ITSM Incident Data Behavioral Analytics via De-normalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity and volume of native ITSM data make it challenging to extract meaningful behavioral insights from incident handling logs in IT infrastructure, as existing systems struggle to analyze and parse through large amounts of machine-generated data effectively.
Innovation Solution
A computer system that transforms native ITSM data into a de-normalized target data source using a transformation processor and statistical processor, creating new normalized fields and aggregating incident handling data to characterize behavioral patterns, such as 'work,' 'wait,' and 'waste,' thereby reducing data complexity and size for easier consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Stability of the object's composition
If native ITSM data is stored in normalized format following ITIL framework standards, then data consistency and standardization are improved, but data complexity and difficulty in extracting behavioral insights increase
Solution Approach 1:
The patent segments the complex normalized ITSM data into distinct behavioral categories (work, wait, waste) by creating separate data fields for each behavior type. This segmentation allows the system to maintain the standardized structure while making the data more analyzable by breaking down the monolithic normalized format into structured behavioral components that can be independently analyzed.
Solution Approach 2:
The patent introduces an intermediary data structure that sits between the normalized ITSM data and the behavioral analysis requirements. This intermediary layer transforms and enriches the normalized data by adding behavioral context and categorization, serving as a bridge that reconciles the standardization requirements with the analytical needs without modifying the original normalized data structure.
2Measurement precision
If incident handling data is aggregated with detailed behavioral characteristics, then behavioral analytics capability is improved, but data processing time and computational resources increase
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing behavioral characteristics (work, wait, waste metrics) during the data aggregation process rather than calculating them in real-time during analysis. The system proactively enriches the aggregated data with behavioral metrics and stores them in an optimized format, so that when behavioral analytics are needed, the computations have already been performed and stored for rapid retrieval.
Solution Approach 2:
The patent changes the parameters of the data structure by transforming raw incident handling data into behavioral parameters (work time, wait time, waste time) with specific units and formats optimized for analysis. This parameter transformation allows the system to maintain detailed behavioral characteristics while reducing processing time by using pre-defined calculation rules and optimized data representations.
3Measurement precision
If de-normalized target data source is created with new normalized fields, then behavioral pattern recognition is improved, but data transformation complexity increases
Solution Approach 1:
The patent segments the data transformation process into distinct stages: extracting incident handling data, creating normalized behavioral fields, aggregating data, and enriching with behavioral characteristics. Each stage handles a specific aspect of the transformation, reducing the overall complexity by breaking down the monolithic transformation process into manageable, reusable components with clear interfaces.
Solution Approach 2:
The patent creates a universal data transformation framework that can handle multiple types of incident handling data through a common set of normalized behavioral fields. The same transformation logic and field structures are applied across different data sources and incident types, making the transformation process reusable and reducing complexity through standardization rather than custom handling for each case.
Data Source
AI summary
A computer system for behavioral analytics of native Information Technology Service Management (ITSM) incident handling data includes a processor, a memory, a de-normalized target data source for behavioral analysis, a transformation processor, and a statistical processor. The transformation processor reads an identified portion of the ITSM data and creates new normalized fields for the de-normalized target data source by parsing selected text fields from the portion of ITSM data. The created new normalized fields include a working group field and an associated support level field. The transformation processor further creates new de-normalized aggregation fields for the incipient de-normalized target data source based on the newly created normalized fields. The newly created de-normalized aggregation fields include fields characterizing incident handling behavior. A statistical processor further processes target data for behavioral analytics. The transformation processor populates the target data source's de-normalized data fields with aggregated incident handling data and behavioral characterizations.


