Event Management Pipeline Algorithm for Root Cause Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network Operations Control teams face overwhelming volumes of network events, making manual analysis and prioritization time-consuming, and existing solutions are inadequate as they often rely on network topology, which can change, requiring frequent updates.

Innovation Solution

A method that groups events into tuples based on logical attributes using a pipeline algorithm to create hierarchized relations, identifying parent tuples as 'root issues' without relying on network topology, thereby reducing the number of critical events and adapting to topology changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual analysis and prioritization of events is performed, then events can be classified according to severity, but the process becomes extensive and time-consuming

Engineering Contradiction:
Improveevent classification accuracyVSAvoidtime for event analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis with an automated machine learning pipeline that processes events through multiple stages (filtering, grouping, parent-child relationship identification). This automated system maintains classification accuracy while eliminating the time-consuming manual review process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service by allowing the machine learning model to automatically learn patterns and relationships from event data without human intervention. The model independently performs filtering, grouping, and prioritization tasks that would otherwise require manual expertise.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If existing event management solutions are used to classify events by severity, then events are categorized, but approximately 10-20% of events are still listed as critical, providing an amount of events far from appropriate

Engineering Contradiction:
Improvecritical event identification accuracyVSAvoidnumber of critical events
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the event classification process into distinct stages: initial filtering to remove noise, grouping events into families based on shared characteristics, and identifying parent-child relationships to prioritize root causes. This multi-stage segmentation allows for more precise identification of truly critical events while filtering out less significant ones.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds dimensional analysis by introducing parent-child relationships and event families beyond simple severity classification. Instead of a single severity dimension, the system analyzes events across multiple dimensions (grouping relationships, causal relationships, temporal patterns), enabling more accurate prioritization and reducing the number of false critical event identifications.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If manually crafted rules are used for event management, then some cases can be handled, but the rules depend on network topology and need to be updated or replaced when topology changes

Engineering Contradiction:
Improveevent management simplicityVSAvoidadaptability to topology changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic system where the machine learning model continuously learns from new event data and adapts to changing network conditions. Unlike static manual rules, the model automatically adjusts its classification and grouping logic based on observed patterns, maintaining effectiveness as network topology evolves without requiring manual rule updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters dynamically by learning optimal filtering thresholds, grouping criteria, and relationship weights from data rather than using fixed manual parameters. This allows the system to adapt to topology changes by adjusting its internal parameters based on observed event patterns rather than requiring external rule modifications.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If the number of critical events is reduced, then NOC teams have fewer events to handle, but it becomes more challenging to identify which events need attention

Engineering Contradiction:
ImproveNOC team efficiencyVSAvoidevent priority identification difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent incorporates feedback mechanisms where the system's classifications and prioritizations can be reviewed and corrected by NOC teams, with these corrections feeding back into the model to improve future classifications. This feedback loop ensures that the reduced set of prioritized events maintains high accuracy and that the system learns from actual operational experience.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system introduces an intermediary layer of automated analysis that bridges the gap between raw event data and NOC team decision-making. This intermediary performs the complex analysis of filtering, grouping, and prioritization, presenting a curated set of events with identified relationships and potential root causes, thereby reducing the difficulty for NOC teams to identify which events need attention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11641304B2Method for managing a plurality of events
Publication Date: 2023.05.02 GUAVUS INC
  • US11641304B2 patent drawing
  • US11641304B2 patent drawing

AI summary

The invention provides a method for managing a plurality of events, wherein each event comprises physical attributes and logical attributes by creating tuples with the events with the same logical attributes, providing a set of hierarchized relations between tuples, by means of a pipeline algorithm, wherein parent-child relations are provided between tuples, classifying the tuples in families, each family contains all the tuples related according to the parent-child relation provided by the pipeline algorithm, identify the parent tuple of each family, defined as the tuple which has at least one children and has no parent and present the parent tuples, together with the physical attributes of the events associated to each parent tuple.