Threshold Crossing Events for Network Telemetry Streaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex network applications generate vast amounts of data that overwhelm simple monitoring systems, making it difficult to handle and analyze effectively, particularly in high-capacity environments like those involving hundreds or thousands of web servers and databases.
Innovation Solution
A method is introduced where network devices detect threshold-crossing events based on pre-determined criteria in network traffic measurement values, generating time series data streams that are sent to a network management system for analysis, allowing for intelligent data collection and monitoring of network behavior, resource consumption, and service level agreement compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If continuous monitoring of all network traffic data is implemented, then complete network visibility is achieved, but system complexity and data processing burden increase exponentially
Solution Approach 1:
The patent extracts only the most relevant data points by implementing threshold-based filtering at the network device level. Instead of transmitting all raw telemetry data, the system selectively extracts and transmits only those data points that exceed predefined thresholds, thereby reducing data volume while maintaining monitoring effectiveness
Solution Approach 2:
The monitoring system is segmented into multiple independent components: local threshold evaluation at network devices, selective data extraction, and centralized analysis at the management system. This segmentation allows each component to operate independently with optimized complexity for its specific function
2Loss of information
If all telemetry data from hundreds/thousands of network devices is collected and transmitted, then comprehensive network insight is achieved, but data transmission overhead and processing load become unmanageable
Solution Approach 1:
The system implements partial monitoring by focusing only on data points that exceed thresholds rather than continuously monitoring all parameters. This partial action approach transmits only the necessary subset of data (excessive only when needed) rather than all possible data continuously
Solution Approach 2:
Instead of continuous data transmission, the system uses event-driven periodic action where data is transmitted only when threshold conditions are met. This transforms continuous monitoring into discrete, condition-based transmission events, significantly reducing overall data volume
3Ease of operation
If simple monitoring techniques are used, then system ease of operation is maintained, but the system becomes overwhelmed by huge data volumes from high-capacity networks
Solution Approach 1:
Threshold definitions and monitoring criteria are configured in advance before deployment. The system performs preliminary filtering and data reduction at the source devices, so that by the time data reaches the management system, it has already been pre-processed to manageable volumes
Solution Approach 2:
The patent introduces threshold-based filtering as an intermediary mechanism between data generation at network devices and data analysis at the management system. This intermediary layer selectively passes only relevant data forward, protecting the management system from being overwhelmed while maintaining operational simplicity
Data Source
AI summary
A network device includes a plurality of ports; a switch configured to switch data frames between the plurality of ports; and a processor configured to obtain one or more measurement values based on network traffic associated with the data frames, responsive to detection of a threshold-crossing event of a measurement value, wherein the threshold-crossing event is one of an indication and a precursor of one or more of an abnormal and unexpected event associated with the network traffic, cause collection of a plurality of time series of measurement values of the network traffic by one or more components in the network device, and send a combination of the plurality of time series as a telemetric data stream for analysis by a network management system related to the abnormal/unexpected event.


