Knowledge Graph Root Cause Analysis for IT Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional monitoring solutions for technology stacks struggle to understand complex interrelationships between components, rely on subjective institutional knowledge, and require significant tuning for each case, failing to provide objective anomaly detection and root cause analysis.
Innovation Solution
A system and method for anomaly detection that generates knowledge graphs from time-series data, determining connections and impact scores between metrics, and uses a root cause determination engine to identify root cause candidates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional monitoring solutions are used, then implementation is straightforward, but they cannot understand complex interrelationships between components and fail to extract meaningful information
Solution Approach 1:
The patent introduces a knowledge graph as an intermediary structure that represents the complex interrelationships between infrastructure components. The knowledge graph serves as a mediator between raw time-series data and anomaly detection algorithms, enabling the system to understand and extract meaningful information about component relationships without requiring the algorithms themselves to be overly complex.
Solution Approach 2:
The system performs preliminary action by pre-building and maintaining knowledge graphs that capture the interrelationships between components before anomaly detection is needed. This preliminary structuring of relationships allows the anomaly detection system to operate more efficiently by querying pre-processed relationship data rather than analyzing raw data in real-time.
2Measurement precision
If manually driven metrics or alerts are used, then implementation is simple, but they require deep institutional knowledge and are subjective
Solution Approach 1:
The system implements self-service by automatically generating knowledge graphs and detecting anomalies without requiring manual configuration or deep institutional knowledge. The automated anomaly detection system queries the knowledge graph and time-series data to objectively identify anomalies, eliminating the need for operators to manually define metrics or interpret complex relationships.
Solution Approach 2:
The patent changes the parameters of anomaly detection from manual, subjective metric definitions to automated, objective queries against structured knowledge graphs. By transforming the detection approach from manual threshold-setting to automated pattern recognition in the knowledge graph, the system achieves more precise and objective anomaly detection.
3Adaptability or versatility
If conventional monitoring solutions are used, then they work for specific cases, but they require significant tuning on a case-by-case basis and are not generally applicable
Solution Approach 1:
The patent achieves universality by creating a knowledge graph framework that can represent different infrastructure components and their relationships in a standardized way. This universal representation allows the same anomaly detection system to be applied across different infrastructure types without requiring case-by-case tuning, as the knowledge graph can adapt to various configurations through automated relationship extraction.
Data Source
AI summary
Systems and computer-implemented methods are disclosed for detecting a system anomaly. A computer-implemented method comprises: receiving, by a data storage module, time-series data from a plurality of sensors of an information technology infrastructure, each sensor corresponding to a respective metric; detecting a plurality of anomalies in the time-series data stored in the data storage module; generating a knowledge graph by: determining connections between the plurality of metrics based on the time-series data; and for each connection, determining a respective weight based on an impact score for metrics joined by the connection; and configuring a root cause determination engine to output one or more metrics as root cause candidates, the one or more metrics based on the knowledge graph, in response to input of a query associated with at least one metric.


