Monitoring Service for Enterprise Log Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internal services within enterprises are not adequately monitored for performance, usage, and security, leading to inefficiencies and security concerns due to lack of visibility into service interactions and latency issues, which are difficult to identify.
Innovation Solution
A monitoring service that aggregates and analyzes log data from multiple services to detect anomalies, establish service relationship models, and provide alerts or remedial actions, enabling administrators to manage service performance and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If internal services are provided within an enterprise's own network, then security is assumed to be maintained, but monitoring capability deteriorates
Solution Approach 1:
The patent introduces a monitoring service as an intermediary component that sits between service consumers and service providers. This monitoring service collects logs from service consumers, aggregates them, and analyzes them to detect anomalies without interfering with the actual service communication. The monitoring service acts as a mediator that provides visibility into internal service interactions while maintaining the security assumptions of the private network.
2Adaptability or versatility
If internal services are used by many different service consumers for many different purposes, then service versatility improves, but monitoring complexity increases
Solution Approach 1:
The monitoring service is designed as a universal system that can monitor multiple services and service consumers simultaneously. It collects logs from various service consumers, aggregates them through a common processing pipeline, and analyzes them using unified anomaly detection algorithms. This multi-functional approach allows the system to handle diverse service interactions without requiring separate monitoring solutions for each service, thereby reducing overall complexity despite the high versatility of the monitored services.
3Adaptability or versatility
If service providers rapidly change or evolve their internal services, then service adaptability improves, but monitoring accuracy deteriorates
Solution Approach 1:
The monitoring service employs dynamic baseline profiles that automatically adapt to service changes. Instead of using static monitoring rules, the system continuously learns from observed service behavior patterns and updates its baselines accordingly. When services evolve or change their operational characteristics, the monitoring system detects these changes and adjusts its anomaly detection parameters dynamically, maintaining accuracy despite rapid service evolution.
4Reliability
If service consumers experience latency or interrupts, then service reliability deteriorates, but diagnostic capability worsens
Solution Approach 1:
The monitoring service implements comprehensive feedback mechanisms that collect information about service consumer behavior, service provider responses, and interaction patterns. By continuously analyzing feedback logs from both service consumers and providers, the system can trace the root causes of latency and interrupts. The feedback mechanism enables the monitoring system to identify whether issues stem from service consumer problems, service provider failures, or network conditions, thereby improving diagnostic capability even when service reliability deteriorates.
Data Source
AI summary
A monitoring service may receive, from a plurality of service providers, log information pertaining to access calls made by service consumers to services or APIs provided by the service providers. The monitoring service aggregates and analyzes the log information for use in monitoring performance of the services, identifying anomalies, and the like. In some instances, the monitoring service may identify multiple services that are behaviorally interrelated based on at least one performance metric, and may group these services together into service groups for monitoring purposes. A service relationship model may be generated for each of the service groups that predicts how each service will behave relative to the other services in the service group. The monitoring service may monitor performance and use of the services based, at least in part, on the one or more service groups and the service relationship model for each group.


