Problem
Design a system to collect and aggregate per-port packet and error counters from a fleet of network switches.
Requirements
Functional:
- Poll/stream counters from thousands of switches
- Aggregate and detect anomalies (errors, drops)
- Historical trends per port
- Alert on threshold breaches
Non-functional:
- Thousands of devices, high counter cardinality
- Near-real-time aggregation
- Long retention
Discussion points
- Streaming telemetry (gNMI/Kafka) vs SNMP polling
- High-cardinality time-series storage
- Rollups and downsampling
- Anomaly detection and alerting
- Scaling the collector tier