Event Clustering Engine for Managed Infrastructure Failures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing and organizing vast amounts of messages/events from multiple infrastructures, such as email and network traffic, face challenges in clustering and filtering due to high volumes of spam and the dynamic nature of data, leading to inefficiencies in storage and retrieval, and require frequent updates in rule-based approaches which are not scalable.
Innovation Solution
A system for clustering events that includes an extraction engine to identify common characteristics and convert events into clusters, utilizing a collaborative interface for decomposing events, and employing algorithms like NMF and k-means to group events related to failures or errors, providing a resilient and adaptive solution for managing infrastructure data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If rule-based approaches are used to filter and organize events, then initial filtering capability is provided, but the system requires frequent updates and is not scalable to handle dynamic data changes
Solution Approach 1:
The system employs unsupervised machine learning algorithms that automatically adapt to new data patterns without requiring manual rule updates. The algorithms self-adjust by learning from incoming event data, enabling the system to handle dynamic data changes autonomously and eliminating the need for frequent manual updates.
Solution Approach 2:
The patent transitions from static rule-based parameters to dynamic algorithmic parameters that automatically adjust based on data characteristics. The machine learning models change their internal parameters (weights, thresholds) automatically in response to data distribution changes, providing adaptability without manual intervention.
2Loss of information
If all events from multiple infrastructures are stored and retained, then complete information is available for retrieval, but storage requirements and retrieval complexity increase significantly
Solution Approach 1:
The system extracts and retains only the most relevant event characteristics and patterns using unsupervised learning. By identifying and keeping only significant features rather than storing all raw event data, the system maintains information completeness for meaningful retrieval while reducing storage requirements and complexity.
Solution Approach 2:
The patent segments events into meaningful clusters based on their characteristics and relationships. By organizing events into groups with common features, the system enables more efficient storage and retrieval operations while preserving the ability to access relevant information through cluster-based queries.
3Ease of operation
If manual organization of events into folders is performed, then events can be categorized by topic, but the process becomes impractical with hundreds of messages per day
Solution Approach 1:
The system automatically performs event organization through unsupervised machine learning algorithms that classify events into clusters based on their characteristics. This eliminates the need for manual folder organization while maintaining effective categorization, thereby improving processing speed without sacrificing organizational quality.
Solution Approach 2:
The patent replaces manual mechanical sorting operations with automated computational algorithms. The unsupervised learning models automatically perform the categorization function that previously required human effort, dramatically increasing productivity while maintaining ease of operation through automated cluster-based organization.
4Device complexity
If traditional folder-based systems are used, then simple structure is maintained, but tasks become invisible and easily neglected
Solution Approach 1:
The system uses visual indicators and annotations to highlight important events and clusters, making tasks visible and noticeable. By applying visual differentiation to cluster representations, the system maintains structural simplicity while ensuring that important tasks are not overlooked or neglected.
Solution Approach 2:
The patent implements feedback mechanisms that actively present relevant cluster information to users based on their interactions and priorities. The system provides feedback about important events and tasks through the interface, ensuring visibility and reducing the likelihood of neglect while maintaining a simple underlying structure.
Data Source
AI summary
A system is provided for clustering events. A first engine receives message data from a managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information. A second engine determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. Events are produced that relate to the managed infrastructure while converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware. A situation room is provided with a collaborative interface (UI) for decomposing events from managed infrastructures. The (UI) is available by one or more designated individuals relative to one or more failures or errors in a managed infrastructure.


