Cross-Cutting Event Correlation in Enterprise Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise computing monitoring systems face inefficiencies due to event flooding and scalability issues, as correlation rules are often centralized, leading to increased communication latency and reduced processing efficiency, especially in large environments where events from multiple nodes need to be correlated.
Innovation Solution
Implementing a cross-cutting event correlation method that moves correlation rules closer to the event source based on frequency of occurrence, using a hierarchy of nodes with embedded correlation engines and an event bus, to process events more efficiently by reducing communication latency and improving pattern detection and remedial actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If correlation rules are centralized at the highest level in the hierarchy, then all events can be captured and processed in a single location, but scalability is sacrificed and communication latency increases
Solution Approach 1:
The patent divides the centralized correlation engine into multiple distributed correlation engines placed at different levels of the hierarchy. Each correlation engine processes events locally at its level, segmenting the processing function across multiple nodes rather than concentrating it at a single centralized location, thereby improving scalability and reducing latency while maintaining processing reliability
Solution Approach 2:
The patent implements local event correlation by placing correlation engines at specific hierarchy levels to process events originating from particular event sources. Each correlation engine is positioned optimally relative to its event sources, enabling local processing with minimal latency. The system determines appropriate placement based on event source characteristics and correlation rule requirements, creating local quality in the distributed architecture
2Productivity
If correlation engines are embedded at lower levels in the hierarchy, then processing efficiency improves by reducing latency, but the ability to capture patterns from multiple nodes is reduced
Solution Approach 1:
The patent makes correlation engines universal by enabling them to perform multiple functions: processing local events from their immediate event sources and simultaneously receiving events from higher hierarchy levels for cross-level pattern detection. Each correlation engine is configured to handle both local correlation rules and inherited rules from parent nodes, making it multi-functional and adaptable to different processing requirements at any hierarchy level
Solution Approach 2:
The patent adds a vertical dimension to event processing by allowing correlation engines to operate not only at their local horizontal level but also to receive and process events from upper hierarchy levels. This creates a multi-dimensional processing approach where correlation engines can detect patterns both locally and across hierarchical dimensions, expanding their pattern detection capability without sacrificing processing efficiency
3Loss of information
If every event is reported through the user interface, then complete event information is available, but the system is overwhelmed by event flooding
Solution Approach 1:
The patent extracts and filters events through correlation engines that process and correlate events before they reach the user interface. The correlation engines identify patterns and root cause events, extracting only the relevant information that needs to be presented to administrators. This extraction process prevents event flooding by filtering out redundant events while preserving critical information about root causes and patterns
Solution Approach 2:
The patent implements feedback mechanisms where correlation engines continuously analyze events and provide feedback about patterns and anomalies to both the event processing system and administrators. This feedback loop enables the system to learn from event patterns and adjust processing behavior, while also providing administrators with curated information about significant events without overwhelming them with complete event data
Data Source
AI summary
Embodiments of the present invention provide a method, system and computer program product for cross-cutting event correlation in an enterprise computing monitoring and management system. An enterprise computing monitoring and management system can include a hierarchy of nodes, where several of the nodes are each coupled to a corresponding embedded correlation engine and an event bus. The system further can include a root node among the nodes. The root node can be coupled to the event bus and to centralized correlation logic programmed to identify a high correspondence between events from a particular event source among the nodes and a particular set of correlation rules in that correlation engine. The identification of such correspondence can be used to move to the set of correlation rules to an embedded correlation engine closer to the particular event source.


