Alert Triage Workflow Automation for Faster Network Fault Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network management systems are inadequate in handling fault management, failing to utilize a broad suite of collection modalities, normalize alerts, and enrich them with device or network information, leading to incomplete information presentation and prolonged fault resolution, which relies heavily on manual operations by technicians.

Innovation Solution

Implementing intelligent alert automation (IAA) that autonomously processes alert and event feeds through triage, workflow determination, and automation, utilizing a scalable system architecture with triage and abattoir systems to prioritize and process alerts and events across multiple servers, enabling efficient creation and management of flow instances and trouble tickets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If conventional network management systems use manual operations by technicians to handle alerts, then the system complexity is low, but the time required to resolve network faults is prolonged

Engineering Contradiction:
Improvefault resolution timeVSAvoidautomation level
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

The system enables self-service through automated alert processing where the network management system automatically performs triage, enrichment, and workflow execution without requiring manual technician intervention for each alert. The IAA system autonomously correlates alerts, enriches them with device and network information, and executes appropriate workflows, allowing the system to serve itself in handling routine fault management tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring multiple collection modalities, normalization rules, and enrichment templates before alerts occur. The triage system is pre-trained with knowledge bases and correlation rules, and the enrichment module has pre-established connections to device inventories and network topology data, enabling rapid automated response when alerts are generated without requiring real-time manual configuration.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If conventional network management systems use only passive monitoring or active polling, then the monitoring approach is simple, but the information completeness is insufficient

Engineering Contradiction:
Improvealert information completenessVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system implements multi-functionality by integrating multiple collection modalities (passive monitoring, active polling, event-driven detection, log analysis) into a single unified platform. The same system architecture handles diverse alert types from various sources, normalizes them through a common framework, and enriches them with relevant context, allowing one system to perform multiple monitoring and analysis functions simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges previously separate functions into an integrated IAA platform: combining alert collection from multiple sources, normalization processing, enrichment with device and network information, triage analysis, and workflow execution into a single cohesive system. This consolidation eliminates information silos and ensures comprehensive alert handling across the entire network management lifecycle.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If conventional network management systems present incomplete information to users, then the system operation is simple, but the fault resolution efficiency is reduced

Engineering Contradiction:
Improvefault resolution efficiencyVSAvoidinformation processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary enrichment module that acts as a mediator between raw alert data and the user interface. This module automatically supplements incomplete alert information by querying device inventories, network topology databases, and historical fault records, then presents comprehensive enriched information to technicians. The intermediary layer handles the complexity of data gathering and synthesis, presenting simplified complete information to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where the triage system continuously learns from resolved faults and refines its correlation rules. The enrichment module uses feedback from workflow outcomes to improve information gathering strategies. Technicians' interactions with enriched alerts provide feedback that进一步优化s the triage algorithms and enrichment templates, creating a self-improving system that increases productivity over time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12579018B2Intelligent alert automation (IAA)
Publication Date: 2026.03.17 LEVEL 3 COMMUNICATIONS LLC
  • US12579018B2 patent drawing
  • US12579018B2 patent drawing
  • US12579018B2 patent drawing

AI summary

Novel tools and techniques are provided for implementing intelligent alert automation (“IAA”). In various embodiments, IAA receives alert/event feeds from several different alerting and ticketing systems via input Redis queues, and uses a triage system to determine whether to process the alert/event or disregard it. If so, IAA may create a flow instance, assign a unique instance ID, and place the flow instance in one of a plurality of jobs queues based on alert/event type and/or or source. An abattoir system retrieves a flow instance from one of the jobs queues (in order of the queue's priority), and processes the next node or step in the flow instance. The flow instance is placed back into the jobs queue for subsequent processing by the same or different abattoir system until no additional nodes or steps remain in the flow, at which point the flow instance is considered complete.