Automated Runbook Association for Network Event Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network Operations Centers (NOCs) face challenges in automating the update and maintenance of runbooks, leading to inefficiencies in identifying and executing remedial actions for network events, as existing solutions lack integration with event consoles and require manual intervention.
Innovation Solution
A system and method that automates the association between network events and runbooks, using a policy engine to execute policies for known events and request new policies for unknown events, with a knowledge base that stores and retrieves runbooks, allowing for automated execution and creation of policies without operator intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If manual runbook creation and maintenance is used, then runbooks can be created and updated, but the process is difficult to maintain and requires significant manual effort
Solution Approach 1:
The system automatically discovers events, creates runbooks, and updates the knowledge base without manual intervention. The automated runbook system performs self-service by monitoring events, identifying patterns, generating runbooks, and maintaining the knowledge base autonomously, eliminating the need for manual runbook creation and maintenance while improving both ease of creation and reducing maintenance complexity
Solution Approach 2:
The patent replaces the manual mechanical process of runbook creation and maintenance with an automated computational system. The automated runbook system uses event monitoring, pattern recognition, and automated documentation generation to substitute human operators, thereby improving ease of runbook creation while reducing the complexity of maintenance through systematic automation
2Ease of operation
If collaborative web-based technologies are used to store runbooks, then runbooks can be accessed centrally, but they lack integration with event consoles requiring operator search
Solution Approach 1:
The system merges the runbook storage functionality with the event console into an integrated automated runbook system. This combination allows the system to both store runbooks centrally and automatically associate them with relevant events, eliminating the need for operators to manually search through runbooks while maintaining central accessibility
Solution Approach 2:
The automated runbook system implements feedback loops where events are continuously monitored, analyzed against existing runbooks, and automatically matched with appropriate remediation procedures. This feedback mechanism ensures that the most relevant runbooks are automatically presented to operators or executed autonomously, reducing search time while maintaining ease of access to the runbook repository
3Productivity
If automated policy execution is implemented for known events, then remediation speed increases, but the system requires accurate event classification
Solution Approach 1:
The system performs preliminary actions by pre-classifying events into known and unknown categories and pre-associating runbooks with event types before automated execution is needed. This preliminary classification and runbook association work enables rapid automated remediation execution while maintaining accuracy, as the classification framework is already established and tested before production use
Solution Approach 2:
The automated runbook system uses feedback mechanisms where the results of automated policy execution are continuously monitored and used to refine event classification accuracy. This feedback loop ensures that as the system processes more events, the classification precision improves while maintaining high-speed automated remediation, resolving the contradiction between speed and accuracy
Data Source
AI summary
The present invention is directed towards systems and methods for automating runbook documentation. The method according to one embodiment of the present invention comprises receiving a network event and determining whether the event is a known or unknown event. The method comprises executing a policy associated with the event if the event is known event. The method comprises passing the event to the operator for review against a database of existing runbooks if the event is an unknown event. The method comprises executing an existing policy if the operator identifies a runbook for the runbook event. The method comprises requesting a new policy for the event if the operator does not identify an existing runbook for the event.


