Network fault correlation
First Claim
1. A method of indicating a fault within a network, the method including the computer-implemented steps of:
- detecting the occurrence of an event within the network;
identifying the event as being a first type of event;
determining whether a threshold number of events identified as being the first type of event have occurred within a first predetermined time period;
if the threshold number of events have occurred within the first predetermined time period, then indicating a fault within the network;
detecting the occurrence of a further event within the network after the step of indicating the fault;
identifying the further event as being the first type of event;
determining whether an escalation threshold number of events identified as being the first type of event have occurred within a second predetermined time period and after the step of indicating the fault; and
if the escalation threshold number of events have occurred within the second predetermined time period then indicating an escalation in a severity level of the fault.
4 Assignments
0 Petitions
Accused Products
Abstract
A method and apparatus for correlating faults in a networking system. A database of fault rules is maintained along with and associated probable causes, and possible solutions for determining the occurrence of faults defined by the fault rules. The fault rules include a fault identifier, an occurrence threshold specifying a minimum number of occurrences of fault events in the networking system in order to identify the fault, and a time threshold in which the occurrences of the fault events must occur in order to correlate the fault. Occurrences of fault events in the networking system are detected and correlated by determining matched fault rules which match the fault events and generating a fault report upon determining that a number of occurrences for the matched fault rules within the time threshold is greater than or equal to the occurrence threshold for the matched fault rules.
465 Citations
19 Claims
-
1. A method of indicating a fault within a network, the method including the computer-implemented steps of:
-
detecting the occurrence of an event within the network; identifying the event as being a first type of event; determining whether a threshold number of events identified as being the first type of event have occurred within a first predetermined time period; if the threshold number of events have occurred within the first predetermined time period, then indicating a fault within the network; detecting the occurrence of a further event within the network after the step of indicating the fault; identifying the further event as being the first type of event; determining whether an escalation threshold number of events identified as being the first type of event have occurred within a second predetermined time period and after the step of indicating the fault; and if the escalation threshold number of events have occurred within the second predetermined time period then indicating an escalation in a severity level of the fault. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. Apparatus for indicating a fault within a network, the apparatus comprising:
-
an identification circuit to identify a network event as being a first type of event; a counter to maintain a count of network events identified by the identification circuit as being the first type of event; a comparator to determine when the count of network events within a first predetermined time period equals or transcends a threshold value; and an indicator to indicate a fault within the network when the count of network events within the first predetermined time period equals or transcends the threshold value; wherein the counter maintains a count of further network events which occur after the indicator has indicated a fault, and which are identified by the identification circuit as being the first type of event; wherein the comparator determines when the count of further network events, within a second predetermined time period, equals or transcends an escalation threshold value; and wherein the indicator indicates an escalation fault identifying an increased severity level of the fault when the count of further network events, within the second predetermined time period, equals or transcends the escalation threshold value. - View Dependent Claims (13, 14, 15, 16, 17)
-
-
18. A method of indicating a fault within a network, the method including the computer-implemented steps of:
-
detecting the occurrence of an event within the network; identifying the event as being a first type of event; determining whether a threshold number of events identified as being the first type of event have occurred within a predetermined time period; if the threshold number of events have occurred within the predetermined time period, then indicating a fault within the network; in response to the step of identifying the event as being the first type of event, indicating a first network device as being in a first state; detecting the occurrence of a further event within the network; determining whether the further event is a second type of event; and indicating the first network device as being in a second state, if the further event is of the second type of event.
-
-
19. An apparatus for indicating a fault within a network, the apparatus comprising:
-
an identification circuit to identify a network event as being a first type of event; a counter to maintain a count of network events identified by the identification circuit as being the first type of event; a comparator to determine when the count of network events within a predetermined time period equals or transcends a threshold value; and an indicator to indicate a fault within the network when the count of network events within the predetermined time period equals or transcends the threshold value; wherein the indicator indicates a first network device as being in a first state when the network event is identified as being the first type of event; wherein the identification circuit identifies a further event within the network as being a second type of event; and wherein the indicator indicates the first network device as being in a second state, if the further event is identified as being the second type of event.
-
Specification