Event Clustering Dashboard for Infrastructure Alert Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing and organizing vast amounts of web-based communication, such as email and network traffic, face challenges in efficiently clustering and filtering messages due to the high volume of spam and the need for constant updates in spam detection algorithms, as well as limitations in monitoring and processing large network traffic data.
Innovation Solution
An event clustering system that uses a sigalizer engine to determine common characteristics of events and produce clusters related to failures or errors in managed infrastructure, employing techniques like Shannon entropy, k-means clustering, and NMF decomposition to create actionable problem clusters, and a dashboard system for displaying these clusters to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If traditional folder-based systems are used to organize messages, then messages can be stored in categories, but it becomes difficult to locate and retrieve messages related to the same topic when receiving hundreds of messages daily
Solution Approach 1:
The patent applies strong oxidants by using aggressive clustering algorithms that rapidly group messages by topic, automatically identifying and categorizing hundreds of daily messages without manual intervention, thereby accelerating the organization process and improving retrieval efficiency
Solution Approach 2:
The system changes parameters by dynamically adjusting clustering thresholds and topic identification parameters based on message volume and user behavior patterns, allowing the system to adaptively optimize message grouping and retrieval as message volumes increase
2Loss of information
If web directories are created to organize web-based information, then information can be hierarchically organized, but the manual process of creating directories and deciding where information belongs is impractical for massive amounts of web information
Solution Approach 1:
The patent implements self-service by enabling the clustering system to automatically analyze message content, identify topics, and create organizational structures without human intervention, allowing the system to autonomously manage massive volumes of web-based information
Solution Approach 2:
The system replaces manual mechanical directory creation with automated computational clustering algorithms that use text analysis and pattern recognition to organize information, substituting human cognitive processes with machine-based automation
3Reliability
If spam detection algorithms are constantly updated to handle high volume spam, then spam detection accuracy improves, but the complexity of maintaining and updating algorithms increases
Solution Approach 1:
The patent applies preliminary action by pre-training clustering models on large datasets of spam and legitimate messages, establishing robust baseline detection capabilities that can handle high volumes without requiring constant updates, thereby maintaining reliability while reducing maintenance complexity
Solution Approach 2:
The system achieves universality by designing a multi-functional clustering framework that handles both spam detection and legitimate message organization using the same underlying technology, reducing the need for separate specialized algorithms and their associated maintenance burdens
4Reliability
If large network traffic data is monitored and processed, then comprehensive infrastructure monitoring is achieved, but the volume of data makes clustering and filtering challenging
Solution Approach 1:
The patent applies segmentation by dividing network traffic data into distinct clusters based on source, destination, protocol, and content characteristics, allowing the system to process large volumes of infrastructure data in manageable segments rather than as a monolithic dataset
Data Source
AI summary
A user interface system has at least a first engine configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information. The at least first engine determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. One or more situations are created that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. A display computer system generates a dashboard display that includes situations from clustered messages received from managed infrastructure. The display computer system is coupled to or included in a situation room coupled to the at least first engines.


