Cross-Domain Analytics Correlation for Heterogeneous Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Efficiently presenting performance data across multiple non-overlapping or partially overlapping monitoring domains while enabling root cause analysis is challenging due to the vast volume and variety of information sources and formats in big data analytics systems.
Innovation Solution
A system management architecture that collects, configures, and displays logged and real-time system management data from multiple service domains using a log management host and service agents or agentless collection mechanisms, processing performance data to generate analytics information for efficient display and correlation across domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple non-overlapping or partially overlapping monitoring domains are used to capture information from various sources, then the coverage and variety of data collected is improved, but the complexity of presenting and correlating analytics across domains increases
Solution Approach 1:
The system segments analytics into domain-specific analytics (DSA) that are organized by monitoring domain. Each DSA contains analytics relevant to a specific domain, allowing independent processing and presentation while maintaining overall system coherence. This segmentation reduces presentation complexity by localizing analytics within their respective domains rather than requiring global correlation of all analytics across all domains.
Solution Approach 2:
The system introduces correlated analytics (CA) as an intermediary mechanism that links DSAs from different domains. The CA identifies and presents correlations between analytics in different monitoring domains, enabling efficient cross-domain analysis without requiring direct comparison of all analytics pairs. This intermediary approach simplifies the presentation complexity while maintaining comprehensive data coverage.
2Loss of information
If analytics are processed to create result reports and alarms from vast volume of information, then the insight quality is improved, but the time and resources required for evaluation increase
Solution Approach 1:
The system performs preliminary organization of analytics into domain-specific analytics (DSA) and identifies correlated analytics (CA) in advance. By pre-organizing analytics by domain and pre-identifying potential correlations, the system reduces the evaluation time required when queries are executed. The analytics are prepared and structured beforehand, allowing rapid retrieval and presentation without requiring exhaustive real-time analysis of all analytics.
3Loss of information
If performance data from multiple service domains is collected and stored, then the completeness of monitoring information is improved, but the difficulty of correlating data across domains increases
Solution Approach 1:
The system segments collected performance data into domain-specific analytics (DSA) organized by service domain. Each DSA contains analytics derived from performance data within a specific monitoring domain, maintaining the completeness of information while organizing it in a manageable structure. This segmentation makes correlation easier by providing a clear organizational framework that groups related analytics together.
Solution Approach 2:
The system uses correlated analytics (CA) as an intermediary to detect and measure relationships between performance data across different service domains. The CA mechanism identifies and presents correlations between DSAs from different domains, reducing the difficulty of detecting cross-domain relationships. This intermediary approach provides a systematic method for discovering and presenting correlations without requiring manual analysis of all possible data combinations.
Data Source
AI summary
Techniques for generating and rendering analytics data from system management data collected for multiple service domains are disclosed herein. In some embodiments, performance data are collected from multiple service domains that are each configured to determine performance metrics for one or more target system entities. The performance data for a first of the service domains is monitoring including, displaying metric objects representing variations in performance metrics for the first service domain and detecting a performance event for the first service domain, wherein the performance event is associated with a target system entity and a performance metric value. In response to said detecting the performance event, a metric object is displayed that indicates an association between an entity identifier (ID) of the target system entity and the performance metric value. An operational association between the target system entity associated with the performance event and a second of the service domains is identified. In response to selection of the event object, an analytics object is displayed that indicates analytics information generated based, at least in part, on a metric type of the performance metric value and the identified operational association between the target system entity associated with the performance event and the second service domain.


