Event Clustering System Using Natural Language Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing and organizing events from managed infrastructures, such as email and network communications, face challenges in efficiently clustering and retrieving relevant information due to the high volume of data and the lack of effective automated indexing, leading to difficulties in identifying actionable problems and resolving issues in a timely manner.
Innovation Solution
A system utilizing natural language processing techniques to analyze event data from managed infrastructures, clustering events related to failures or errors, and identifying common characteristics to create actionable problem clusters, thereby facilitating resolution through a situation room interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual organization of events into folders is used, then information can be sorted by topic, but the process becomes impractical due to the massive volume of information generated daily
Solution Approach 1:
The system automatically indexes and categorizes events without human intervention. The automated indexing service analyzes event data, extracts meaningful information, and organizes events into clusters based on common characteristics, allowing the system to serve itself rather than requiring manual user action for each event.
Solution Approach 2:
The patent replaces manual mechanical sorting operations with automated computational processes. Instead of users physically dragging and dropping events into folders, an automated indexing service using natural language processing and machine learning algorithms performs the organization, substituting human cognitive and manual labor with computational automation.
2Productivity
If automated indexing is implemented, then processing speed increases, but the system complexity increases due to the need for sophisticated algorithms
Solution Approach 1:
The automated indexing service is divided into distinct functional components: event data reception modules, natural language processing engines, clustering algorithms, and result output interfaces. This segmentation allows each component to be optimized independently and facilitates modular deployment, reducing overall system complexity while maintaining high processing speeds.
Solution Approach 2:
The patent introduces an automated indexing service as an intermediary layer between raw event data and the user interface. This intermediary handles the complex processing tasks of parsing, analyzing, and clustering events, shielding the user from system complexity while enabling rapid information retrieval and organization.
3Device complexity
If events are placed in single folders, then organization is simple, but tasks become invisible and are easily neglected
Solution Approach 1:
The automated indexing service enables events to belong to multiple clusters simultaneously based on different characteristics. A single event can be categorized under multiple topics or priorities, allowing it to serve multiple functions and remain visible across different organizational contexts, thereby increasing the likelihood of task completion without complicating the underlying structure.
4Adaptability or versatility
If manual directory creation is used, then directory structure can be customized, but the process is impractical for handling massive amounts of web-based information
Solution Approach 1:
The system automatically analyzes event characteristics and creates appropriate clustering structures without requiring users to manually design directory hierarchies. The automated service adapts the organization structure based on the actual content and patterns in the data, making the system self-configuring rather than requiring manual setup for each new information domain.
Data Source
AI summary
A system is provided for decomposing events from managed infrastructures. A first engine is configured to receive message data from a managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, The at least one engine is configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in a physical hardware of the managed infrastructure directed to supporting the flow and processing of information. The first engine is configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. A second engine is configured to determine one or more common steps from events and produces clusters relating to events. The second engine determines one or more common characteristics of events and produces clusters of events relating to the failure or errors in the managed infrastructure. The system is configured to use natural language processing techniques to analyze threshold entries in a situation room to identify resolutions to problems.


