Observability platform service for operational environment

US12537734B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12537734-B2
Application numberUS-202318537968-A
CountryUS
Kind codeB2
Filing dateDec 13, 2023
Priority dateDec 13, 2023
Publication dateJan 27, 2026
Grant dateJan 27, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provided are systems and methods that facilitates cross-correlation among alerts within different systems in a complex operating environment. In one example, a method may include receiving a plurality of alert messages generated by a plurality of systems within a distributed and shared operating environment and storing the plurality of alert messages, identifying a subset of alert messages among the plurality of alert messages that are correlated based on relationships identified from the subset of alert messages, generating a description of a root cause of the subset of alert messages based on execution of an artificial intelligence (AI) model on the identified subset of alert messages, and displaying the description of the root cause via a user interface.

First claim

Opening claim text (preview).

What is claimed is: 1 . A computing system comprising: a storage; and a processor configured to: receive a plurality of alert messages generated by a plurality of systems within a distributed and shared operating environment and store the plurality of alert messages in the storage, each individual alert message of the plurality of alert messages including an identifier of a location where a performance issue for at least one of the plurality of systems has been detected and an identity of a server where the performance issue was detected; identify a subset of alert messages in the storage that are correlated based at least in part on attributes within the alert messages, the attributes indicating one or more of: geographic locations, virtual machine locations, routers, switches, load balancers, or server locations identified from the subset of the alert messages; execute a large language model (LLM) on the subset of alert messages; generate a request for information based on the execution of the LLM on the subset of the alert messages, display the request for information via the user interface, receive a response to the request for information via the user interface, and determine a description of the root cause based on execution of the LLM on the request for information and the response to the request for information; and display the description of the root cause via a user interface. 2 . The computing system of claim 1 , wherein the processor is configured to receive the plurality of the alert messages from a plurality of heterogeneous systems, respectively, within an operating environment of a wide area network (WAN). 3 . The computing system of claim 1 , wherein the processor is further configured to enrich the plurality of alert messages with additional context of the distributed and shared operating environment based on one or more data feeds, prior to the execution of the LLM. 4 . The computing system of claim 1 , wherein the processor is further configured to determine an area of impact within the distributed and shared operating environment based on execution of the LLM on the subset of the alert messages, and display a map of the distributed and shared operating environment including the area of impact via the user interface. 5 . The computing system of claim 1 , wherein the processor is further configured to generate a description of a strategy for triaging the root cause based on execution of the LLM on the subset of the alert messages, and display the description of the strategy via the user interface. 6 . A method comprising: receiving a plurality of alert messages generated by a plurality of systems within a distributed and shared operating environment and storing the plurality of alert messages, each individual alert message of the plurality of alert messages including an identifier of a location where a performance issue for at least one of the plurality of systems has been detected and an identity of a server where the performance issue was detected; identifying a subset of alert messages among the plurality of alert messages that are correlated at least in part on attributes within the alert messages, the attributes indicating one or more of: geographic locations, virtual machine locations, routers, switches, load balancers, or server locations identified from the subset of the alert messages; executing a large language model (LLM) on the subset of alert messages; generating a request for information based on the execution of the LLM on the subset of the alert messages, display the request for information via the user interface, receive a response to the request for information via the user interface, and determining a description of the root cause based on execution of the LLM on the request for information and the response to the request for information; and displaying the description of the root cause via a user interface. 7 . The method of claim 6 , wherein the receiving comprises receiving the plurality of alert messages from a plurality of heterogeneous systems, respectively, within an operating environment of a wide area network (WAN). 8 . The method of claim 6 , wherein the method further comprises enriching the plurality of alert messages with additional context of the distributed and shared operating environment based on one or more data feeds, prior to the execution of the LLM. 9 . The method of claim 6 , wherein the method further comprises determining an area of impact within the distributed and shared operating environment based on execution of the LLM on the subset of the alert messages, and displaying a map of the distributed and shared operating environment including the area of impact via the user interface. 10 . The method of claim 6 , wherein the method further comprises generating a description of a strategy for triaging the root cause based on execution of the LLM on the subset of the alert messages, and displaying the description of the strategy via the user interface. 11 . A non-transitory computer-readable storage medium comprising instructions which when executed by a processor cause a computer to perform: receiving a plurality of alert messages generated by a plurality of systems within a distributed and shared operating environment and storing the plurality of alert messages, each individual alert message of the plurality of alert messages including an identifier of a location where a performance issue for at least one of the plurality of systems has been detected and an identity of a server where the performance issue was detected; identifying a subset of alert messages among the plurality of alert messages that are correlated based at least in part on attributes within the alert messages, the attributes indicating one or more of: geographic locations, virtual machine locations, routers, switches, load balancers, or server locations identified from the subset of the alert messages; executing a large language model (LLM) on the subset of alert messages; generating a request for information based on the execution of the LLM on the subset of the alert messages, display the request for information via the user interface, receive a response to the request for information via the user interface, and determining a description of the root cause based on execution of the LLM on the request for information and the response to the request for information; and displaying the description of the root cause via a user interface. 12 . The non-transitory computer-readable storage medium of claim 11 , wherein the receiving comprises receiving the plurality of the alert messages from a plurality of heterogeneous systems, respectively, within an operating environment of a wide area network (WAN).

Assignees

Inventors

Classifications

  • comprising specially adapted graphical user interfaces [GUI] · CPC title

  • Additional information in the notification, e.g. enhancement of specific meta-data · CPC title

  • using network fault recovery (ring fault isolation or reconfiguration in loop networks without recovery actions by a network management system H04L12/437) · CPC title

  • using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis · CPC title

  • using machine learning or artificial intelligence · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12537734B2 cover?
Provided are systems and methods that facilitates cross-correlation among alerts within different systems in a complex operating environment. In one example, a method may include receiving a plurality of alert messages generated by a plurality of systems within a distributed and shared operating environment and storing the plurality of alert messages, identifying a subset of alert messages amon…
Who is the assignee on this patent?
Sap Se
What technology area does this patent fall under?
Primary CPC classification H04L41/0654. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 27 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).