Determining alert criteria in a network environment

US9529655B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9529655-B2
Application numberUS-201514867972-A
CountryUS
Kind codeB2
Filing dateSep 28, 2015
Priority dateMay 6, 2014
Publication dateDec 27, 2016
Grant dateDec 27, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Alert conditions datasets are created from historic data taken from actual incidents for which the alert condition datasets are to indicate during future operations. A networked computers system including various devices is monitored for alert conditions associated with one, or more, of the devices. The severity of an alert is based on the number of alert conditions met for a given alert conditions dataset.

First claim

Opening claim text (preview).

The claims are as follows: 1. A method comprising: determining a time range for a first instance of an incident in a computer system; collecting conditions of a plurality of components of the computer system; and deriving a set of alert conditions for the incident from the collected conditions at least by selecting from the collected conditions the set of alert conditions based, at least in part, on a pre-determined variance between a value of a condition in the collected conditions and a corresponding value of a condition in a set of baseline conditions; wherein: existence of the incident inhibits functionality of at least one component of the plurality of components; the collected conditions were present during the time range; and at least the collecting and deriving steps are performed by computer software running on computer hardware. 2. The method of claim 1 , further comprising: monitoring the plurality of components for the existence of an alert condition included in the set of alert conditions; and responsive to identifying existence of the alert condition in the plurality of components, generating an alert of a second instance of the incident. 3. The method of claim 2 , wherein the alert indicates a percentage of alert conditions included in the set of alert conditions that are identified as existing in the plurality of components. 4. The method of claim 1 , wherein the step of deriving the set of alert conditions for the incident from the collected conditions further includes: comparing the collected conditions to the set of baseline conditions. 5. The method of claim 1 further comprising: collecting the set of baseline conditions for at least one system component during operation of the computer system when no existence of an alert condition in the set of alert conditions is identified. 6. The method of claim 1 , wherein the plurality of components of the computer system is a set of two components of a networked computer system, a component of a first device and a component of a second device. 7. The method of claim 1 , wherein the set of alert conditions includes a first alert condition corresponding to a first component of the plurality of components and a second alert condition corresponding to a second component of the plurality of components. 8. A computer program product comprising a computer-readable storage medium having a set of instructions stored therein which, when executed by a processor, causes the processor to perform a method that includes: determining a time range for a first instance of an incident in a computer system; collecting conditions of a plurality of components of the computer system; and deriving a set of alert conditions for the incident from the collected conditions at least by selecting from the collected conditions the set of alert conditions based, at least in part, on a pre-determined variance between a value of a condition in the collected conditions and a corresponding value of a condition in a set of baseline conditions; wherein: existence of the incident inhibits functionality of at least one component of the plurality of components; and the collected conditions were present during the time range. 9. The computer program product of claim 8 , further causing the processor to perform a method that includes: monitoring the plurality of components for the existence of an alert condition included in the set of alert conditions; and responsive to identifying existence of the alert condition in the plurality of components, generating an alert of a second instance of the incident. 10. The computer program product of claim 8 , wherein the step of deriving the set of alert conditions for the incident from the collected conditions further includes: comparing the collected conditions to the set of baseline conditions. 11. The computer program product of claim 8 , wherein the plurality of components of the computer system is a set of two components of a networked computer system, a component of a first device and a component of a second device. 12. The computer program product of claim 8 , wherein the set of alert conditions includes a first alert condition corresponding to a first component of the plurality of components and a second alert condition corresponding to a second component of the plurality of components. 13. The computer program product of claim 8 , further causing the processor to perform a method that includes: collecting the set of baseline conditions for at least one system component during operation of the computer system when no existence of an alert condition in the set of alert conditions is identified. 14. A computer system comprising: a processor set; and a computer readable storage medium; wherein: the processor set is structured, located, connected, and/or programmed to run program instructions stored on the computer readable storage medium; and the program instructions which, when executed by the processor set, cause the processor set to perform a method that includes: determining a time range for a first instance of an incident in a computer system; collecting conditions of a plurality of components of the computer system; and deriving a set of alert conditions for the incident from the collected conditions at least by selecting from the collected conditions the set of alert conditions based, at least in part, on a pre-determined variance between a value of a condition in the collected conditions and a corresponding value of a condition in a set of baseline conditions; wherein: existence of the incident inhibits functionality of at least one component of the plurality of components; and the collected conditions were present during the time range. 15. The computer system of claim 14 , further causing the processor to perform a method that includes: monitoring the plurality of components for the existence of an alert condition included in the set of alert conditions; and responsive to identifying existence of the alert condition in the plurality of components, generating an alert of a second instance of the incident. 16. The computer system of claim 14 , wherein the step of deriving the set of alert conditions for the incident from the collected conditions further includes: comparing the collected conditions to the set of baseline conditions. 17. The computer system of claim 14 , wherein the plurality of components of the computer system is a set of two components of a networked computer system, a component of a first device and a component of a second device. 18. The computer system of claim 14 , wherein the set of alert conditions includes a first alert condition corresponding to a first component of the plurality of components and a second alert condition corresponding to a second component of the plurality of components. 19. The computer system of claim 14 , wherein the alert indicates a percentage of alert conditions included in the set of alert conditions that are identified as existing in the plurality of components. 20. The computer system of claim 14 , further causing the processor to perform a method that includes: collecting the set of baseline conditions for at least one system component during operation of the computer system when no existence of an alert condition in the set of alert conditions is identified.

Assignees

Inventors

Classifications

  • in a distributed system consisting of a plurality of standalone computer nodes, e.g. clusters, client-server systems · CPC title

  • Checking or monitoring of signalling or alarm systems; Prevention or correction of operating errors, e.g. preventing unauthorised operation · CPC title

  • Calibration, including self-calibrating arrangements · CPC title

  • Means for error signaling, e.g. using interrupts, exception flags, dedicated error registers · CPC title

  • Error or fault detection not based on redundancy (power supply failures G06F1/30; network fault management H04L41/06) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9529655B2 cover?
Alert conditions datasets are created from historic data taken from actual incidents for which the alert condition datasets are to indicate during future operations. A networked computers system including various devices is monitored for alert conditions associated with one, or more, of the devices. The severity of an alert is based on the number of alert conditions met for a given alert condit…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F11/0709. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 27 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).