Glossary
Using WhaTap monitoring, you keep meeting the same words. Project, agent, metrics. This document gathers what those terms mean in one place.
It is for anyone adopting WhaTap for the first time, or starting to use another product alongside. When an unfamiliar word appears in a product document, look it up here.
Terms are split three ways. WhaTap service terms used regardless of product, general monitoring terms that are not WhaTap specific but worth knowing, and product specific terms used only in one product.
The glossary is updated continuously.
WhaTap service terms
Terms used across WhaTap services regardless of product.
Project
The basic unit of monitoring. You separate monitoring targets and manage member permissions per project.
Projects are created per WhaTap product, such as application, server, or database. A different product means a different project. Within the same product, you can also split projects by purpose, such as Front, Gateway, and API.
Group
A unit that bundles several projects. Projects of different products can be bundled together. For example, if one team uses a server, an application, and a database, the three projects go into one group.
Adding a member to a group grants the same permission across every project in that group.
A project belongs to only one group. Some projects belong to no group at all.
Organization
The top unit that bundles several groups. Projects and groups are enough for most cases.
Organizations help when you manage several customers as separate groups, as a managed service provider (MSP) does. Grant permissions to each group's members and the groups run independently.
Agent
A program that collects data from a monitoring target and sends it to the WhaTap repository server. WhaTap monitoring runs on the data agents send, so install an agent before using any product.
Agents differ by product, and installation location and composition differ by monitoring target.
| Target | Location |
|---|---|
| Application (APM) | Application server. Runs together with the application |
| Server | The server you monitor |
| Database | A separate server, not the DB server. The agent connects to the DB and collects |
| Container (Kubernetes) | The cluster. Composed of a master agent and a node agent |
One agent may collect from several targets. A database agent, for example, installs on one representative node of a cluster and finds the remaining nodes automatically.
Agent names follow the product. Java agent, PHP agent, server agent, and so on. Only databases use individual names, because three agents there serve different roles.
For installation steps per product, see each product's installation document.
Collection Server
The server that receives the monitoring data agents send. With SaaS you use the collection servers WhaTap operates, so you do not build one yourself.
Instance
An individual unit of monitoring. What counts as one differs by product.
| Product | Instance |
|---|---|
| Application (APM) | One application process with an agent attached. Running the same application on several machines makes each one an instance |
| Server | One server |
| Database | One DB node |
| Container (Kubernetes) | One node or container |
Metrics
Numeric indicators collected from monitoring targets. Values that change over time, such as CPU usage, response time, and token usage, are stored as time series.
MXQL
A query language for reading the data WhaTap collects. The name stands for metrics query language.
Use it to pull data in a shape the default screens do not offer, or to check collected values directly. For syntax and functions, see the MXQL guide.
Metrics Chart
The collected data is displayed on the time-series chart. After selecting a time zone, select a desired metric. Then its result appears.
Dashboard
You can use the dashboard to see the status of the entire system in real time. The dashboard displays key metrics such as status of active transactions, distribution of response times for terminated transactions, number of users, CPU, and memory trend.
For more information, see the following document.
Cube
Statistical data WhaTap aggregates in five minute units. Every product has cubes, and cube analysis looks back over past intervals using this data.
Real time metrics show the current state. Cubes are for reviewing past intervals in five minute units.
For the cube screen of each product, see that product's document. For how cubes are stored, see Cube data storage.
Widget
An individual component of a dashboard. Each widget shows one metric or one point of view as a chart, table, or number. Widgets combine into a dashboard.
Flex Board
This dashboard allows you to customize the method. Data of the WhaTap projects such as applications, servers, databases, and containers, can be freely arranged on the screen.
For more information, see the following.
Alert
A feature that notifies you through the channels you choose when a condition you set occurs. You define which situations to detect in event settings.
Event
A situation detected on a monitoring target. You define which situations count as events through conditions in event settings, and an alert goes out when one occurs.
Notification
A message sent to users in real time through several channels when a problem occurs on a monitoring target.
WhaTap provides notification rules predefined for the characteristics of your system, and you can set conditions yourself when needed.
oname · okind
Two values that identify an agent. They come as a pair but point to different things.
| Option | Description |
|---|---|
oname | Object name of the agent. A unique value for one agent |
okind | Kind of the agent. A value that groups agents serving the same purpose |
If oname is a name tag, okind is a category tag. For an agent serving mobile UI, set okind to mobile_ui and view agents of the same purpose together.
-Dwhatap.oname=web-01
-Dwhatap.okind=mobile_ui
General monitoring terms
Terms that are not WhaTap specific but worth knowing for monitoring.
Log
Logs are stored in files that record events and messages that occur during application execution.
It is required to look at the log files to understand application activities and root causes of issues.
Monitoring
Monitoring means monitoring or observing something. In the field of IT services, services are provided with limited costs and resources. Therefore, it is very important to prepare and overcome unexpected situations and failures through monitoring.
Observability
The property of being able to tell what happens inside a system from the data it emits.
Monitoring checks whether predefined indicators stay within range. Observability focuses on tracing the cause when something unexpected goes wrong.
APM (Application Performance Management)
Application performance management. Application performance is measured by the response time of a web service, so APM traces and analyzes transactions.
- Application, the application being monitored
- Performance, measured by response time
- Management or Monitoring
In WhaTap, the application monitoring product corresponds to APM.
For more information, see the following document.
OpenMetrics
A time series metric standard based on the Prometheus metric format. WhaTap collects metrics exposed in this format and lets you query and analyze them.
OpenAgent
An agent that collects metrics from endpoints exposing the Prometheus or OpenMetrics format. It is a static binary built in Go, so no separate runtime is required.
Topology
A diagram of call relationships between components. It shows where delays or errors happen along the flow.
Transaction
In Application Monitoring, a transaction means the process from a single request to the returning of result by the application processes.
TPS (Transactions Per Second)
It means the number of transactions processed per second. It is the basic criterion among service performance metrics. WhaTap displays the entire project TPS in real time.
Throughput
In terms of performance, the throughput means how many requests can be completed. This means how many transactions the system can process.
Throughput is measured in seconds or minutes. Throughput is different from the request volume. Throughput is the amount of finalized requests. If the number of requests per second (RPS) is 100 but the throughput per second (TPS) is 10, 90 requests are still unprocessed.
Average response time
It is the time needed for the application server to return the request result. The WhaTap's service calculates the average response time for transactions every 5 seconds. The average response time is meaningful as a tuning metric.
Thread
It is a unit of execution within a process. Every process has one or more threads to perform tasks.
A process with multiple threads is called "multi-thread process." Each thread has its own stacks and resisters.
Product specific terms
Terms used only in a specific product.
Application monitoring (APM)
Active Transaction
It means the transaction in progress.
For more information, see the following document.
Multi-transaction
This function allows you to identify where a problem has occurred and needs improvement, if it is required to trace the call relationship of multiple applications such as MSA.
Transaction Trace
It indicates a series of processes while executing a single transaction.
Transaction Map
It is the distribution of response times for individual terminated transactions. Same as the hitmap, you can find and analyze problems based on the distribution patterns.
The hitmap displays transactions grouped by the 5-minute timeframe, whereas the transaction map shows transactions individually.
Apdex (Application Performance Index)
Apdex stands for Application Performance Index. Apdex is based on the response time and is quantified as a percentage for total requests satisfied and accepted. Apdex can be used as a metric for user satisfaction and have a value between 0 and 1.
For more information, see the following document.
Hitmap
It is the response time's distribution chart. You can see the distribution of response times over a specific period.
Slow transactions can be easily found based on the location. You can also quickly find errors through the color. The X-axis indicates the end time of the transaction, and the Y-axis indicates the response time of the transaction. If you drag a specific area on the hitmap, it goes to the screen that displays a list of transactions.
For more information, see the following.
Top Stack
Top stack collects stack information in transactions and provides the usage analysis of active methods by the statistics.
At the top of the stack, use the usage statistics to check which method has the most impact on the service. If you know how often the method is called, you can analyze the reason why there is a load on the CPU or memory.
For more information, see the following.
Unique Stack
It is the statistical information collected when the same set of methods has been executed. Using the Unique Stack, you can get insight into which particular type of stack has been used frequently.
If methods have been repeatedly exposed in Unique Stack, they are frequently called or require long time to complete.
For more information, see the following.
Active Stack
Active Stack collects data in active transactions. Stack information is collected every 10 seconds. Collected data can be checked in statistical data.
Statistical information can be identified through the rates for both long-term methods and short-term but frequently executed methods. You can check which part has been delayed at the method level while the transactions are active.
For more information, see the following.
Heap Memory
JVM (Java Virtual Machine) allocates the data storage in memory to run programs.
Memory space is broadly classified into three areas. The areas are Static, Stack, and Heap. Key data such as objects (instances) and arrays is stored in the heap memory area.
For more information, see the following document.
Concurrent users (Realtime User)
It displays the number of real-time browser users. Every 10 seconds, users who have generated transactions within the last 5 minutes are counted and displayed.
Users are counted based on their browser's IP. In the agent settings, the IP or cookies can be used to distinguish users.
Application Topology
It represents the relationship of all applications included in the project scope.
Active Status
It displays the numbers of active transactions for each status.
- METHOD: Method running
- SQL: SQL running
- HTTPC: External API called
- DBC: A transaction is attempting to get a new connection from the connection pool
- SOCKET: TCP socket is being connected to outside
For more information, see the following.
MSA Analysis (Microservices Architecture)
It displays the call relationship between services as a percentage based on the URL.
Caller and Callee
- Caller: Transaction that called a service.
- Callee: Transaction in which a service has been invoked.
Performance Trend
You can see information that affected the performance in the specified time. You can also see graphs for all and individual application servers. You can see which application servers have significant impacts on the performance.
The following data can be viewed in the performance trend:
- Real-time User
- Transaction/Sec (Sum)
- Response Time
- CPU
- Heap Memory
- Active TX
- Top 10 transactions
- HTTP Call Top 10
- SQL Top 10
Resource Board
You can monitor all servers registered in a single project on the resource board. It provides the CPU resource map to check the summary of all servers in the project and changes in real-time resource usage.
It displays the total resource size, CPU, memory, and top 5 utilization processes. You can immediately recognize and respond to failures through the resource board.
For more information, see the following.
Kubernetes monitoring
Master Agent · Node Agent
The agents for Kubernetes monitoring. Install both together.
| Agent | Description |
|---|---|
whatap-master-agent | Collects cluster level metrics |
whatap-node-agent | Collects node and container level metrics |
WhaTap Operator
An operator that installs and manages WhaTap agents on Kubernetes. Write the configuration you want in the WhatapAgent custom resource (CR) and the operator deploys the agents accordingly.
Log monitoring
Log Monitoring
Through WhaTap's log monitoring, you can see logs in real time. Or you can selectively see only the desired logs by applying a specific time, category, tag, or filter.
For more information, see the following.
Live Tail
A screen that streams incoming logs in real time. Logs you do not store also appear here if you turn on the display toggle in log filter settings.
Log Explorer
A screen for narrowing down collected logs. Combine time, category, tag, and filter to pick out only the logs you want.
Log Parser
A feature that turns irregular logs into a queryable structure. There are two types. The GROK parser uses regular expressions and GROK syntax, and the JSON parser handles JSON logs.
Fast Index
An index built in advance to speed up search in environments that collect large volumes of logs.
Long-term Log Archive
Logs are large and hard to keep for long. Long-term archive reduces them to statistics instead of raw records and keeps them longer.
Personal Data De-identification
A feature that masks personal data in logs or replaces it with safe values. Sensitive data you designate is encrypted before storage.
Server monitoring
Resource Equalizer
It displays a list of the top 5 servers in real time for CPU, memory, disk I/O, and disk IOPS.
CPU Resource Map
This distribution chart displays the CPU usage of all servers. It displays data for 10 minutes and is updated every 10 seconds.
Compound Eye
Each server where the WhaTap agent has been installed is expressed as an eye. It brings the servers together in a place.
It provides 5 different data.
- CPU Usage
- Memory Usage
- Disk Usage
- Network Rx (received amount)
- Network Tx (sent amount)
For more information, see the following document.
DISK I/O
The disk I/O (%) metric displays the disk utilization. If the disk I/O (%) exceeds 80%, the system performance can be affected.
The default alert value is 90%. If the disk I/O (%) is 100%, it means that the disk is working non-stop.
DISK IOPS (Input/Output Operations Per Second)
It is a unit of measure representing inputs and outputs per second. It is measured in KiB.
The underlying drive technology determines the maximum amount of data in which the volume is calculated by a single I/O. HDDs typically range from 55 to 180 IOPS. SSDs have 3,000 to 40,000 IOPS.
CPU Steal Time
CPU Steal Time is a percentage of time when the virtual CPU waits for the actual CPU while the hypervisor is servicing another virtual processor.
Virtual machines (VMs) running in a virtual environment share resources with other instances on a single host.
CPU Steal Time displays how long the CPU in the VM is waiting to receive resources from a physical machine.
Database monitoring
DBX · DMX · XOS
The agents for database monitoring. Other products use the product name as the agent name, but databases have three agents with different roles, so each has its own name.
| Agent | Description |
|---|---|
DBX | Connects to the database and collects metrics. Installed on a separate server, not the DB server |
DMX | For Oracle Pro only. Provided separately |
XOS | Additionally collects DB server resources. Optional |
Redis server
It is an in-memory data repository. WhaTap uses it as a session repository that holds HTTP sessions.
LLM Observability
AI Agent
A program that reasons with an LLM and calls the tools it needs to carry out a task. Handling one user request may take several LLM calls and tool runs.
This differs from the agent WhaTap installs. The WhaTap agent collects data, while an AI Agent is what gets observed.
LLM Observability observes the execution flow, token usage, and response performance of AI Agents.
SDK (Software Development Kit)
A library you call directly from application code to declare instrumentation scopes. Wrap a region with workflow or agent from whatap.llm, and the LLM calls inside it group into a single transaction.
from whatap.llm import workflow
An SDK does a different job from an agent. The agent instruments automatically without code changes, while the SDK sets scope boundaries from within your code. Use the SDK when automatic instrumentation alone does not produce the units you want.
LLM (Large Language Model)
An AI model trained on large volumes of text to understand and generate natural language.
Every call is billed by token, and the same prompt returns a different response each time. These two traits require you to observe cost and quality differently from conventional applications.