Neural Graph-Based Alert Representations for Related Event Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in managing and analyzing vast amounts of diverse machine data from IT environments, where existing systems struggle to efficiently process and search unstructured data, leading to overwhelming alert volumes and a lack of insight into related events, hindering effective monitoring and analysis.

Innovation Solution

A data intake and query system utilizing a late-binding schema that processes and stores machine data with flexible field extraction rules, enabling real-time analysis and identification of related events through graph-based dense representations, allowing for user feedback to improve customization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If all machine data is stored and processed, then greater flexibility and insight opportunities are provided, but the number of alerts becomes overwhelming and analysis time increases

Engineering Contradiction:
Improvedata analysis flexibilityVSAvoidalert analysis time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system extracts only the most relevant events and alerts from the vast amount of machine data using graph-based representations. By identifying and extracting key events that are directly related to system health and performance, the system provides actionable insights without overwhelming the analyst with all possible alerts.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Graph-based dense representations serve as an intermediary between raw machine data and human analysis. These graphs transform complex multi-dimensional data relationships into visual, interpretable structures that highlight only the most significant patterns and anomalies, acting as a mediator that filters and presents information in a manageable form.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional alerting systems process all data, then comprehensive monitoring is achieved, but related events are not connected and alert relevance decreases

Engineering Contradiction:
Improvesystem monitoring coverageVSAvoidevent relationship context
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system merges multiple data sources and event types into a unified graph-based representation that preserves relationships between events. By combining structured and unstructured data into a cohesive graph model, the system maintains comprehensive monitoring coverage while explicitly representing event relationships that traditional separate processing would lose.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent transitions from traditional flat alert processing to multi-dimensional graph representations that capture relationships across different data dimensions. This dimensional transformation allows the system to maintain comprehensive monitoring while revealing hidden relationships between events that exist in different data layers and timeframes.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If pre-processing extracts specified data items, then retrieval efficiency is improved, but the remainder of generated data is discarded and flexibility is reduced

Engineering Contradiction:
Improvedata retrieval efficiencyVSAvoiddata analysis flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary organization of data into graph-based structures during data ingestion, creating efficient indexes and relationships in advance. This preliminary action enables fast retrieval when needed while preserving all original data, allowing the system to balance retrieval efficiency with analytical flexibility without discarding any generated data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250225183A1Generation Of Graph-Based Dense Representations Of Events Of A Nodal Graph Through Deployment Of A Neural Network
Publication Date: 2025.07.10 CISCO TECHNOLOGY INC
  • US20250225183A1 patent drawing
  • US20250225183A1 patent drawing
  • US20250225183A1 patent drawing

AI summary

A computerized method is disclosed that includes operations of receiving a plurality of alerts, generating a graph-based dense representation of each alert of the plurality of alerts including processing of each alert with a neural network, wherein a result of processing an individual alert by the neural network is a graph-based dense representation of the individual alert, computing relatedness scores between at least a subset of the plurality of alerts, and generating a graphical user interface illustrating a listing of at least a subset of the plurality of alerts, wherein the graphical user interface is configured to receive user input corresponding to selection of a first alert, wherein the graphical user interface is rendered on a display screen. Additionally, an additional operation may include training the neural network to produce graph-based dense representations, wherein the training is performed on a corpus of metapaths.