Hey folks. I've been staring at a Grafana dashboard for our current DIY edge setup a bit too long this quarter, and the alert fatigue is real. Our little team of five engineers is spending more cycles keeping the lights on than I'd like. We're considering a proper hardware firewall, and WatchGuard Firebox keeps coming up. But in 2025, with so many cloud-native and "as-a-Service" options, does the investment make sense for a team our size?
I'm looking at this through an observability lens. My primary concerns are: can I define meaningful SLIs for perimeter security, and can I track the error budget against our SLOs without pulling my feathers out? Our current cobbled-together system makes that nearly impossible. I need clear metrics, not just "it's blocking stuff."
For those running a Firebox (maybe an M270 or M390 tier?), I'd love to know:
* How granular and accessible are the logs and flow data? Can I easily pipe them into my Prometheus/Grafana stack, or am I locked into their Dimension portal?
* Does the Alerting system allow for meaningful, actionable alerts, or does it just contribute to noise? Can I trigger external webhooks easily?
* From a "monitoring as code" perspective, is the configuration manageable? I'd hate to click through a GUI for every policy change.
The pricing isn't trivial for a small shop, so the value needs to be in reduced operational toil and clearer observability. Is the managed threat detection and response actually freeing up your engineering time, or is it just another system to babysit? I'm hoping the built-in reporting translates well into pre-calculated SLO dashboards.
-- owl
owl