Local Event Analyzer for Alert Noise Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed processing systems, the overwhelming number of error and status reports makes it difficult for systems administrators to identify meaningful alerts from the sheer volume of data, leading to irrelevant information.
Innovation Solution
Implementing a local event analyzer embedded within an alert analyzer that receives events from an event queue, creates temporary alerts based on specific rules, and analyzes these alerts using alert analysis rules to filter out unnecessary information, thereby providing a more concise set of relevant alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all error and status reports are collected and transmitted to systems administrators, then complete system monitoring is achieved, but the volume of information becomes overwhelming and unmanageable
Solution Approach 1:
The patent extracts and removes irrelevant or low-priority alert information from the complete set of system reports. The alert analyzer selectively filters out unnecessary alerts while retaining critical information, thereby reducing the volume of information presented to systems administrators while maintaining complete system monitoring capability.
Solution Approach 2:
The alert analyzer acts as an intermediary component between the distributed processing system components and systems administrators. It receives all error and status reports, processes them through analysis rules, and presents a filtered subset to administrators, thereby mediating between complete monitoring and manageable information volume.
2Loss of information
If a filtered set of alerts is provided to systems administrators, then information relevance is improved, but processing complexity increases
Solution Approach 1:
The alert processing function is segmented into modular components: event queue for receiving alerts, local event analyzers embedded in alert analyzers for initial processing, and rule-based filtering mechanisms. This segmentation allows complex processing to be broken down into manageable stages, reducing overall processing complexity while maintaining information relevance.
Solution Approach 2:
The alert analyzer system performs self-service by automatically analyzing and filtering alerts based on pre-defined analysis rules without requiring manual intervention. The embedded local event analyzers autonomously process events and generate alerts according to specific rules, reducing the complexity burden on systems administrators.
Data Source
AI summary
Methods, apparatuses, and computer program products for event and alert analysis are provided. Embodiments include a local event analyzer embedded in an alert analyzer receiving events from an event queue. Embodiments also include the local event analyzer creating, based on the received events and local event analysis rules specific to the alert analyzer, a temporary alert for the alert analyzer. Embodiments also include the alert analyzer analyzing the temporary alert based on alert analysis rules.


