Storm detection, analysis, remediation, and other network behavior
First Claim
Patent Images
1. Apparatus includinga network monitoring device coupleable to a communications network, said communication network providing network status information;
- said network monitoring device coupleable to one or more management rules defining a behavior of said communication network, and including one or more instructions directing said network monitoring device to learn from behavior of said communication network;
said network monitoring device coupled to at least one of;
a remedial element coupled to said communication network, said remedial element accepting instructions from said network monitoring device;
an alert element coupled to one or more users of said communication network, said users being selected from;
users of resources coupleable to said communication network or managers or operators of said communication network,whereinsaid network monitoring device coupleable to a communication network is coupleable to at least one first type of device sending network data on their own behest, and at least one second type of device sending network status data upon the request of said network monitoring device;
said network monitoring device including a buffer of network status data, being divided into a plurality of clock ticks, each clock tick representing status data from a discernable past time;
when said network monitoring device maintains status data from said network at least temporarily in said buffer, at a location associated with said discernable past time; and
when said discernable past time exceeds a selected threshold, said network monitoring device reduces an effect of said status data from a particular discernable past time associated with said selected threshold.
9 Assignments
0 Petitions
Accused Products
Abstract
A monitoring device responds to status data to detect storms, analysis, and to attempt to remediate those storms. The monitoring device several types of storms, for each of which it has a technique for analysis of the storm. The monitoring device can determine if the storm is due to resource contention, excess or unbalanced performance activity, or network degradation. Once analyzed, the monitoring device analyzes the storm, and attempts to remediate the cause of the storm.
16 Citations
20 Claims
-
1. Apparatus including
a network monitoring device coupleable to a communications network, said communication network providing network status information; -
said network monitoring device coupleable to one or more management rules defining a behavior of said communication network, and including one or more instructions directing said network monitoring device to learn from behavior of said communication network; said network monitoring device coupled to at least one of; a remedial element coupled to said communication network, said remedial element accepting instructions from said network monitoring device; an alert element coupled to one or more users of said communication network, said users being selected from;
users of resources coupleable to said communication network or managers or operators of said communication network,wherein said network monitoring device coupleable to a communication network is coupleable to at least one first type of device sending network data on their own behest, and at least one second type of device sending network status data upon the request of said network monitoring device; said network monitoring device including a buffer of network status data, being divided into a plurality of clock ticks, each clock tick representing status data from a discernable past time; when said network monitoring device maintains status data from said network at least temporarily in said buffer, at a location associated with said discernable past time; and when said discernable past time exceeds a selected threshold, said network monitoring device reduces an effect of said status data from a particular discernable past time associated with said selected threshold.
-
-
2. Apparatus including
a network monitoring device, the network monitoring device responsive to network status data from one or more reporting devices coupled to a distributed network monitoring environment, the distributed network monitoring environment having a plurality of endpoints coupled thereto, the endpoints disposed to access resources available using the distributed network monitoring environment; -
the network monitoring device including an alert storm detection element, an alert storm including an unusually large number of alerts all relating to the same resource at an endpoint, wherein the resource includes one or more of;
processor time, memory utilization, storage utilization, network bandwidth utilization, application delivery utilization;the network monitoring device including an alert storm analysis element; the network monitoring device including an alert storm amelioration element. - View Dependent Claims (3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification