CORRELATION OF NETWORK ALARM MESSAGES BASED ON ALARM TIME
First Claim
1. A computing device-implemented method, comprising:
- receiving, by the device, a plurality of alarm messages, indicating detection of an error condition in a network, from network devices in the network;
clustering, by the device, the alarm messages based on a time at which the alarm messages were generated, to obtain a cluster of alarm messages;
determining, by the device, a set of circuits in the network in which each circuit in the set of circuits is associated with at least one of the alarm messages in the cluster;
analyzing, by the device, overlap of circuits in the set of circuits to locate potential problems in the network; and
outputting, by the device, an indication of the potential problems.
1 Assignment
0 Petitions
Accused Products
Abstract
Problems in a network may be diagnosed based on alarm messages received from devices in the network and based on logical circuit path information of the network. In one implementation, a device may log alarm messages, in which each of the logged alarm messages may identify a network device that generated the alarm message and each of the alarm messages are associated with a time value. The device may group the alarm messages in the log of alarm messages based on the time values of the alarm messages to obtain one or more alarm message clusters and analyze the alarm message clusters to locate potential causes of the logged alarm messages.
8 Citations
20 Claims
-
1. A computing device-implemented method, comprising:
-
receiving, by the device, a plurality of alarm messages, indicating detection of an error condition in a network, from network devices in the network; clustering, by the device, the alarm messages based on a time at which the alarm messages were generated, to obtain a cluster of alarm messages; determining, by the device, a set of circuits in the network in which each circuit in the set of circuits is associated with at least one of the alarm messages in the cluster; analyzing, by the device, overlap of circuits in the set of circuits to locate potential problems in the network; and outputting, by the device, an indication of the potential problems. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A device comprising:
-
one or more processors; and one or more memories, coupled to the one or more processors, the one or more memories storing instructions, that when executed by the one or more processors, cause the one or more processors to; log alarm messages, received from network devices in a network, indicating detection of an error condition in the network, each of the alarm messages identifying a network device that generated the alarm message and each of the alarm messages being associated with a time value, group the alarm messages in the log of alarm messages based on the time values of the alarm messages to obtain one or more alarm message clusters, analyze the alarm message clusters to locate potential causes of the logged alarm messages, and output the located potential causes of the logged alarm messages. - View Dependent Claims (10, 11, 12, 13, 14, 15, 16, 17)
-
-
18. A system comprising:
-
an alarm log to store alarm messages that indicate an error condition was detected in a network that is being monitored; a network circuit information store to store information relating to circuits that represent logical paths through the network; an analysis component to; cluster the alarm messages based on a time at which the alarm messages were generated, to obtain a cluster of alarm messages, determine a set of circuits in the network circuit information store in which each circuit in the set of circuits is associated with at least one of the alarm messages in the cluster, and analyze overlap of circuits in the set of circuits to locate potential problems in the network; and an output interface to output an indication of the potential problems to a user. - View Dependent Claims (19, 20)
-
Specification