Temporal Event Correlation via Feature Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing event correlation techniques in IT operations primarily rely on textual similarity and struggle to capture non-textual relationships between events, requiring manual rule definitions that are impractical for comprehensive coverage.
Innovation Solution
A system and method for managing temporal data events by identifying predefined features of interest, correlating events in real-time or scheduled modes using a sliding window and predefined rules, and predicting future events through clustering and pattern mining techniques, eliminating the need for extensive manual rule definitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual rule definitions are used to correlate events based on non-textual affinity, then event correlation accuracy improves, but system complexity and maintenance effort increase significantly
Solution Approach 1:
The system enables self-service by automatically learning event correlation patterns from historical data without requiring manual rule definitions. The machine learning model autonomously identifies relationships between events based on features like event type, source, target, and temporal patterns, eliminating the need for domain experts to manually create and maintain extensive rule sets while maintaining high correlation accuracy
Solution Approach 2:
The patent replaces the mechanical system of manual rule creation and maintenance with an automated machine learning-based system. Instead of manually defining correlation rules, the system uses algorithms to learn patterns from historical event data, substituting human cognitive effort with computational processes that automatically adapt to new event types and relationships
2Adaptability or versatility
If extensive manual rules are defined to cover all possible event groups, then event correlation coverage improves, but implementation and maintenance become infeasible
Solution Approach 1:
The system implements dynamics by making event correlation rules adaptive rather than static. The machine learning model continuously learns from new event data, automatically updating correlation patterns to cover emerging event types and relationships. This dynamic approach allows the system to achieve comprehensive event group coverage without requiring manual updates to rule sets, as the model adapts autonomously to new scenarios
Solution Approach 2:
The patent achieves universality by creating a single automated machine learning system that can handle diverse event types across multiple IT infrastructure domains. Rather than requiring separate rule sets for different event categories, the unified model learns general correlation patterns that apply across various event types, sources, and targets, making the system feasible to implement and maintain while achieving broad coverage
3Ease of operation
If textual similarity is used for event grouping, then implementation simplicity is maintained, but correlation accuracy for non-textually similar events deteriorates
Solution Approach 1:
The system transitions from one-dimensional textual similarity comparison to multi-dimensional event analysis by incorporating additional feature dimensions such as event type, source, target, temporal patterns, and causal relationships. The machine learning model processes these multiple dimensions simultaneously to identify correlations that extend beyond textual similarity, maintaining implementation simplicity through automated feature extraction while significantly improving correlation accuracy for non-textually similar events
Data Source
AI summary
The present invention provides a system and method of managing events of temporal data. The method may include receiving, by a receiving module 510, at least one current event related to the temporal data. The method may include identifying, by an identification module 512, at least one predefined feature of interest of the at least one current event. The method may include correlating, by a correlation module 514, the at least one current event with one or more clusters of events based on the at least one predefined feature of interest, in one of a real-time manner and a scheduled manner. Subsequently, the method may include predicting at least one future event in one of a real-time manner and a scheduled manner.


