Skip to main content
 

2.174.1 Enterprise Monitoring Platform

Manual Transmittal

August 13, 2025

Purpose

(1) This transmits new IRM 2.174.1, chapter is Monitoring and Event Management, section is Enterprise Monitoring Platform

Material Changes

(1) IRM chapter 2.174 Monitoring and Event Management to be created

(2) IRM section 2.174.1 Enterprise Monitoring Platform to be created

(3) This chapter and section will be in line with the other Information Technology Infrastructure Library 4.0 type chapters within IRM Part 2 Information Technology and provide clarity with respect to the other Information Technology Infrastructure Library functional areas such as Change Management, Knowledge Management, Asset Management and Configuration Management.

Effect on Other Documents

none

Audience

This policy applies to all Information Technology organizations, all IRS personnel and business unit organizations having contractual arrangements with the IRS, including employees, contractors, vendors, stakeholders, volunteers, and cloud outsourcing providers which use or operate that store, process, or transmit IRS information or connect to an IRS network or system.

Effective Date

(08-13-2025)

Kaschit Pandya,
Chief Information Officer

Program Scope and Objectives

  1. Purpose. This Internal Revenue Manual document describes the formal Information Technology (IT) policy for implementing the requirements for IRS Enterprise Monitoring and Event Management with respect to establishing the purpose, scope, authority and mandates for institutionalizing this process. The objectives of Monitoring and Event Management are as follows:

    1. ensure that monitoring and event management processes are aligned with other Information Technology Service Management processes , such as Incident Management, Problem Management, Change and Configuration management so that monitored events are managed in a coordinated and effective manner across the IRS Information Technology organization.
    2. The establishment of an IRS Enterprise Monitoring Platform is essential for an effective monitoring and event management process so that IT services are delivered efficiently, effectively and in a manner that meets the needs of the Internal Revenue Service and its customers
    3. Effectively improve service availability, reduction of mean time to repair, enhancement of customer satisfaction, increased operational efficiency, provide for better decision making, support proactive problem management, and facilitate compliance with other IRM mandates for monitoring..

     

  2. Audience. The Monitoring and Event Management policy is applicable to all Information Technology organizations, all IRS personnel and organizations having contractual arrangements with the IRS, including employees, contractors, vendors, stakeholders, volunteers, and cloud outsourcing providers which use or operate that store, process, or transmit IRS information or connect to an IRS network or system.
  3. Policy Owner. Director, Information Technology, Enterprise Operations, IT Operations Command Center.
  4. Program Owner. The senior manager in the office of Monitoring Solutions Branch within Information Technology, Enterprise Operations, IT Operations Command Center.
  5. Primary Stakeholders. All Information Technology (IT) organizations having responsibility, managing, or controlling their IT system and/or system components, Business Operating Divisions (BODs) obtaining IT services or support, service providers, and employees including contractors must abide by the criteria and processes set forth in this IRM
  6. Contact Information. to be determined - use MSB organizational DL/mailbox.
  7. Program Goals Establishing a standardized monitoring and event management platform via modernized advanced technology, analytics, and the promotion of operational efficiency by increasing the availability of IRS information and information systems for the delivery of a better taxpayer experience

Background

  1. IT Operational Monitoring is listed as an integral part of service management capabilities within the goals of IRS around enterprise service management to ensure healthy services via the tracking of event patterns and performance issues. One of the guiding principles is promoting visibility with data analytics. Information Technology Operations Command Center ( ITOCC) Monitoring Solutions Branch is working to improve and expand application monitoring, testing visibility, application reliability, service availability, streamline process integration/automation to improve restoration times, and increase the use of the change management pipeline to reduce defects and outages.
  2. Event Management and monitoring goals::

    • Integrating IT monitoring toolsets to eliminate silos.
    • Identifying inadequate monitoring P1/P2 analysis to mitigate.
    • Ensure application dependencies are discovered, mapped, or monitored end-to-end.
    • Develop a single-pane view integrated monitoring model of the entire IT operating environment.
    • Include monitoring as a required reusable enterprise level (RELR) program-level requirement for all projects.

     

Authority

  1. The ITOCC Division has sole responsibility for the established Enterprise Monitoring Platform. All business operating divisions (BOD), applications and programs are responsible to request monitoring on their applications and services.

Responsibilities

  1. This IRM establishes mandates for IRS IT enterprise control functions (IT ACIO and business unit support organizations). Through internal controls during the initiation, design, development, deployment, and operations of the agency’s IT systems these mandates shall be satisfied. This Directive requires adherence to the following mandates:

    • Compliance with Federal, Treasury, and IRS Policies.
    • Promulgation of enterprise-wide control processes.
    • Satisfaction of requirements as part of the IRS enterprise monitoring platform.

     

Program Management and Review

  1. The Information Technology (IT), Enterprise Operations, IT Operations Command Center (ITOCC) is responsible for the development, implementation, and maintenance of this IRM. All proposed changes to this document must be submitted in writing, with supporting rationale to Enterprise Operations IT Operations Command Center.

Program Controls

  1. Each IRM in the Information Technology 2.x series is assigned an author who reviews their IRM annually to ensure accuracy. Any changes or revisions are done in collaboration with applicable stakeholders, for potential impact to the IRS operational environment.

Terms/Definitions/Acronyms

  1. Definition of terms

    Terms

    TermDefinitionExample
    (These examples are for illustration purposes only, not actual instruction.)
    EventEvent is an occurrence that has meaningful significance or impact for the management of the IT Infrastructure or the delivery of IT services, business processes, or application functions and the evaluation of the impact a deviation or an occurrence might cause to the services. Events are typically notifications created by an IT service, Configuration Item (CI) or monitoring tool. 
       
       

     

    Acronyms

    AcronymDefinition
    ITOCCInformation Technology Operations Command Center
    MSBMonitoring Solutions Branch
    ITILInformation Technology Infrastructure Library

     

     

Related Resources

  1. Application Performance Management:
  2. IRWorks Request for Advanced Monitoring:

Enterprise Monitoring Platform Policy and Guidance

  1. The IRS in order to meet the recommendations set forth as part of IRA transformation, modernization, and technology improvements must develop and establish an enterprise level monitoring platform taking into consideration the complex monitoring requirements about the standard system monitoring requirements as mandated by [ reference IRM 10.8.1 - Continuous Monitoring]
  2. The Enterprise Monitoring Platform shall encompass monitoring consumption standards based on IRS approved software, middle ware, and technologies.
  3. In order to satisfy key requirements for end to end visibility and monitoring three key layers are integral to the success of the enterprise monitoring platform:

    • A data collection foundation layer for the collection of metrics that can consist of some or all of the following combinations of agents, log files, API’s, or other IRS approved standardized communication protocols in order to access monitoring data from hardware and or software based systems.
    • A software based layer that serves as the integration hub for any and all deployed monitoring tools that allows for the processing and analysis of raw data with the inclusion of an event handling system for any generated thresholds violations. This system shall be the established authority source for events, alarms and triggers for ticketing or communications with the IRS Enterprise Services Management toolset.
    • A presentation layer that can display the analyzed data and events in a variety of formats such as graphs, charts and tables via a graphical user interface.

     

  4. Deployed monitoring tools such as network monitors, application performance monitors, server and system resources monitors, database monitors, and log file monitoring tools shall be integrated with the Enterprise Monitoring Platform so that key performance indicators, actionable events and any alarm conditions warranting a ticketing response from the IRS Service Management tool can be handled from the established enterprise monitoring platform for universal action by the IT Operations Command Center.
  5. Establishment of a checklist to be leveraged by IRS procurement and contract specialists to ensure IT acquisitions, programs and projects adhere to the policy in this IRM for the integration with the IRS Enterprise Monitoring Platform.
  6. Enterprise Monitoring Platform tools checklist shall include but not be limited to the following

    • monitor system performance in real time or near real time (e.g. response time, latency, error rates, and throughput)
    • monitor system level resources utilization.
    • ensure monitoring tools for integration can effectively measure median, 95th percentile, and 98th percentile performance as per industry standards
    • creation of automated alerts based on the integrations with deployed monitoring tools
    • ensure that any and all managed service providers have the capability and will integrate with the IRS Enterprise Monitoring Platform via application and Cloud monitoring standards.

     

  7. Application and Cloud Monitoring Consumption Standards table outlining approved integration standards

    Application and Cloud Monitoring Standards

    Monitoring AreasOn PremAWSAzureSaaS
    API SupportXXXX
    Application AvailabilityXXXX
    Application Performance MonitoringXXX 
    AWS Cloud WatchXXXX
    Azure MonitorXXXX
    Browser Real User Monitor/Digital ExperienceXXXX
    Business Service AvailabilityXXXX
    Cloud MonitoringXXXX
    CMDBX  X
    Configuration FileXXXX
    Customer ToolsX XX
    Data ForwardingX   
    Database MonitoringXXXX
    Event From DB (Operations Connector Only)XXXX
    Event From Perl ScriptX XX
    Event From REST Web ServiceX XX
    Event From Structured Log FileX XX
    Event From XML FileX XX
    File MonitorX XX
    Flexible ManagementX   
    Generic Output from Agent StoreX XX
    Generic Output from DB (Operations Connector)X XX
    Generic Output from Perl ScriptX XX
    Generic Output from Rest Web ServiceX XX
    Generic Output from Structured Log FileX XX
    Generic Output from Windows Event LogX XX
    Generic Output from XML FileX XX
    Google Cloud Operations SuiteXXXX
    Infrastructure MonitoringXXXX
    Java Heap monitorXXXX
    JMSQ cluster monitorXXXX
    JMSQ queue depth monitorXXXX
    JMX MonitorXXXX
    Kubernetes MonitoringXXXX
    Log File EntryX XX
    Log File MonitoringX XX
    Log4JX XX
    Measurement ThresholdXXXX
    MetricsXXXX
    Metric from DB (Operations Connector Only)XXXX
    Metric from Perl ScriptXXXX
    Metric from REST Web ServiceXXXX
    Metric from Structured Log FileXXXX
    Metric from XML FileXXXX
    Metric Streaming ConfigurationXXXX
    Mid-Tier MonitoringXXXX
    MQ MonitoringXXXX
    MQ Queue queue depthXXXX
    MQ Status monitorXXXX
    Multi log monitorX X 
    Network MonitoringXXX 
    Node InfoXXXX
    Open Message InterfaceX XX
    OpenTelemetryXXXX
    Operations Connection High AvailabilityX   
    Ping for server availabilityX   
    Processing Rate monitoring via Logfile monitoringX XX
    Queue DepthsXXXX
    Scheduled TaskX  X
    Service Level Agreement (SLA)X XX
    Service AvailabilityXXXX
    Service Auto-DiscoveryXX X
    Service/Process MonitoringXXXX
    SNMP v3 InterceptorX XX
    Synthetic TransactionsXX  
    SyslogX XX
    Technology Integration logfile monitor for file transfersX X 
    Topology from REST WebserviceX  X
    Topology from XML FileX  X
    Transaction ObservabilityXX  
    WebSphere Application monitoringXXX 
    Windows Event LogX XX
    Windows Management InterfaceXXXX
    XMLXXXX