Observability

See Everything Your
Firewall Is Doing.

Neurowall exports comprehensive Prometheus metrics — throughput, drops, rule hits, DDoS activity, threat intel health, HA status, and more — so you're never guessing what the firewall did during an incident, or whether it's healthy right now.

37
Prometheus metrics across firewall, DDoS, TI, DB, LLM, and audit subsystems
/health
Kubernetes-ready health endpoints for liveness & readiness probes
Grafana
Pre-built dashboards, provisioned automatically via docker-compose
Why It Matters

A firewall you can't observe
is a firewall you can't trust.

A firewall making silent decisions is a liability — you need to know it's actually dropping what it should, passing what it should, and staying healthy under load. Neurowall treats observability as a first-class feature, not an afterthought bolted on for compliance.

Confirm Enforcement Is Working

Packet-level counters for allowed/blocked/dropped traffic confirm rules are actually being enforced — not just present in the database.

Catch Degradation Early

Threat intel feed health, HA leader status, and database connection metrics surface subsystem issues before they become outages.

Understand Attacks As They Happen

DDoS-specific counters show drop rates and threshold state in real time during an active attack, not just after the fact.

Feed Existing Ops Tooling

Standard Prometheus exposition format means metrics plug straight into whatever Grafana, Alertmanager, or paging setup you already run.

What You Can Monitor

Every layer, one dashboard.

CategoryWhat you see
Firewall / data planeActive rule count, packets processed/blocked, bytes, rule evaluation latency, flow cache size & evictions
DDoS protectionDrop counters by attack type, config reload events, enabled-module state, threshold values, controller poll timestamps
Threat intelligenceIndicator counts, match rates, feed update latency & errors, data-integrity alerts
HTTP APIRequest rate, latency, and payload size — useful for spotting automation gone wrong
DatabaseQuery count, duration, active/idle connections — early warning for capacity issues
High availabilityLeader election state, cluster node health, failover events
AuditAudit log write count, write errors, and latency — confirms the audit trail itself is healthy
How To Use It

Point your existing
stack at it.

Scrape /metrics

Neurowall exposes a standard Prometheus scrape endpoint — add it to your existing prometheus.yml, no custom exporter needed.

Import the Dashboards

Pre-built Grafana dashboards ship with the deployment and are provisioned automatically via docker-compose — no manual panel-building required.

Wire Up Alerts

Use Alertmanager rules against DDoS drop rates, TI feed errors, or HA failover events to page on-call before users notice a problem.

What Other Firewalls Give You Instead

"It has logs" is not the
same as observability.

Most firewalls technically produce some output. Whether that output is actually usable for real-time operations or incident response is a different question.

Common approachWhere it falls short
Proprietary log format, vendor-only viewerLogs can't be correlated with the rest of your infrastructure's Prometheus/Grafana stack without a custom parser or a separate pane of glass nobody checks
Aggregate throughput graphs onlyTotal packets/sec tells you traffic exists, not whether DDoS mitigation is engaged, whether a specific rule is misfiring, or whether the TI feed silently stopped updating three days ago
Health check limited to "process is running"A process can be alive while its rule sync is broken, its threat feed is stale, or its HA state is split-brain — "up" and "healthy" are not the same claim
Metrics as a paid add-on tierObservability gets treated as an upsell rather than a baseline requirement — teams either pay extra or fly blind on exactly the system meant to protect them
What Happens Without Real Observability

You find out from an outage,
not a dashboard.

The threat intel feed silently stops updating
Without a feed-health metric and alert, the firewall keeps running against a stale blocklist for days or weeks — new attack infrastructure goes unblocked, and nobody knows until it's exploited.
A DDoS attack is underway right now
Without real-time drop-rate visibility, an on-call engineer is debugging blind — no way to confirm mitigation is actually engaging, or which threshold is or isn't tripping.
An HA cluster silently loses its leader
Without leader-election metrics wired to an alert, a failover event that should page someone in seconds instead surfaces only when traffic actually drops — reactive instead of proactive.
Database connections are quietly exhausted
Without connection-pool metrics, capacity problems present as mysterious rule-sync slowness or API timeouts — hard to diagnose after the fact, easy to catch as a trend beforehand.
Why CloudArmour

Observability is built in,
not sold separately.

Standard Prometheus Format, No Add-On Tier

All 37 metrics ship with every deployment and expose through a standard /metrics endpoint — no separate license, no proprietary viewer required.

Health Means Subsystem Health

Beyond a basic liveness check, metrics distinguish "process is running" from "TI feed is current," "HA leader is stable," and "DB connections are healthy" — the distinctions that actually matter during an incident.

Dashboards Ship Pre-Built

Grafana dashboards are provisioned automatically via docker-compose, so day-one visibility doesn't depend on someone finding time to build panels from scratch.

Fits the Stack You Already Run

No requirement to adopt a new vendor's monitoring platform — Neurowall's metrics plug into the Prometheus/Grafana/Alertmanager stack most infrastructure teams already operate.

Get started

Stop guessing what your firewall did.