Local Event Analyzer for Alert Noise Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed processing systems, the overwhelming number of error and status reports makes it difficult for systems administrators to identify meaningful alerts from the sheer volume of data, leading to irrelevant information.

Innovation Solution

Implementing a local event analyzer embedded within an alert analyzer that receives events from an event queue, creates temporary alerts based on specific rules, and analyzes these alerts using alert analysis rules to filter out unnecessary information, thereby providing a more concise set of relevant alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all error and status reports are collected and transmitted to systems administrators, then complete system monitoring is achieved, but the volume of information becomes overwhelming and unmanageable

Engineering Contradiction:
Improvesystem monitoring completenessVSAvoidvolume of alert information
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and removes irrelevant or low-priority alert information from the complete set of system reports. The alert analyzer selectively filters out unnecessary alerts while retaining critical information, thereby reducing the volume of information presented to systems administrators while maintaining complete system monitoring capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The alert analyzer acts as an intermediary component between the distributed processing system components and systems administrators. It receives all error and status reports, processes them through analysis rules, and presents a filtered subset to administrators, thereby mediating between complete monitoring and manageable information volume.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If a filtered set of alerts is provided to systems administrators, then information relevance is improved, but processing complexity increases

Engineering Contradiction:
Improveinformation relevanceVSAvoidalert processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The alert processing function is segmented into modular components: event queue for receiving alerts, local event analyzers embedded in alert analyzers for initial processing, and rule-based filtering mechanisms. This segmentation allows complex processing to be broken down into manageable stages, reducing overall processing complexity while maintaining information relevance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The alert analyzer system performs self-service by automatically analyzing and filtering alerts based on pre-defined analysis rules without requiring manual intervention. The embedded local event analyzers autonomously process events and generate alerts according to specific rules, reducing the complexity burden on systems administrators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10171289B2Event and alert analysis in a distributed processing system
Publication Date: 2019.01.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10171289B2 patent drawing
  • US10171289B2 patent drawing
  • US10171289B2 patent drawing

AI summary

Methods, apparatuses, and computer program products for event and alert analysis are provided. Embodiments include a local event analyzer embedded in an alert analyzer receiving events from an event queue. Embodiments also include the local event analyzer creating, based on the received events and local event analysis rules specific to the alert analyzer, a temporary alert for the alert analyzer. Embodiments also include the alert analyzer analyzing the temporary alert based on alert analysis rules.