Event Clustering System for Managed Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing and organizing vast amounts of messages/events from infrastructure, such as email and network communications, face challenges in clustering and retrieving relevant information due to the lack of automated indexing and the scalability issues of rule-based systems, leading to inefficiencies in spam detection and application dependency analysis in data centers.
Innovation Solution
An event clustering system that utilizes a sigalizer engine to determine common steps from events, produce clusters, and employ graphing technology with vectors, effectively grouping events related to alerts and failures in managed infrastructure, and utilizing historical data for resilience and error estimation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If manual directory creation and organization is used, then information can be organized into hierarchical structures, but the process becomes impractical for massive amounts of web-based information and requires significant human time and effort
Solution Approach 1:
The system enables self-service by automatically analyzing incoming events, extracting characteristics, and organizing them into clusters without human intervention. The event clustering system autonomously performs what previously required manual directory creation, using algorithms to identify patterns and group related events automatically.
Solution Approach 2:
The system transforms the organization approach by changing from manual hierarchical classification to automated parameter-based clustering. Events are organized based on extracted characteristics and patterns rather than manual directory structures, allowing the system to handle massive volumes of information efficiently.
2Adaptability or versatility
If rule-based systems are used for spam detection and event management, then specific patterns can be detected, but the systems face scalability issues and cannot effectively handle evolving spam techniques
Solution Approach 1:
The system transitions from static rule-based detection to dynamic pattern recognition. The event clustering system continuously learns from incoming events, adapting to new spam patterns and techniques automatically. This dynamic approach allows the system to evolve with emerging threats without requiring manual rule updates.
Solution Approach 2:
The system replaces mechanical rule-based filtering with intelligent pattern recognition algorithms. Instead of relying on predefined rules that require manual updates, the system uses automated clustering and characteristic extraction to detect and adapt to evolving spam patterns, reducing the need for manual system reconfiguration.
3Ease of operation
If folders are used to organize messages, then messages can be sorted into categories, but tasks become invisible and easily neglected, and messages can only be in one folder at a time
Solution Approach 1:
The event clustering system provides multi-functionality by allowing events to belong to multiple clusters simultaneously based on their characteristics. Unlike traditional single-folder organization, the system can categorize the same event under different clusters depending on the perspective or type of analysis, enabling comprehensive task management and improved visibility.
Solution Approach 2:
The system adds another dimension to message organization by implementing multi-dimensional clustering. Instead of single-folder hierarchy, events are organized across multiple clustering dimensions simultaneously, allowing users to view and retrieve messages from multiple perspectives while maintaining task visibility through various cluster views.
Data Source
AI summary
A system is provided for clustering events. A first engine is configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information. A second engine determines common characteristics of events and produces clusters of events relating to a failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. One or more situations are created that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. In response to the production of the clusters one or more physical changes in the managed infrastructure hardware.


