Alert Clustering and Visualization for IT Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual examination and prioritization of large volumes of semi-structured and unstructured textual alerts and incidents in IT infrastructure are inefficient, lacking effective clustering and visualization methods to identify patterns and trends.

Innovation Solution

A data clustering and visualization system that performs tokenization, normalization, distance metric computation, and hierarchical clustering to group similar alerts and incidents, enabling intuitive visualization and business intelligence metric analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual examination and prioritization of alerts and incidents is performed, then accuracy in understanding alert nature can be maintained, but productivity and operational efficiency deteriorate due to the large volume of textual data

Engineering Contradiction:
Improvealert processing throughputVSAvoidtime for manual examination
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical examination of alerts with an automated computational system that performs tokenization, normalization, distance metric computation, and hierarchical clustering. This substitution of human cognitive processing with algorithmic processing dramatically increases productivity while reducing time loss, as the system can process large volumes of semi-structured and unstructured alert data automatically without fatigue or delay.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates visual representations (copies) of clustered alert data that preserve the essential patterns and relationships. The visualization system generates graphical displays of clusters, allowing analysts to quickly comprehend alert patterns without manually examining each individual alert, thus maintaining understanding accuracy while dramatically improving processing throughput.

Inventive Principle:
Principle #26Copying

2Loss of information

If clustering algorithms are applied to group similar alerts, then patterns and trends become identifiable, but device complexity increases due to multiple processing steps

Engineering Contradiction:
Improveinformation about alert patternsVSAvoidcomplexity of clustering system
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the complex task of alert analysis into distinct modular processing steps: tokenization, normalization, distance metric computation, hierarchical clustering, and visualization. Each module handles a specific aspect of the problem, making the overall complex system more manageable and maintainable while effectively preserving alert pattern information through systematic processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate data structures and representations, such as distance matrices and cluster groupings, that serve as mediators between the raw alert data and the final visual output. These intermediaries transform unstructured text into organized numerical representations that can be processed by clustering algorithms, preserving information while managing complexity through structured transformation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If hierarchical clustering with distance metrics is performed, then alert similarity accuracy improves, but computational time and resource usage increase

Engineering Contradiction:
Improvesimilarity measurement accuracyVSAvoidcomputation time
Core Design Contradiction:
Measurement precisionVSDuration of action of moving object

Solution Approach 1:

The patent performs preliminary processing steps (tokenization and normalization) before the computationally intensive clustering operation. By pre-processing the text data into standardized token representations, the system prepares the data in a format that enables more efficient distance metric computation and clustering, reducing the overall computational time while maintaining measurement precision.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11720599B1Clustering and visualizing alerts and incidents
Publication Date: 2023.08.08 VMWARE INC
  • US11720599B1 patent drawing
  • US11720599B1 patent drawing
  • US11720599B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for clustering and visualizing textual data. A data clustering and visualization system clusters large volumes of semi-structured and unstructured textual data into categories. Each category can include a group of similar alerts and incidents. The categories are then graphically presented.