Common Information Model for IT Service KPI Normalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data centers face challenges in processing and indexing large volumes of machine-generated data due to its unstructured nature, making it difficult to apply semantic meaning and perform effective searching operations.

Innovation Solution

The implementation of an optimized common information model allows for the creation of entity and service definitions, enabling the normalization of heterogeneous machine data and the derivation of key performance indicators (KPIs) for monitoring service-level performance, facilitating efficient data processing and visualization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If machine data is processed in its original unstructured format, then data volume is preserved, but indexing and searching operations become difficult and inefficient

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddifficulty of applying semantic meaning
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent transforms unstructured machine data into structured data by changing its format parameters. Machine data is converted into standardized events with defined fields, types, and semantic meanings, enabling efficient indexing and searching while preserving the essential information content

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary processing layer that sits between raw machine data and the analysis system. This intermediary layer parses, normalizes, and structures the data into a common format, making it searchable and analyzable without losing the original data's informational value

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional monitoring approaches are used, then implementation is straightforward, but they lack the flexibility to adapt to heterogeneous data sources and evolving service definitions

Engineering Contradiction:
Improveflexibility to associate entities with servicesVSAvoidcomplexity of data normalization and processing
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic entity and service definitions that can be modified at runtime. Entity definitions and service definitions are not fixed but can be updated to accommodate new data sources, services, and relationships, providing adaptability while managing complexity through structured schemas

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the monitoring system into distinct modular components: entity definitions, service definitions, event schemas, and processing logic. This segmentation allows each component to be independently configured and modified, enhancing flexibility while organizing complexity into manageable units

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11748390B1Evaluating key performance indicators of information technology service
Publication Date: 2023.09.05 CISCO TECHNOLOGY INC
  • US11748390B1 patent drawing
  • US11748390B1 patent drawing
  • US11748390B1 patent drawing

AI summary

Technologies are disclosed for providing a common information model. Features include: detecting a scheduled time for a key performance indicator reflecting how a service provided by one or more entities is performing, entity definition information recording the association between the entities and its machine data, service definition information associating the entities that provide the service, and the KPI being defined by a search query, including a field identifier specified in a data model, the KPI derives a value from the machine data; performing the query in response to said detecting, including: associating values in the machine data having disparate field names in accordance with disparate schemas with the field identifier specified in the data model, and processing the associated values as semantically equivalent data instances. In doing so, values having the same semantic (or related semantics) can be used together despite being associated with disparate field names from disparate schemas.