produce two authoritative actives
CORE AACTIVE
⇄fenced authority
CORE BSTANDBY
Sensors continue collection / buffering through control-plane transition