Alert Grouping via Avalanche and Conditional Probability Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing systems face challenges in efficiently managing and triaging numerous alerts related to hardware or software issues, as existing monitoring tools struggle to identify patterns and group alerts effectively, leading to inefficient resource management and potential service disruptions.

Innovation Solution

An apparatus comprising a processor with modules for avalanche pattern detection, conditional probability pattern detection, and alert grouping, which processes historical alert data to identify event patterns and group current alerts, enabling efficient triage and visualization of alert groups for system operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If automated monitoring tools are used to detect alert conditions, then the detection capability of system issues is improved, but the quantity of alerts generated increases significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidquantity of alerts
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent combines multiple alerts into alert groups based on detected patterns. Alerts that share common characteristics (such as affecting the same configuration items or following similar temporal patterns) are merged into single grouped alerts, reducing the total quantity of alerts presented to operators while preserving the underlying information.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary pattern detection and alert grouping before presenting alerts to operators. By pre-processing alerts to identify and group them according to detected patterns, the system reduces the workload operators would otherwise face in manually analyzing individual alerts.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If operators manually triage each alert individually, then the accuracy of alert dispositioning is improved, but the time required to process alerts increases

Engineering Contradiction:
Improveaccuracy of dispositioningVSAvoidtime to process alerts
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary pattern detection and alert grouping before presenting alerts to operators. By pre-processing alerts to identify and group them according to detected patterns, the system reduces the workload operators would otherwise face in manually analyzing individual alerts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system learns from operator actions and feedback to refine its pattern detection algorithms. When operators interact with grouped alerts (such as dismissing a group or drilling down into specific alerts), this feedback is used to improve future pattern recognition and grouping accuracy.

Inventive Principle:
Principle #23Feedback

3Productivity

If pattern detection algorithms are applied to group alerts, then the efficiency of alert management is improved, but the complexity of the system increases

Engineering Contradiction:
Improveefficiency of alert managementVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the alert management system into distinct functional modules: pattern detection, alert grouping, and presentation. This modular approach allows each component to be developed and maintained independently, managing system complexity while enabling sophisticated alert management capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10469309B1Management of computing system alerts
Publication Date: 2019.11.05 SERVICENOW INC
  • US10469309B1 patent drawing
  • US10469309B1 patent drawing
  • US10469309B1 patent drawing

AI summary

An apparatus for grouping alerts generated by automated monitoring of at least an operating condition of a machine, represented as a configuration item in a configuration management database, in a computer network. A first event pattern is identified based on configuration items associated with an alert avalanche identified from received historical alert data stored in memory. A second event pattern is identified based on co-occurrences of configuration item pairs in the historical alert data and on at least one conditional probability parameter. At least one alert group is determined by comparing at least one configuration item associated with a current alert to the plurality of configuration items of the first event pattern and of the second event pattern stored in memory. A graphical display region for displaying the alert group is generated.