Adaptive Network Event Forensics Data Collection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems face challenges in collecting timely and relevant context information about network events, as existing methods lack the ability to dynamically customize context collection and often miss the opportunity to gather necessary data at the time of the event, leading to inadequate root cause analysis.
Innovation Solution
A data processing system that includes a data repository for event message definitions, event annotation logic to specify context information, and an event forensics definitions generator to dynamically distribute and collect context information at managed network elements, enabling near-real-time collection and storage of context data in metalogs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If context information is collected manually after events occur, then analysis can be performed, but the information is lost by the time queries are issued
Solution Approach 1:
The system pre-configures event forensics definitions that specify what context information should be collected for different event types. When events occur, the predefined definitions enable automatic collection of relevant context information immediately, preserving data that would otherwise be lost while eliminating manual collection delays
Solution Approach 2:
The system continuously monitors network events and automatically triggers context information collection based on detected events. This feedback mechanism ensures that relevant data is captured at the moment of occurrence and fed back to the network management computer for analysis, preventing information loss and reducing response time
2Loss of information
If heavy system administration tasks are performed to customize context collection, then relevant information can be gathered, but the process becomes complex and time-consuming
Solution Approach 1:
The system automatically performs context information collection based on pre-configured event forensics definitions. The automated agent on the network management computer monitors events and triggers data collection without requiring manual script writing or heavy administration tasks, reducing complexity while ensuring relevant information is gathered
Solution Approach 2:
The system uses configurable parameters in event forensics definitions to dynamically adjust what context information is collected based on event types and operational environments. This parameter-based approach allows customization of data collection without requiring complex manual configuration, enabling relevant information gathering through simple parameter settings
3Loss of information
If context information is collected for all events, then comprehensive data is available, but the system becomes inefficient and resource-intensive
Solution Approach 1:
The system applies different collection strategies to different event types based on their specific requirements. Event forensics definitions specify exactly what context information is relevant for each event type, ensuring comprehensive data collection for critical events while avoiding unnecessary collection for less important events, thus maintaining completeness while improving efficiency
Solution Approach 2:
The system collects context information selectively based on event severity and relevance criteria defined in event forensics definitions. Rather than collecting all possible data for every event, the system performs partial collection focused on the most relevant information for each event type, improving efficiency while maintaining sufficient completeness for effective analysis
4Adaptability or versatility
If scripts are manually written and distributed across the network, then context collection can be customized, but the process becomes cumbersome and difficult to maintain
Solution Approach 1:
Instead of manually writing and distributing scripts, the system uses event forensics definitions that can be copied and distributed as configuration files. These definitions specify context collection parameters for different event types and can be easily replicated across the network, providing customization capability while eliminating the complexity of manual script management and maintenance
Data Source
AI summary
In an embodiment, a data processing system comprises a repository configured to store a plurality of event message definitions for error messages, syslog messages, or other notification messages that may be emitted by one or more managed network elements; event annotation logic coupled to the data repository and configured to receive and store one or more annotations to each of the event message definitions, wherein each of the annotations specifies event context information to be collected in the managed network elements when an associated event message occurs; event forensics definitions generator logic coupled to the event annotation logic and configured to generate an event forensics definitions file capable of interpretation by one or more managed network elements and comprising event type identifiers and context information identifiers for context information to be collected, and configured to cause distributing the event forensics definitions file to the one or more managed network elements.


