Root cause and impact determination based on automated service identification
An implementation may involve: obtaining a representation of a network event relating to a network, wherein the network enables operation of a plurality of services each involving one or more computing devices or software applications; obtaining information associated with the network event, wherein the information identifies one of the computing devices or the software applications; based on the information, identifying a subset of services of the plurality of services based on determining that each of the subset of services satisfies an impact criterion with respect to the network event, wherein the subset of services are associated with candidate service maps that were generated by a machine learning process; and providing an indication that the subset of services are related to the network event.
1 . A method comprising:
obtaining a representation of a network event relating to a network, wherein the network enables operation of a plurality of services each involving one or more computing devices or software applications;
obtaining information associated with the network event, wherein the information identifies one of the one or more computing devices or the software applications;
based on the information, identifying a first subset of services of the plurality of services that satisfies an impact criterion with respect to the network event, wherein the first subset of services is associated with approved service maps, wherein the approved service maps contain representations of one or more additional computing devices or additional software applications;
based on the one or more additional computing devices or the additional software applications, identifying a second subset of services of the plurality of services that satisfies the impact criterion with respect to the network event, wherein the second subset of services is associated with candidate service maps that were automatically generated by a predictive intelligence process that includes network connections from the network that exceed a threshold extent of network traffic, wherein the candidate service maps have not been approved for production use;
causing an incident database to create an incident record based on one or more of the second subset of services, wherein the incident record is configured to initiate a workflow associated with the network event;
using the candidate service maps, performing functional testing, wherein the functional testing involves simulating one or more scenarios; and
based on the simulation of the one or more scenarios, approving a candidate service map of the candidate service maps for production use.
2 . The method of claim 1 , wherein the representation of the network event was generated by an event management application that receives monitoring data relating to status of the one or more computing devices or the software applications.
3 . The method of claim 1 , wherein the network event is represented as a set of fields that specify one or more of a source of the network event, a network address or network name of a computing device related to the network event, a unique identifier of the computing device related to the network event as appearing in a configuration management database, a severity of the network event, a time of occurrence of the network event, or a reason for generation of the network event.
4 . The method of claim 1 , wherein the information associated with the network event comprises a network address of a computing device related to the network event, a network name of the computing device related to the network event, or a unique identifier of the computing device related to the network event as appearing in a configuration management database.
5 . The method of claim 1 , wherein the candidate service maps are disjoint from the approved service maps.
6 . The method of claim 1 , wherein the approved service maps have been approved for production use.
7 . The method of claim 1 , wherein the impact criterion with respect to the network event is that the first subset of services includes the one of the one or more computing devices or the software applications.
8 . The method of claim 1 , further comprising:
providing an indication that the second subset of services is related to the network event, wherein providing the indication that the second subset of services is related to the network event comprises updating an event management database to specify that the network event is related to each service in the second subset of services.
9 . The method of claim 1 , further comprising:
providing an indication that the second subset of services is related to the network event, wherein providing the indication that the second subset of services is related to the network event comprises transmitting, to a client device, a notification specifying that at least one service in the second subset of services is potentially impacted by the network event.
10 . The method of claim 1 , wherein the impact criterion with respect to the network event comprises that the network event potentially impacts each service in the second subset of services.
11 . The method of claim 1 , wherein the predictive intelligence process comprises:
ranking the network connections according to their respective extents of the network traffic; and
including, in the candidate service maps, the network connections exceeding the threshold extent of the network traffic.
12 . The method of claim 1 , further comprising:
initiating, based on the incident record, the workflow for resolving the network event.
13 . The method of claim 1 , wherein the impact criterion with respect to the network event is that the second subset of services includes the one of the one or more computing devices or the software applications.
14 . A non-transitory computer-readable medium, having stored thereon program instructions that, upon execution by a computing system, cause the computing system to perform operations comprising:
obtaining a representation of a network event relating to a network, wherein the network enables operation of a plurality of services each involving one or more computing devices or software applications;
obtaining information associated with the network event, wherein the information identifies one of the one or more computing devices or the software applications;
based on the information, identifying a first subset of services of the plurality of services that satisfies an impact criterion with respect to the network event, wherein the first subset of services is associated with approved service maps, wherein the approved service maps contain representations of one or more additional computing devices or additional software applications;
based on the one or more additional computing devices or the additional software applications, identifying a second subset of services of the plurality of services that satisfies the impact criterion with respect to the network event, wherein the second subset of services is associated with candidate service maps that were automatically generated by a predictive intelligence process that includes network connections from the network that exceed a threshold extent of network traffic, wherein the candidate service maps have not been approved for production use;
causing an incident database to create an incident record based on one or more of the second subset of services, wherein the incident record is configured to initiate a workflow associated with the network event;
using the candidate service maps, performing functional testing, wherein the functional testing involves simulating one or more scenarios; and
based on the simulation of the one or more scenarios, approving a candidate service map of the candidate service maps for production use.
15 . The non-transitory computer-readable medium of claim 14 , wherein the information associated with the network event comprises a network address of a computing device related to the network event, a network name of the computing device related to the network event, or a unique identifier of the computing device related to the network event as appearing in a configuration management database.
16 . The non-transitory computer-readable medium of claim 14 , wherein the impact criterion with respect to the network event is that the first subset of services includes the one of the one or more computing devices or the software applications.
17 . The non-transitory computer-readable medium of claim 14 , wherein the impact criterion with respect to the network event is that the second subset of services includes the one of the one or more computing devices or the software applications.
18 . The non-transitory computer-readable medium of claim 14 , wherein the program instructions cause the computing system to perform operations further comprising:
providing an indication that the second subset of services is related to the network event, wherein providing the indication that the second subset of services is related to the network event comprises updating an event management database to specify that the network event is related to each service in the second subset of services.
19 . A system comprising:
one or more processors; and
a memory, containing program instructions that, upon execution by the one or more processors, cause the system to perform operations comprising:
obtaining a representation of a network event relating to a network, wherein the network enables operation of a plurality of services each involving one or more computing devices or software applications;
obtaining information associated with the network event, wherein the information identifies one of the one or more computing devices or the software applications;
based on the information, identifying a first subset of services of the plurality of services that satisfies an impact criterion with respect to the network event, wherein the first subset of services is associated with approved service maps, wherein the approved service maps contain representations of one or more additional computing devices or additional software applications;
based on the one or more additional computing devices or the additional software applications, identifying a second subset of services of the plurality of services that satisfies the impact criterion with respect to the network event, wherein the second subset of services is associated with candidate service maps that were generated by a predictive intelligence process that includes network connections from the network that exceed a threshold extent of network traffic, wherein the candidate service maps have not been approved for production use;
causing an incident database to create an incident record based on one or more of the second subset of services, wherein the incident record is configured to initiate a workflow associated with the network event;
using the candidate service maps, performing functional testing, wherein the functional testing involves simulating one or more scenarios; and
based on the simulation of the one or more scenarios, approving a candidate service map of the candidate service maps for production use.