Multi-Model Incident Correlation for IT Configurable Items
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT management systems face challenges in efficiently determining the root cause of incidents in complex IT architectures, often requiring significant time and resources to identify related configurable items.
Innovation Solution
A computer-implemented method and system that utilize multiple models to determine a list of configurable items related to an incident by analyzing metadata, historical incident data, and logical associations, and then aggregate and filter these items to provide a comprehensive list.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If multiple models are used to determine configurable items from different dimensions (applications/services, products, lines of business), then the completeness and accuracy of incident correlation is improved, but the system complexity and computational resources required increase
Solution Approach 1:
The system segments the incident correlation task into three distinct models operating at different logical levels: application/service level model, product level model, and line of business level model. Each model focuses on a specific dimension of the IT landscape, processing data independently and contributing specialized insights to the overall incident correlation, thereby improving accuracy without requiring a single monolithic complex system
Solution Approach 2:
The patent introduces an intermediary aggregation layer that collects outputs from the three specialized models, removes duplicates, and consolidates results into a unified list of configurable items. This intermediary structure allows each model to remain relatively simple while achieving comprehensive correlation through their coordinated outputs
2Measurement precision
If comprehensive incident analysis across all configurable items is performed, then the root cause identification accuracy is improved, but the time required to resolve incidents increases
Solution Approach 1:
The system performs preliminary actions by pre-establishing the three analytical models and their respective data structures before incidents occur. Historical data is organized and tagged across application/service, product, and line of business dimensions in advance, enabling rapid querying and correlation during actual incident response without requiring time-consuming analysis from scratch
Solution Approach 2:
The patent applies partial action by focusing analysis on the three most critical dimensions (application/service, product, line of business) rather than attempting to analyze every possible attribute of every configurable item. This selective approach achieves sufficient correlation accuracy while significantly reducing the time and computational resources required compared to exhaustive analysis
3Adaptability or versatility
If decentralized personnel and systems are used to resolve incidents across large IT organizations, then the adaptability to different incident types is improved, but the efficiency and coordination between teams deteriorate
Solution Approach 1:
The patent creates a universal incident correlation framework that serves multiple functions simultaneously: it correlates incidents across different technical layers (application, product, business), identifies root causes, and provides a standardized output format. This multi-functional system can be uniformly applied across all decentralized teams and incident types, enabling consistent efficient resolution while maintaining the ability to handle diverse incident scenarios
4Adaptability or versatility
If manual research of related configurable items is performed during incidents, then the flexibility in investigating unusual cases is improved, but the time and resources consumed increase significantly
Solution Approach 1:
The system provides self-service by automatically performing the research and correlation work that previously required manual investigation. The three models autonomously analyze incident data, query relevant configurable items across different dimensions, and generate the correlation list without human intervention, eliminating the time-consuming manual research phase while maintaining investigative capability through the structured multi-dimensional analysis
Data Source
AI summary
A method for determining configurable items related to an incident is disclosed. The method includes receiving a data object indicating an occurrence of a current incident, the data object including metadata; determining, utilizing a first model and based on the metadata, one or more first configurable items associated with one or more applications and/or services related to the current incident; determining, utilizing a second model and based on the metadata, one or more second configurable items associated with one or more products related to the current incident; determining, utilizing a third model and based on the metadata, one or more third configurable items associated with one or more lines of business and/or logical associations related to the current incident; generating a list of configurable items by aggregating the one or more first configurable items, the one or more second configurable items, and the one or more third configurable items.


