Synthetic Alert Feeds for Complete Data Center Violation Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large-scale networked systems, such as data centers, face challenges in ingesting and managing vast amounts of data, with current monitoring technologies failing to accurately identify non-alert triggering violations, leading to alert fatigue and inaccurate analytics due to the exclusion of these violations.
Innovation Solution
A monitoring tool that generates two separate data feeds: one for alert triggering violations and another including synthetic alerts for non-alert triggering violations, providing a comprehensive view of a data center's performance by leveraging additional 'noise' to identify patterns and anomalies, thereby aiding in issue detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If current monitoring technologies filter out non-alert triggering violations to reduce noise, then alert fatigue is reduced, but measurement precision deteriorates because important patterns and anomalies are missed
Solution Approach 1:
The patent segments the data feed into two distinct streams: one containing only alert-triggering violations for operational alerting purposes, and another containing all violations including non-alert triggering ones for analytical purposes. This segmentation allows the system to maintain low noise levels in alerts while preserving complete data for pattern recognition and anomaly detection, thereby resolving the contradiction between reducing alert fatigue and maintaining measurement precision.
Solution Approach 2:
The patent introduces an intermediary synthetic alert feed that acts as a bridge between raw violation data and final alerts. This intermediary layer processes all violations including non-alert triggering ones, generates synthetic alerts for analytical purposes, and enables pattern recognition without causing alert fatigue in the operational alerting system. The intermediary preserves measurement precision while maintaining ease of operation.
2Measurement precision
If all violations are included in the alert feed, then measurement precision is improved by capturing complete data, but alert fatigue worsens due to excessive noise
Solution Approach 1:
The patent divides the violation data into two segments: alert-triggering violations that generate operational alerts, and non-alert triggering violations that are processed separately for analytical purposes. This segmentation ensures complete data capture for measurement precision while preventing alert fatigue by excluding non-critical violations from the operational alert feed.
Solution Approach 2:
The patent creates a copy of the complete violation data feed for analytical processing, generating synthetic alerts that mirror the structure and content of real alerts. This copying approach allows comprehensive data analysis including all violations without causing alert fatigue in the operational system, as the synthetic alerts are used solely for pattern recognition and analytics rather than operational alerting.
3Measurement precision
If synthetic alerts are generated for non-alert triggering violations, then measurement precision is improved by identifying patterns, but device complexity increases due to additional processing
Solution Approach 1:
The patent generates synthetic alerts as simplified copies of real alert structures for non-alert triggering violations. These synthetic alerts replicate the essential format and content of operational alerts but are derived from less critical violations. This copying approach enables comprehensive pattern recognition and anomaly detection across all violation types while managing device complexity by using a standardized alert format that requires minimal additional processing infrastructure.
Data Source
AI summary
Systems and methods provide for automatically generating a data model that includes a first data feed conforming to industry standards where only alerts for alert triggering violations are provided. The data model further comprises a second data feed that includes both the alerts from the first data feed and a plurality of synthetic alerts for any violations that occur in a data center but do not qualify as alert triggering violations. This second data feed provides a complete picture of the performance of a data center's devices and allows for accurate analytics.


