Event Clustering Engine for Managed Infrastructure Failures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing and organizing vast amounts of messages/events from multiple infrastructures, such as email and network traffic, face challenges in clustering and filtering due to high volumes of spam and the dynamic nature of data, leading to inefficiencies in storage and retrieval, and require frequent updates in rule-based approaches which are not scalable.

Innovation Solution

A system for clustering events that includes an extraction engine to identify common characteristics and convert events into clusters, utilizing a collaborative interface for decomposing events, and employing algorithms like NMF and k-means to group events related to failures or errors, providing a resilient and adaptive solution for managing infrastructure data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If rule-based approaches are used to filter and organize events, then initial filtering capability is provided, but the system requires frequent updates and is not scalable to handle dynamic data changes

Engineering Contradiction:
Improveadaptability to dynamic dataVSAvoidsystem update frequency
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system employs unsupervised machine learning algorithms that automatically adapt to new data patterns without requiring manual rule updates. The algorithms self-adjust by learning from incoming event data, enabling the system to handle dynamic data changes autonomously and eliminating the need for frequent manual updates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transitions from static rule-based parameters to dynamic algorithmic parameters that automatically adjust based on data characteristics. The machine learning models change their internal parameters (weights, thresholds) automatically in response to data distribution changes, providing adaptability without manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If all events from multiple infrastructures are stored and retained, then complete information is available for retrieval, but storage requirements and retrieval complexity increase significantly

Engineering Contradiction:
Improveinformation completenessVSAvoidstorage and retrieval complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system extracts and retains only the most relevant event characteristics and patterns using unsupervised learning. By identifying and keeping only significant features rather than storing all raw event data, the system maintains information completeness for meaningful retrieval while reducing storage requirements and complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments events into meaningful clusters based on their characteristics and relationships. By organizing events into groups with common features, the system enables more efficient storage and retrieval operations while preserving the ability to access relevant information through cluster-based queries.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If manual organization of events into folders is performed, then events can be categorized by topic, but the process becomes impractical with hundreds of messages per day

Engineering Contradiction:
Improveevent organizationVSAvoidprocessing speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system automatically performs event organization through unsupervised machine learning algorithms that classify events into clusters based on their characteristics. This eliminates the need for manual folder organization while maintaining effective categorization, thereby improving processing speed without sacrificing organizational quality.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical sorting operations with automated computational algorithms. The unsupervised learning models automatically perform the categorization function that previously required human effort, dramatically increasing productivity while maintaining ease of operation through automated cluster-based organization.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Device complexity

If traditional folder-based systems are used, then simple structure is maintained, but tasks become invisible and easily neglected

Engineering Contradiction:
Improvesystem structureVSAvoidtask visibility
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system uses visual indicators and annotations to highlight important events and clusters, making tasks visible and noticeable. By applying visual differentiation to cluster representations, the system maintains structural simplicity while ensuring that important tasks are not overlooked or neglected.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent implements feedback mechanisms that actively present relevant cluster information to users based on their interactions and priorities. The system provides feedback about important events and tasks through the interface, ensuring visibility and reducing the likelihood of neglect while maintaining a simple underlying structure.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10346229B2System for decomposing events from managed infrastructures
Publication Date: 2019.07.09 DELL PROD LP
  • US10346229B2 patent drawing
  • US10346229B2 patent drawing
  • US10346229B2 patent drawing

AI summary

A system is provided for clustering events. A first engine receives message data from a managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information. A second engine determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. Events are produced that relate to the managed infrastructure while converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware. A situation room is provided with a collaborative interface (UI) for decomposing events from managed infrastructures. The (UI) is available by one or more designated individuals relative to one or more failures or errors in a managed infrastructure.