SNMP, syslog, NetFlow, and streaming telemetry as data sources; monitoring platforms, baselines, capacity planning, alerting, and documentation as the discipline that turns that data into an operations practice.
A network that only gets attention when something breaks is a network being run by luck. This module covers the toolset that tells you what an enterprise network is actually doing right now — SNMP polling and traps, syslog's centralized event history, NetFlow/sFlow/IPFIX traffic visibility, and the streaming telemetry that is gradually replacing the old polling model — and the monitoring platforms that pull all of it into one place.
The second half is about turning that raw data into judgment: building real performance baselines, using them for capacity planning that gets ahead of a saturating link instead of reacting to one, and designing alerting that people actually trust instead of learning to ignore.