Event Clusters for IT System Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT systems face challenges in efficiently resolving events across a large number of configuration items (CIs), leading to increased complexity and cost due to manual identification and limited effectiveness in handling evolving environments and unknown events.
Innovation Solution
The system automates event detection and classification by converting event descriptions into standardized formats, allowing for the formation of event clusters based on similarity, which reduces the number of work orders through correlation, suppression, verification, and throttling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If manual identification of CIs is used, then event resolution can be performed with simple systems, but the complexity and cost increase with the number of CIs
Solution Approach 1:
The system enables self-service by automatically detecting events on CIs and classifying them without requiring manual identification. The event detection mechanism autonomously monitors CIs, extracts event data, and performs classification based on predefined criteria, allowing the system to manage itself without human intervention for routine event processing.
Solution Approach 2:
An event correlation service acts as an intermediary between event generators (CIs) and event handlers. This service receives events from multiple CIs, correlates them based on relationships defined in the configuration management database, and manages event clusters, thereby reducing the complexity of direct manual management while maintaining system coherence.
2Productivity
If manual event processing is used, then simple event handling is possible, but productivity decreases with large numbers of CIs
Solution Approach 1:
The system merges multiple related events into event clusters based on correlation relationships. By grouping events that are related through the configuration management database relationships, the system processes them collectively rather than individually, significantly improving productivity when handling large numbers of CIs and reducing the time required for event resolution.
Solution Approach 2:
The system performs preliminary action by pre-defining correlation relationships between CIs in the configuration management database before events occur. When events are generated, the correlation service can immediately match them against pre-established relationships, enabling rapid event clustering and resolution without time-consuming manual analysis of event relationships.
3Reliability
If all events are processed individually, then complete event coverage is achieved, but the number of work orders increases unnecessarily
Solution Approach 1:
The system merges multiple related events into single event clusters that generate one work order instead of multiple separate work orders. By identifying correlation relationships between events through the configuration management database, the system consolidates redundant or related work items, maintaining complete event coverage while reducing the total quantity of work orders to be managed.
Data Source
AI summary
Event clusters can in an example embodiment include converting a description of an event associated with a configuration item (CI) to a standardized description, classifying the event based on a comparison of the standardized description of the event with a standardized description of a prior event included in an existing event cluster, and assigning the classified event to an event cluster.


