Semantic Clustering Engine for Event Decomposition in Managed Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing and organizing large volumes of messages and events from managed infrastructures, such as emails and network traffic, face challenges in effective clustering and fault localization, leading to difficulties in retrieving relevant information and reducing spam, due to the lack of automated and efficient semantic clustering techniques.
Innovation Solution
A system employing a data-driven approach with a clustering engine that uses semantic clustering to analyze text descriptions of events in a sliding window of data, identifying common characteristics and producing clusters related to failures or errors in managed infrastructures, and operates in a streaming manner to provide real-time fault localization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual organization of messages and events into folders is used, then information can be sorted by topic, but the process becomes impractical when handling massive amounts of web-based information generated daily
Solution Approach 1:
The system enables automated self-service organization of events by extracting attributes from event data and automatically clustering them into groups without human intervention. The clustering engine processes events autonomously, identifying patterns and creating organized structures based on semantic similarity, thereby eliminating the need for manual folder sorting while handling massive volumes of information.
2Productivity
If automated clustering techniques are implemented, then information organization becomes efficient at scale, but the system complexity increases
Solution Approach 1:
The system segments the complex clustering task into distinct modular components: an extraction engine that identifies attributes from raw event data, a clustering engine that groups events based on semantic similarity, and a situation model that organizes clusters into meaningful structures. This segmentation reduces overall system complexity by creating independent, specialized modules that can be developed and maintained separately.
Solution Approach 2:
The patent introduces intermediate data structures and processing layers between raw event input and final organized output. The extraction engine creates structured attribute representations as intermediaries, and the situation model serves as an intermediary layer that synthesizes clustering results into coherent organizational structures, thereby managing complexity through staged processing.
3Ease of operation
If traditional folder-based organization is used, then messages can be stored in designated locations, but tasks become invisible and easily neglected
Solution Approach 1:
The system creates multi-functional event groups that simultaneously serve as storage containers and active task management structures. Each clustered group of events can be viewed as a situational context that combines information archiving with task tracking capabilities, allowing users to monitor and manage tasks within the same organizational structure used for information storage, thereby preventing tasks from becoming invisible.
4Measurement precision
If semantic clustering is applied to decompose events, then fault localization accuracy improves, but the computational processing requirements increase
Solution Approach 1:
The system applies partial semantic clustering by focusing extraction and clustering operations on specific attributes most relevant to fault localization rather than processing all event attributes uniformly. The extraction engine selectively identifies key attributes, and the clustering engine applies semantic analysis only to those critical attributes, achieving adequate fault localization accuracy while reducing unnecessary computational overhead.
Data Source
AI summary
A system is provided for decomposing events from managed infrastructures. A first engine is configured to receive message data from a managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, the at least one engine is configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in a physical hardware of the managed infrastructure directed to supporting the flow and processing of information. The first engine is configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. A second engine is configured to determine one or more common steps from events and produces clusters relating to events. The second engine determines one or more common characteristics of events and produces clusters of events relating to the failure or errors in the managed infrastructure. The system is configured to use data-driven fault localization, more particularly using semantic clustering.


