Cloud Alert Enrichment via Identity Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud storage systems, identifying the source of faults or alerts is challenging due to the complexity of components from multiple vendors, leading to inefficient information exchange and time-consuming troubleshooting, which can result in significant detrimental impacts on enterprises.

Innovation Solution

A method that processes alerts/events using a computer processor with an identity matching service to generate resource identifiers, enabling the identification of associated services, platforms, virtual machines, virtual applications, virtual data centers, organizations, and platform components, thereby providing context for IT personnel to prioritize and address issues effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If alerts/events are collected from multiple components without enrichment, then the system can maintain simplicity in alert collection, but IT personnel cannot efficiently identify the source or context of faults

Engineering Contradiction:
Improveease of fault identificationVSAvoidcontext information of alerts
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system performs preliminary enrichment of alerts by associating them with relevant physical or logical topology resources before presentation to IT personnel. This includes identifying the source component, propagating alerts through the topology to affected resources, and enriching with contextual information such as organization, application, and service relationships. This preliminary action eliminates the need for manual troubleshooting and ensures context is available when alerts are first presented.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If manual troubleshooting of unenriched alerts is performed, then IT personnel can analyze each alert individually, but the process becomes time-consuming and results in significant detrimental impact on enterprises

Engineering Contradiction:
Improvealert resolution speedVSAvoidtroubleshooting time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system introduces an intermediary enrichment process that automatically associates alerts with relevant topology resources and contextual information. This intermediary layer transforms raw, unenriched alerts into enriched alerts containing source identification, affected resources, and contextual relationships. This eliminates the need for manual analysis and significantly reduces troubleshooting time while maintaining accurate fault identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If alerts are presented without association to physical or logical topology resources, then the alert system remains simple to implement, but IT personnel cannot prioritize alerts or take proper actions

Engineering Contradiction:
Improvealert prioritization capabilityVSAvoidalert enrichment system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The enrichment system performs multiple functions simultaneously: identifying the source component of alerts, propagating alerts through the topology to identify affected resources, associating alerts with organizational and application context, and enabling prioritization. This multi-functional approach provides comprehensive alert management capabilities while managing complexity through automated processes and standardized data structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9170951B1Method and apparatus for event/alert enrichment
Publication Date: 2015.10.27 EMC IP HLDG CO LLC
  • US9170951B1 patent drawing
  • US9170951B1 patent drawing
  • US9170951B1 patent drawing

AI summary

Methods and apparatus to provide alert enrichment in a cloud storage system. In one embodiment, the system performs alert/event identification with information from an identity matching service for the components of the cloud storage system to generate a resource identifier for the component associated with a first one of the processed alerts/events, and use the resource identifier to identify a service, platform, virtual machine, virtual application, virtual data center, organization and/or platform component associate with the first one of the processed alerts/events.