System for decomposing events from managed infrastructures with situation room
First Claim
1. A system for clustering events, comprising:
- at least a first engine configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, the at least first engine configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information, the at least first engine configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure;
a second engine using a source address for each of an event and a graph topology of the managed infrastructure that represents a node to node connectivity and a graph coordinate for each of an event, with an optional subset of attributes extracted for each of an event, the second engine providing a list of connections between components or nodes in the managed infrastructure,a display computer system with a collaborative interface (UI) accessible by at least two parties for situations relative to clustered messages relating to the managed infrastructure wherein the collaborative interface allows the at least two parties to take an action relative to a clustered message; and
converting the events into words and subsets used to group the events into clusters that relate to alerts and events indicative of failures or errors in the managed infrastructure and in response to grouping the events physical changes are made to managed infrastructure physical hardware.
5 Assignments
0 Petitions
Accused Products
Abstract
A system is provided for clustering events. At least one engine is configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information. The at least one engine is configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. The at least one engine is configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. A situation room includes a collaborative interface (UI) for decomposing events from managed infrastructures. In response to production of the clusters one or more physical changes in a managed infrastructure hardware is made, where the hardware supports the flow and processing of information.
44 Citations
30 Claims
-
1. A system for clustering events, comprising:
-
at least a first engine configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, the at least first engine configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information, the at least first engine configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure; a second engine using a source address for each of an event and a graph topology of the managed infrastructure that represents a node to node connectivity and a graph coordinate for each of an event, with an optional subset of attributes extracted for each of an event, the second engine providing a list of connections between components or nodes in the managed infrastructure, a display computer system with a collaborative interface (UI) accessible by at least two parties for situations relative to clustered messages relating to the managed infrastructure wherein the collaborative interface allows the at least two parties to take an action relative to a clustered message; and converting the events into words and subsets used to group the events into clusters that relate to alerts and events indicative of failures or errors in the managed infrastructure and in response to grouping the events physical changes are made to managed infrastructure physical hardware. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30)
-
Specification