Event Storm Detection via Dynamic Baseline Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In information technology operations management, event storms overwhelm personnel with excessive event logs, making it difficult to distinguish important events from normal activity, leading to false positives and inefficient problem resolution.
Innovation Solution
A computer-implemented method and system that detects event storms by analyzing dynamic baseline event rates and using anomaly detection algorithms to identify constituent events, clustering them based on attribute metrics, and correlating groups to accurately identify events contributing to the storm.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If static thresholds are used to detect event storms, then the detection process is simple, but the accuracy is low leading to false positives
Solution Approach 1:
The patent transitions from static thresholds to dynamic baselines that adapt over time. The system learns normal event rates from historical data and dynamically adjusts thresholds, allowing the detection mechanism to respond to changing system conditions while maintaining accuracy and reducing false positives.
Solution Approach 2:
The patent changes the parameter from fixed threshold values to dynamically calculated baselines based on historical event rates. By using statistical measures like mean and standard deviation from learned data, the system adapts thresholds to reflect actual system behavior patterns, improving detection precision.
2Quantity of substance
If all events in an event storm are grouped together, then the volume of events is reduced, but the ability to identify contributing events is lost
Solution Approach 1:
The patent segments the event storm into constituent event groups based on statistical analysis. Instead of treating all events uniformly, the system identifies and separates events that deviate significantly from the baseline, preserving information about which specific events contribute to the storm while still reducing overall volume through systematic categorization.
Solution Approach 2:
The patent applies different treatment to different events within the storm based on their statistical properties. Events are evaluated individually against the dynamic baseline, and those showing significant deviation are identified as contributing events, giving each event appropriate attention based on its local characteristics rather than uniform grouping.
3Measurement precision
If operational personnel manually analyze event logs, then detailed inspection is possible, but the process is time-consuming and inefficient
Solution Approach 1:
The patent implements self-service through automated statistical analysis that performs detailed event evaluation without human intervention. The system automatically learns baselines, detects anomalies, identifies contributing events, and generates insights, enabling detailed analysis at machine speed and eliminating the time cost of manual review while maintaining or improving accuracy.
Solution Approach 2:
The patent replaces the mechanical process of manual log analysis with automated computational methods. Statistical algorithms and machine learning models substitute for human operators, performing detailed event inspection, pattern recognition, and anomaly detection automatically, thereby achieving both precision and speed.
4Measurement precision
If dynamic baseline algorithms are used to detect event storms, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent introduces statistical measures (mean, standard deviation, z-scores) as intermediaries between raw event data and storm detection decisions. These statistical tools serve as mediators that translate complex event patterns into interpretable metrics, improving detection accuracy while maintaining system comprehensibility and manageable complexity.
Data Source
AI summary
A method and system are provided for identification of constituent events in an event storm in operations management. The method includes: detecting an event storm by detecting an anomaly from a dynamic baseline range of expected event rates in a sample time period; and, when an event storm is detected, for each of a group of events grouped by an event category and occurring in a sample time period of an event storm, identifying the group of events as constituting part of the event storm if the rate of the event occurrences of the group in the sample time period is outside a threshold deviation from an average for that group.


