Real-time monitoring alert chaining, root cause analysis, and optimization

US10534658B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10534658-B2
Application numberUS-201715710279-A
CountryUS
Kind codeB2
Filing dateSep 20, 2017
Priority dateSep 20, 2017
Publication dateJan 14, 2020
Grant dateJan 14, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Managing real-time monitoring alerts is provided. An alert is generated for one or more metrics exceeding corresponding defined metric threshold values. A root cause dependency table showing relationships between alerts is retrieved. It is determined whether current real-time metrics are needed from one or more monitoring agents that correspond to dependent alerts not triggered in an alert chain of the generated alert based on information in the root cause dependency table. In response to determining that the current real-time metrics are needed from the one or more monitoring agents that correspond to the dependent alerts not triggered in the alert chain of the generated alert based on the information in the root cause dependency table, the current real-time metrics are requested from the one or more monitoring agents that correspond to the dependent alerts not triggered in the alert chain.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer system for managing real-time monitoring alerts, the computer system comprising: a bus system; a storage device connected to the bus system, wherein the storage device stores program instructions; and a processor connected to the bus system, wherein the processor executes the program instructions to: generate an alert for one or more metrics exceeding corresponding defined metric threshold values; retrieve a root cause dependency table showing relationships between alerts; determine whether current real-time metrics are needed from one or more monitoring agents that correspond to dependent alerts not yet triggered in an alert chain of the generated alert based on information in the root cause dependency table; and request the current real-time metrics from the one or more monitoring agents that correspond to the dependent alerts not yet triggered in the alert chain in response to determining that the current real-time metrics are needed from the one or more monitoring agents that correspond to the dependent alerts not yet triggered in the alert chain of the generated alert based on the information in the root cause dependency table. 2. The computer system of claim 1 , wherein the processor further executes the program instructions to: determine whether the current real-time metrics trigger the dependent alerts in the alert chain; and generate a root cause alert chain corresponding to the generated alert and the dependent alerts in response to determining that the current real-time metrics trigger the dependent alerts in the alert chain. 3. The computer system of claim 2 , wherein the processor further executes the program instructions to: process the generated alert in response to determining that the current real-time metrics do not trigger the dependent alerts in the alert chain; and send the generated alert to a system administrator. 4. The computer system of claim 2 , wherein the generated root cause alert chain identifies current alert dependencies and their corresponding metric collection time sequences. 5. A computer program product for managing real-time monitoring alerts, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to perform a method comprising: generating, by the computer, an alert for one or more metrics exceeding corresponding defined metric threshold values; retrieving, by the computer, a root cause dependency table showing relationships between alerts; determining, by the computer, whether current real-time metrics are needed from one or more monitoring agents that correspond to dependent alerts not yet triggered in an alert chain of the generated alert based on information in the root cause dependency table; and responsive to the computer determining that the current real-time metrics are needed from the one or more monitoring agents that correspond to the dependent alerts not yet triggered in the alert chain of the generated alert based on the information in the root cause dependency table, requesting, by the computer, the current real-time metrics from the one or more monitoring agents that correspond to the dependent alerts not yet triggered in the alert chain. 6. The computer program product of claim 5 further comprising: determining, by the computer, whether the current real-time metrics trigger the dependent alerts in the alert chain; and responsive to the computer determining that the current real-time metrics trigger the dependent alerts in the alert chain, generating, by the computer, a root cause alert chain corresponding to the generated alert and the dependent alerts. 7. The computer program product of claim 5 further comprising: responsive to the computer determining that the current real-time metrics do not trigger the dependent alerts in the alert chain, processing, by the computer, the generated alert; and sending, by the computer, the generated alert to a system administrator. 8. The computer program product of claim 5 , wherein the generated root cause alert chain identifies current alert dependencies and their corresponding metric collection time sequences. 9. The computer program product of claim 8 further comprising: updating, by the computer, the root cause dependency table to include the current alert dependencies based on the generated root cause alert chain. 10. The computer program product of claim 8 further comprising: adjusting, by the computer, a configuration of the one or more monitoring agents and the corresponding defined metric threshold values based on the generated root cause alert chain to optimize metric collection. 11. The computer program product of claim 8 further comprising: sending, by the computer, a root cause alert chain alert that contains the generated root cause alert chain to a system administrator.

Assignees

Inventors

Classifications

  • Real-time · CPC title

  • where the reporting involves data filtering, e.g. pattern matching, time or event triggered, adaptive or policy-based reporting · CPC title

  • Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters · CPC title

  • Threshold · CPC title

  • for performance assessment · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10534658B2 cover?
Managing real-time monitoring alerts is provided. An alert is generated for one or more metrics exceeding corresponding defined metric threshold values. A root cause dependency table showing relationships between alerts is retrieved. It is determined whether current real-time metrics are needed from one or more monitoring agents that correspond to dependent alerts not triggered in an alert chai…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F11/079. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 14 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).