2022 Gartner® Magic Quadrant™ for APM and Observability Read the Report

DevOps and Security Glossary Terms

Glossary Terms


Active Directory

Active Directory is a specialized software tool that was developed by Microsoft to make it easier for the administrators to manage and deploy system changes.

Agile Methodology

Agile methodology is a set of techniques, values, and principles designed to guide how software development teams work together to deliver new applications and updates.

AIOps (Artificial Intelligence Operations)

AIOps (artificial intelligence for IT operations) is the use of artificial intelligence, machine learning, and pattern recognition to perform and automate tasks.

API Management

API (Application Program Interface) management includes the entire process of creating and publishing an API for your application.

Application Containerization

Application containerization is a rapidly developing technology that is changing the way developers test and run application instances in the cloud.

Application Infrastructure

Application infrastructure includes all of the computational and operational infrastructure and components that are necessary to manage the development, deployment, and management of enterprise applications.

Application Lifecycle Management

Application lifecycle management (ALM) encompasses all aspects of the application lifecycle from gathering initial requirements through to service and maintenance.

Application Migration

Application migration describes the process of moving an application, along with its associated data and host servers, from one environment into another.

Application Performance Monitoring (APM)

APM (Application Performance Monitoring) tools capture data, and aggregate and analyze the data to detect patterns and present actionable insights in a human-readable format.

Application Program Interface (API)

API is a specified communication protocol that allows two applications to interface with each other, or for a client application to access information within another application.

Application Security

Application security is a catch-all term that encompasses any security measures deployed at the application level of an organization's technology stack.

Application Whitelisting

Application whitelisting is a common method used by IT organizations to secure on-premise and cloud-based networks and infrastructure against malicious cyber attacks and unwanted network penetration.

Attack vector

An attack vector is a method or pathway used by a hacker to access or penetrate the target system. Attack vectors can be former employees or even hackers.

Authentication Factor

An authentication factor is a security credential that is used to verify the identity and authorization of a user attempting to gain access or request data from a secured network.

AWS Monitoring

AWS is the most popular cloud platform in the world. Learn about the many different tools that are available to monitor and secure the performance of apps powered by AWS.

Amazon EBS monitoring

Amazon Elastic Block Storage (EBS) is a cloud-based solution that comes from the smirking retail/ tech/ global innovations goliath, and provides persistent block storage volumes for use with Amazon Elastic Compute Cloud (EC2) instances in the Amazon Web Services (AWS) cloud.

AWS RDS Postgres Monitoring

For applications based in the Amazon Cloud, tracking and monitoring performance is a critical, but relatively easy, process to undertake to ensure optimum performance and avoid critical failure.

ASP.Net Core Monitoring

App building as a career enjoys a set-it-and-forget-it reputation amongst would-be developers who have never developed an app before.


Blue-Green Deployment

Blue/green deployment is a methodology for releasing new code into the production environment whose purpose is to reduce software downtime.

Business Analytics

Business analytics makes use of mathematics, statistics, predictive modeling, and other investigative tools to discover and interpret patterns in data.

Business Intelligence

Business intelligence (BI) describes the set of processes that business use to analyze operational data and create actionable insights that drive effective business decision-making.

Business Technology (BT)

Business technology can be simply defined as any application of information technology that is integrated into the operation of a business.



Containers-as-a-service (CaaS) is a category of cloud services where the service provider offers customers the ability to manage and deploy containerized application and clusters.


A Cloud Access Security Broker (CASB) is a software application that mediates user access to cloud-based application. CASB tools can be hosted on-premises or in the cloud.

CDN (Content Delivery Network)

A content delivery network (CDN) is an important tool for optimizing the performance of heavily-trafficked websites and applications that are deployed in cloud environments.

Cloud Application

A cloud application simply refers to any software application that is deployed in a cloud environment rather than being hosted on a local server or machine.

Cloud Automation

Cloud automation is the practice of using specialized software and methodologies to automate the manual tasks associated with managing cloud-based IT infrastructure.

Cloud Computing

Cloud computing is the delivery of computer system resources, including applications, virtual machines, containers, data storage and processing power over the internet.

Cloud Computing Security

Cloud computing security refers to the technical discipline and processes that IT organizations use to secure their cloud-based infrastructure.

Cloud Infrastructure

Cloud infrastructure consists of all hardware and software components that are needed to support the delivery of cloud services to the customer.

Cloud Management

Cloud management is the process of maintaining oversight and administrative control of cloud computing products and services.

Cloud Orchestration

Cloud orchestration is designed to help IT organizations manage interconnections and interactions between disparate systems in increasingly complex cloud environments.

Cloud Security Monitoring

Cloud security monitoring typically involves supervising servers, both virtual and physical, in order to continuously assess and analyze data and infrastructures for threats and vulnerabilities.


A container is a virtualized environment whose contents are an application and all of the files, libraries, binaries and dependencies needed to execute that application.

Continuous Deployment

Continuous deployment (CD) is a strategy where any new code change is deployed directly into the live production environment where it will be visible to customers.

Continuous Integration

Continuous integration is a software engineering practice where all developers merge their working copies into a shared mainline several times a day.

Continuous Intelligence

Continuous intelligence (CI) is real-time analytics and insights delivered from a single, cloud-native platform across multiple use cases to speed decision-making and drive world-class customer experiences.

Continuous Monitoring

Continuous monitoring is a technology and process that IT organizations may implement to enable rapid detection of compliance issues and security risks within the IT infrastructure.

CRUD (create, read, update and delete)

CRUD is an acronym that refers to the four functions that are considered necessary to implement a persistent storage application: create, read, update and delete.

Cyber Security

Cyber security refers to the set of processes, policies and techniques that work together to secure and organization against digital attacks.

Cloud Migration

Cloud migration is the process of moving applications, data, and other components hosted on servers inside an organization to a cloud-based infrastructure.


Data Security

Data security is the set of policies, processes, procedures, and tools that prevent unauthorized access to their networks, servers, and data storage.

Database Management

Database management is the process of defining, manipulating, retrieving and otherwise managing data that exists in a database.


DevOps is a collection of best practices for the software development process to shorten the development life cycle such as continuous integration, delivery and deployment.

Docker Swarm

Docker swarm is a container orchestration tool, meaning that it allows the user to manage multiple containers deployed across multiple host machines.

Denial of Service

Denial of service (DoS) attacks are threats that directly shut down a machine or network, making it impossible for its intended users to access their devices/servers.

Directory Traversal

A directory traversal is an HTTP attack that allows attackers to gain access to restricted files. Directory traversal attacks, also known as path traversal, are some of the most common and dangerous attacks that businesses will see.

Distributed Tracing

With the popularity of microservice architectures, or simply microservices, the demand to understand control flow and monitor distributed systems is becoming more and more of a necessity.

Digital Customer Experience

Digital experiences are where your customers meet your business. The majority of consumers find a positive experience with a brand to be more influential than great advertising. Learn why.

DORA metrics

Learn what DORA metrics are. Explore how to measure them, why they matter, and how they help engineering and DevOps teams maximize performance.



Encapsulation is way to restrict direct access to some components of an object, so users cannot access state values for all of the variables of a particular object.

Endpoint Security

Endpoint security is an organizations’ strategy and approach to maintaining the security of network endpoints and external devices that are directly connected to the IT infrastructure.

Enterprise Application Integration (EAI)

Enterprise Application Integration (EAI) is the implementation of technologies that facilitate communication between enterprise applications.

Enterprise Security

There are several challenges and considerations related to security that apply in a special way to enterprises, which are typically defined as organizations with at least one thousand employees.

Error Tracking

Error tracking is the proactive process of monitoring web applications or microservices to identify problems and fix them before they become serious issues.

Error Budget

An error budget is how much downtime a system can afford without upsetting customers, or, in other words, the margin of error permitted by a service level objective (SLO).


Function as a Service (FaaS)

Functions-as-a-Service (FaaS) is a cloud computing model on serverless technologies and architectures that allow software developers to easily deploy applications in the cloud.

File inclusion

Businesses rely on their web applications. They’re the essential building blocks that provide organizations with the tools they need to execute their tasks, automate tedious processes, manage and store data, and so much more.


Gain privileges

Gaining privileges (also known as privilege escalation) is the act of exploiting a vulnerability or configuration issue in a software/operating system that gives attackers more administrative privileges.


Hadoop Architecture

Hadoop Architecture was designed to allow many data storage devices to work in parallel instead of one large one, making it one of the most popular data processing platforms.

Hybrid Cloud

Hybrid cloud is a specific deployment model for cloud service delivery that combines private, on-premise cloud infrastructure and services with public cloud services.


IIS Log Viewer

An IIS Log Viewer is a software application whose function is to streamline the process of viewing log files from an IIS web server.

IIS Server

The Windows Internet Information Services (IIS) Server is an extensible web server that was created by Microsoft to be used on Windows operating systems.

Incident Response

Incident Response is a documented, formalized set of policies and procedures for managing cyber attacks, security breaches and other types of IT or security incidents.

Indicators of Compromise

Indicators of Compromise (IoC) is evidence which suggests that a data breach may have occurred and that further investigation of the incident response plan is necessary.

Information Security

Information security can be defined as the implementation and management of the set of tools and processes whose goal is to preserve security in the business.

Information Security Management

Information security management (ISM) describes the set of policies and procedural controls that organizations implement to secure their informational assets against threats.

Infrastructure as a Service

Infrastructure-as-a-Service (IaaS) is a delivery model for cloud services where customers purchase access to managed IT infrastructure from a cloud services provider.

Infrastructure as Code

Infrastructure as Code (IaC) refers to the increasingly common practice of provisioning and managing IT infrastructure using coding.

Infrastructure Management (IM)

Infrastructure management includes the management of processes, equipment, data, human resources and external contacts needed to ensure that operations run smoothly and efficiently.

Infrastructure monitoring

Infrastructure monitoring software tools capture log files from throughout the network and aggregate them into a single database where they can be sorted, queried and analyzed by either humans or machine algorithms.

IT Infrastructure

IT infrastructure includes all of the hardware, software, and network resources that are necessary to deliver IT services within the organization.

IT Infrastructure Management

IT infrastructure consists of physical components that support the activities and services that are required by users to support business functions.

IT Operations

IT operations refers to the set of processes and services that are administered by an IT department within a larger organization or business.


IT operations management (ITOM) refers to the administration of all technology components and application requirements within an organization.


Information Technology Service Intelligence (ITSI) is a software tool that uses artificial intelligence and machine learning to helps monitor complex computing environments.


Log Aggregation

Log aggregation is a software function that consolidates log data from throughout the IT infrastructure into a single centralized platform where it can be reviewed and analyzed.

Log Analysis

Log analysis is the process of reviewing, interpreting and understanding computer-generated records called logs.

Log Analyzer

When we say log analyzer, we’re referring to software designed for use in log management and log analysis.

Load Balancer

When an organization allocates more than one server to handle requests for a website or business application, a load balancer is used to distribute requests between them.

Log File

A log file is a computer-generated data file that contains information about usage patterns, activities, and operations within a system, application, server or device.

Log Levels

Log levels are a fundamental tool for tracking and analyzing events that take place throughout your IT infrastructure and cloud-based computing environments.

Log4Shell Vulnerability

Apache Log4j is a very popular and widely used open-source library for Java applications. Log4j allows for logging capabilities, the ability to write various log files, log rolling patterns, and much more. Anyone who has ever worked with a Java application has likely seen Log4j in some capacity.


Machine Data

Machine data is digital information that is automatically created by the activities and operations of networked devices, including computers, phones, and more.

Machine Learning

Machine learning is a programming technique used to automate the construction of analytical models and enable applications to perform specified tasks more efficiently.

Managed Detection and Response

Managed Detection and Response (MDR) is an outsourced security service that helps organizations detect malicious network activity and quickly respond to eliminate the threat.

Managed SIEM

Managed SIEM is an alternative to on-premise deployment, setup and monitoring of a SIEM software solution hosted by a third-party service provider.


Microservices are an important innovation in application development and deployment.


NIST SIEM Requirements and Standards

The National Institute of Standards and Technology (NIST) produces guidance on security information and event management (SIEM).

Node Logging

Logging is an essential aspect of monitoring, debugging, and ensuring optimal network and application functionality. Node, or Node.js, is an open-source, back end environment that allows developers to write with JavaScript code directly onto a computer, as opposed to through its browser.

NPM (network performance monitoring)

Network performance monitoring (NPM) is the process in which IT organizations can assess how users are experiencing their networks.



Observability of a system is defined as if the system's current state can be determined in a finite time period using only the outputs of the system.

Operational Intelligence

Operational Intelligence is the application of data analysis techniques to data that is generated or collected in real-time through an organization's IT infrastructure.

Open Integration Framework (OIF)

OIF fundamentally changes the way integrations are being utilized within a platform, allowing users to easily integrate with third-party technologies, develop external connectors and trigger various automated actions.


PaaS (Platform-as-a-Service)

Platform-as-a-service (PaaS) is a model of cloud service delivery where a cloud service provider delivers some hardware and software tools to customers over the internet.

Pivotal Cloud Foundry (PCF)

Pivotal Cloud Foundry (PCF) is a distribution of the open-source Cloud Foundry platform that includes additional features that expand the capabilities of Cloud Foundry.


Polymorphism is the ability of a programming language to present the same interface for several different underlying data types.

Private Cloud

A private cloud is a deployment model for cloud services where the cloud environment and infrastructure is dedicated to providing services for a single organization.

Predictive Analytics

Predictive analytics is a set of methods and technologies that can be used to analyze current and historical data with the goal of making predictions about future events.


Real-Time Big Data Analytics

Real-time big data analytics is a software feature or tool capable of analyzing large volumes of incoming data at the moment that it is stored or created with the IT infrastructure.

Real-Time Dashboard

Real-time dashboards are being used to display data in real-time, providing the most up-to-date information on a variety of performance metrics.

Role Based Access Control

Role Based Access Control (RBAC) is a critical capability for organizations that deploy applications into the cloud. Gain complete visibility with Sumo Logic today!

Root Cause Analysis

Root cause analysis (RCA) is a method of problem solving used to investigate known problems and identify their antecedent and underlying causes.

Real User Monitoring (RUM)

Real user monitoring (RUM) is an important aspect of application performance management that helps capture and analyze every event that your users make within your application or website.



Software-as-a-service (SaaS) is a model of software distribution where customers pay a fee and the application becomes available over the internet.


In software development, Scrum is a project management framework or methodology that is used to efficiently produce quality work while adapting quickly to change.


SecOps is a methodology that IT managers implement to enhance the connection, collaboration, and communication between IT security and IT operations teams.

Security Intelligence

Security Intelligence describes the practice of collecting, standardizing and analyzing data that is generated by networks, applications, and other IT infrastructure in real-time.

Security Remediation

Security remediation is the process of identifying threats and taking the proper steps to resolving them.

Server Monitoring

The primary objective of server monitoring is always to protect the server from possible failure that would interrupt service availability.


Serverless computing is an execution model for cloud computing services where servers are not accessible to the developers running the code.

Service Level Agreement (SLA)

A service level agreement (SLA) is a legal obligation or set of obligations made between a service provider and a client or customer, which guarantees certain quality assurances for availability, responsibility and other key metrics.

Service Level Indicator (SLI)

A service level indicator (SLI) is a specific metric that helps companies measure some aspect of the level of services to their customers.

Service Level Objective (SLO)

A service level objective (SLO) is an important aspect of a service level agreement (SLA), which represents an agreement between a service provider and or client.

Service Reliability

Service reliability is a method for measuring the probability that a system, product, or service will maintain performance standards for a specific period of time.


SIEM (security information and event management) is an approach in cybersecurity that combines SIM and SEM.

SIEM Environment

Security Information and Event Management (SIEM) Environments are virtual spaces in which log data is collected, interpreted and represented visually.

SIEM Solutions

SIEM solutions are tools that help implement SIEM capabilities into your network.

SIEM Tools

SIEM tools are typically external software solutions that aggregate and analyze log data with the hopes of improving security and security response for IT teams.

SIEM vs Log Management

SIEM and Log Management are two examples of software tools that allow IT organizations to monitor their security posture using log files, detect and respond to IoCs.


SOAR was created with the intention to overcome common obstacles that torment obsolete technologies in a SOC. SOAR is meant to act as a force multiplier, a connective tissue that enhances the productivity of every other tool and technology it collaborates with within the SOC.

Software Deployment

Software deployment includes all of the steps, processes, and activities that are required to make a software system or update available to its intended users.

Software Life Cycle

The software life cycle, or software development life cycle (SDLC), can be summarized as a set of activities and processes that are required to develop a new application.

Software Stack

A software stack refers to the set of components that work together to support the execution of the application, which power back-end and front-end processes, as well as interfaces.

Structured Logging

Structured logging is the practice of implementing a consistent, predetermined message format for application logs that allows them to be treated as data sets rather than text.

Standard operating procedures (SOPs)

Standard operating procedures are processes that include a set of written instructions that help security practitioners follow a straightforward and well-laid-out framework to achieve optimum efficiency in task completion.


Technology Stack

A technology stack includes all of the hardware and software systems that are needed to develop and run a single website, web integration or mobile application.

Testing as a Service (TaaS)

Testing-as-a-Service (TaaS) represents a new avenue for outsourcing many types of testing that are demanded in today's IT environment.

Threat Detection and Response (TDR)

Threat detection and response is the most important aspect of cybersecurity for IT organizations that depend on cloud infrastructure.

Threat Hunting

Threat hunting, aka cyber threat hunting or proactive threat hunting, is the act of seeking out unknown threats to a network.

Threat Intelligence

Threat Intelligence refers to the practice of collecting data, information and knowledge that keep an organization informed about potential cyber security threats.


Virtual Private Cloud (VPC)

Virtual private cloud (VPC) represents a unique delivery model for private cloud services that allow an organization to establish a virtual network under their control.


Web Application Development

Web application development describes the process of designing, building, testing and deploying web-based applications delivered to users or customers via the internet.