ITSM Incident Data Behavioral Analytics via De-normalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity and volume of native ITSM data make it challenging to extract meaningful behavioral insights from incident handling logs in IT infrastructure, as existing systems struggle to analyze and parse through large amounts of machine-generated data effectively.

Innovation Solution

A computer system that transforms native ITSM data into a de-normalized target data source using a transformation processor and statistical processor, creating new normalized fields and aggregating incident handling data to characterize behavioral patterns, such as 'work,' 'wait,' and 'waste,' thereby reducing data complexity and size for easier consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Stability of the object's composition

If native ITSM data is stored in normalized format following ITIL framework standards, then data consistency and standardization are improved, but data complexity and difficulty in extracting behavioral insights increase

Engineering Contradiction:
Improvedata consistencyVSAvoiddata complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent segments the complex normalized ITSM data into distinct behavioral categories (work, wait, waste) by creating separate data fields for each behavior type. This segmentation allows the system to maintain the standardized structure while making the data more analyzable by breaking down the monolithic normalized format into structured behavioral components that can be independently analyzed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary data structure that sits between the normalized ITSM data and the behavioral analysis requirements. This intermediary layer transforms and enriches the normalized data by adding behavioral context and categorization, serving as a bridge that reconciles the standardization requirements with the analytical needs without modifying the original normalized data structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If incident handling data is aggregated with detailed behavioral characteristics, then behavioral analytics capability is improved, but data processing time and computational resources increase

Engineering Contradiction:
Improvebehavioral analytics capabilityVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing behavioral characteristics (work, wait, waste metrics) during the data aggregation process rather than calculating them in real-time during analysis. The system proactively enriches the aggregated data with behavioral metrics and stores them in an optimized format, so that when behavioral analytics are needed, the computations have already been performed and stored for rapid retrieval.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameters of the data structure by transforming raw incident handling data into behavioral parameters (work time, wait time, waste time) with specific units and formats optimized for analysis. This parameter transformation allows the system to maintain detailed behavioral characteristics while reducing processing time by using pre-defined calculation rules and optimized data representations.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If de-normalized target data source is created with new normalized fields, then behavioral pattern recognition is improved, but data transformation complexity increases

Engineering Contradiction:
Improvebehavioral pattern recognitionVSAvoiddata transformation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the data transformation process into distinct stages: extracting incident handling data, creating normalized behavioral fields, aggregating data, and enriching with behavioral characteristics. Each stage handles a specific aspect of the transformation, reducing the overall complexity by breaking down the monolithic transformation process into manageable, reusable components with clear interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal data transformation framework that can handle multiple types of incident handling data through a common set of normalized behavioral fields. The same transformation logic and field structures are applied across different data sources and incident types, making the transformation process reusable and reducing complexity through standardization rather than custom handling for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11657063B2Behavioral analytics in information technology infrasturcture incident management systems
Publication Date: 2023.05.23 BMC HELIX INC
  • US11657063B2 patent drawing
  • US11657063B2 patent drawing
  • US11657063B2 patent drawing

AI summary

A computer system for behavioral analytics of native Information Technology Service Management (ITSM) incident handling data includes a processor, a memory, a de-normalized target data source for behavioral analysis, a transformation processor, and a statistical processor. The transformation processor reads an identified portion of the ITSM data and creates new normalized fields for the de-normalized target data source by parsing selected text fields from the portion of ITSM data. The created new normalized fields include a working group field and an associated support level field. The transformation processor further creates new de-normalized aggregation fields for the incipient de-normalized target data source based on the newly created normalized fields. The newly created de-normalized aggregation fields include fields characterizing incident handling behavior. A statistical processor further processes target data for behavioral analytics. The transformation processor populates the target data source's de-normalized data fields with aggregated incident handling data and behavioral characterizations.