Cross-Cutting Event Correlation in Enterprise Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise computing monitoring systems face inefficiencies due to event flooding and scalability issues, as correlation rules are often centralized, leading to increased communication latency and reduced processing efficiency, especially in large environments where events from multiple nodes need to be correlated.

Innovation Solution

Implementing a cross-cutting event correlation method that moves correlation rules closer to the event source based on frequency of occurrence, using a hierarchy of nodes with embedded correlation engines and an event bus, to process events more efficiently by reducing communication latency and improving pattern detection and remedial actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If correlation rules are centralized at the highest level in the hierarchy, then all events can be captured and processed in a single location, but scalability is sacrificed and communication latency increases

Engineering Contradiction:
Improveevent processing reliabilityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the centralized correlation engine into multiple distributed correlation engines placed at different levels of the hierarchy. Each correlation engine processes events locally at its level, segmenting the processing function across multiple nodes rather than concentrating it at a single centralized location, thereby improving scalability and reducing latency while maintaining processing reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local event correlation by placing correlation engines at specific hierarchy levels to process events originating from particular event sources. Each correlation engine is positioned optimally relative to its event sources, enabling local processing with minimal latency. The system determines appropriate placement based on event source characteristics and correlation rule requirements, creating local quality in the distributed architecture

Inventive Principle:
Principle #3Local quality

2Productivity

If correlation engines are embedded at lower levels in the hierarchy, then processing efficiency improves by reducing latency, but the ability to capture patterns from multiple nodes is reduced

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidpattern detection capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent makes correlation engines universal by enabling them to perform multiple functions: processing local events from their immediate event sources and simultaneously receiving events from higher hierarchy levels for cross-level pattern detection. Each correlation engine is configured to handle both local correlation rules and inherited rules from parent nodes, making it multi-functional and adaptable to different processing requirements at any hierarchy level

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds a vertical dimension to event processing by allowing correlation engines to operate not only at their local horizontal level but also to receive and process events from upper hierarchy levels. This creates a multi-dimensional processing approach where correlation engines can detect patterns both locally and across hierarchical dimensions, expanding their pattern detection capability without sacrificing processing efficiency

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Loss of information

If every event is reported through the user interface, then complete event information is available, but the system is overwhelmed by event flooding

Engineering Contradiction:
Improveevent information completenessVSAvoidsystem throughput
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent extracts and filters events through correlation engines that process and correlate events before they reach the user interface. The correlation engines identify patterns and root cause events, extracting only the relevant information that needs to be presented to administrators. This extraction process prevents event flooding by filtering out redundant events while preserving critical information about root causes and patterns

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements feedback mechanisms where correlation engines continuously analyze events and provide feedback about patterns and anomalies to both the event processing system and administrators. This feedback loop enables the system to learn from event patterns and adjust processing behavior, while also providing administrators with curated information about significant events without overwhelming them with complete event data

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9210057B2Cross-cutting event correlation
Publication Date: 2015.12.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9210057B2 patent drawing
  • US9210057B2 patent drawing
  • US9210057B2 patent drawing

AI summary

Embodiments of the present invention provide a method, system and computer program product for cross-cutting event correlation in an enterprise computing monitoring and management system. An enterprise computing monitoring and management system can include a hierarchy of nodes, where several of the nodes are each coupled to a corresponding embedded correlation engine and an event bus. The system further can include a root node among the nodes. The root node can be coupled to the event bus and to centralized correlation logic programmed to identify a high correspondence between events from a particular event source among the nodes and a particular set of correlation rules in that correlation engine. The identification of such correspondence can be used to move to the set of correlation rules to an embedded correlation engine closer to the particular event source.