Customer background
The Sangfor IT-SRE team faces a vast IT panorama supporting thousands of employees and global operations. Core ERP, CRM, and supply chain systems bear intense business flow pressures; each type of log, metric, and link data may be linked to financial collections, customer delivery, and internal collaboration.
Sangfor's IT architecture is a typical high-availability hybrid architecture: underlying it includes mature hyperconverged and managed cloud systems, K8s containerized microservices clusters, and retaining some multi-site IIS systems that have been running for years.
As business continues to expand, traditional monitoring systems are increasingly unable to support cross-service and cross-level problem positioning. When business units report that the system response is slow, SRE needs to switch between multiple independent tools such as Metrics, Logs, and Traces, stretching the troubleshooting process.
Multiple generations of architecture coexist, with scattered perspectives
Hyperconverged, managed cloud, K8s microservices, and IIS historical systems run in parallel, with underlying infrastructure, middleware, and application data scattered across different monitoring entrances.

Cross-service problem positioning chains are long
A slow response may involve business applications, databases, middleware, and underlying resources, and SRE requires manual stitching of metrics, logs, and link-to-link documentation.

High alarm noise makes core risks easily overwhelmed
Previously, alerting strategies were one-size-fits-all and redundant alerts, so SRE teams had to sift through large amounts of low-value information to identify events that truly needed immediate action.

Solutions
Unifying IaaS, PaaS, and SaaS data to build a full-chain perspective
Guance helps Sangfor integrate data from IaaS infrastructure, PaaS middleware, and upper-layer SaaS application data in multiple dimensions, establishing standardized data labeling and tiering systems.
SRE teams can view metrics, logs, links, and the overall business overview on a unified platform, tracking from a system perspective down to specific business flow stages.
Layered governance alert strategies reduce ineffective noise
Sangfor divides applications into four levels: S/A/B/C, and decouples monitoring items from application hierarchies, allowing core resources to focus on S/A-level critical business.
Edge logs in S-level applications no longer trigger high-quality alerts, while critical errors in A-level applications are immediately upgraded, making Critical events more prominent.
The business dashboard translates IT metrics into business language
Focusing on the quarter-end financial and sales sprint scenario, Sangfor has built a money, goods, and goods monitoring dashboard that visualizes the business chain in real time including quotations, contracts, orders, shipments, and payment collections.
When contract circulation is blocked or financial statement generation is delayed, the system can provide timely warnings, shifting IT operations from resource assurance to business support.
Customer outcomes
Alarm noise reduced by 70%:
Through business hierarchy and policy decoupling, redundant alerts are significantly reduced, allowing SRE teams to focus on critical events that truly need immediate attention.

Mean Time for Fault Localization Reduced by 50%:
Metrics, logs, and link data are analyzed and correlated on the same platform, so cross-service issues no longer rely on manual contextual splicing, significantly improving positioning efficiency.

Mean Downtime Recovery Reduced by 65%:
Unified on-site observation helps teams more quickly identify impact areas, pinpoint root causes, and advance recovery, reducing the duration of business system anomalies.

Cross-service performance troubleshooting reduced to minutes:
Through full-link tracing and business dashboards, SRE can drill down from business flow health down to specific applications, services, and underlying resources, accelerating the handling speed of complex issues.
