Time Varying Static Thresholds for KPI Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern data centers face challenges in processing and indexing large volumes of machine-generated data due to its unstructured nature, making it difficult to apply semantic meaning and effectively monitor service-level performance using key performance indicators (KPIs).
Innovation Solution
A service monitoring system that normalizes heterogeneous machine data by creating entity and service definitions, allowing users to associate entities with services and define KPIs using search queries, which can include thresholds and aggregation periods, to provide a comprehensive view of service performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If machine data is processed and indexed to enable KPI monitoring, then service performance monitoring capability is improved, but processing complexity and time consumption increase due to unstructured data volume
Solution Approach 1:
The system performs preliminary actions by pre-defining KPI templates with associated search queries, thresholds, and aggregation periods before actual monitoring begins. Entity definitions and service definitions are established in advance, creating a structured framework that enables rapid processing of machine data without requiring complex real-time analysis of unstructured data formats.
Solution Approach 2:
The system changes parameters by allowing dynamic adjustment of KPI thresholds and aggregation periods based on time of day, day of week, or other contextual factors. This enables the monitoring system to adapt to varying data patterns and volumes, improving measurement precision while optimizing processing time by using appropriate aggregation levels for different time periods.
2Loss of information
If heterogeneous machine data is normalized through entity and service definitions, then data structure and semantic meaning are improved, but system complexity increases
Solution Approach 1:
The system segments the complex task of data normalization into distinct, manageable components: entity definitions for individual components, service definitions for collections of entities, and KPI definitions for performance metrics. Each segment handles a specific aspect of normalization, making the overall system more manageable while preserving semantic meaning through structured relationships between segments.
Solution Approach 2:
The system implements universal templates and definitions that can be applied across multiple entities and services. A single KPI template can be reused across different services, and entity definitions can be referenced by multiple service definitions, reducing overall system complexity while maintaining comprehensive semantic coverage through multi-functional definitions.
3Speed
If real-time KPI tracking and automatic updates are implemented, then service performance monitoring responsiveness is improved, but processing load and resource consumption increase
Solution Approach 1:
The system implements periodic action through aggregation periods that determine how frequently KPI values are updated and recalculated. Instead of continuous real-time processing, the system updates KPIs at defined intervals (e.g., every 5 minutes, hourly, or daily), reducing processing resource consumption while maintaining acceptable monitoring responsiveness. The aggregation period can be adjusted based on the specific KPI and service criticality.
Data Source
AI summary
One or more processing devices derive values indicative of various aspects of how a particular service in an information technology (IT) environment is performing at a point in time or for a period of time. The values are derived by a search query over machine data associated with the one or more entities that provide the service. The one or more processing devices define and apply time varying static thresholds in respect to the values. A user (e.g., IT manager) may be enabled to manipulate or define multiple sets of KPI thresholds that vary over time.


