Event Correlation System for Data Center Storm Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data centers and computing environments, event storms often occur due to multiple systems generating events when a single resource experiences issues, overwhelming operators with uncorrelated data, making it difficult to efficiently manage and address performance issues.

Innovation Solution

A system and technique for correlating computing network events by identifying resources associated with a deployment pattern, using a correlation identifier to group events generated by resources within a common deployment pattern, thereby reducing the number of events that need to be addressed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple systems generate events independently when a resource experiences issues, then each system can detect and report problems accurately, but the quantity of events increases dramatically creating event storms that overwhelm operators

Engineering Contradiction:
Improveevent detection accuracyVSAvoidevent quantity
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent merges multiple independent event streams into a unified correlated view by identifying relationships between events from different systems. The event management system correlates events based on resource relationships, combining them into a consolidated representation that maintains detection accuracy while reducing the apparent quantity of events operators must process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The event management system acts as an intermediary between multiple generating systems and operators. It receives events from various systems, processes them through correlation logic, and presents a consolidated view to operators, thereby mediating the information flow and reducing event storm impact.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a consolidated view of events is provided to reduce the number of events operators must handle, then issue management efficiency improves, but the complexity of the event correlation system increases

Engineering Contradiction:
Improveissue management efficiencyVSAvoidevent correlation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary correlation processing of events as they are received, establishing relationships between events and resources before presentation to operators. This advance processing consolidates event data in real-time, improving operational efficiency without requiring complex post-processing or manual analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11177999B2Correlating computing network events
Publication Date: 2021.11.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11177999B2 patent drawing
  • US11177999B2 patent drawing
  • US11177999B2 patent drawing

AI summary

A system and technique for correlating computing network events includes receiving a deployment request for a computing service and identify a deployment template corresponding to the requested computing service where the deployment template indicates resources needed for providing the computing service. Available resources are identified and targeted based on the deployment template. The targeted resources are deployed and the deployment template is associated in a memory with an identification of a resource set indicating each of the deployed resource elements. Responsive to receiving an event including a resource identifier, an event manager identifies the resource set having the deployed resource corresponding to the resource identifier and correlates the event with at least one other active event corresponding to the resource set.