IP Library Granted Patent US 7,131,037
Granted Patent B1
US 7,131,037 · App. 10/164,464 · Granted Oct 31, 2006

Method and system to correlate a specific alarm to one or more events to identify a possible cause of the alarm

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,131,037
App. No.
10/164,464
Granted
Oct 31, 2006
Kind
B1
Abstract

A system is provided to monitor network performances. The system maintains a database of performance abnormalities, alarms and events from a system of monitored elements. The system automatically identifies a possible cause of a specific alarm by correlating the specific alarm with a plurality of events using the database. The system displays the cause of the specific alarm. The database includes alarms and events of network devices, network systems, and network applications. The specific alarm consists of a notification of an occurrence of the plurality of events.

Claims (73)

1. A method of monitoring network performance comprising:

maintaining a database of alarms and events from a system of monitored elements; and

automatically identifying a possible cause of a specific alarm by correlating the specific alarm with a plurality of events using the database, wherein automatically identifying the possible cause comprises:

(1) analysis of performance abnormalities and at least one of an event or alert;

(2) statistical correlation;

(3) elimination of unrelated causes;

(4) user defined groupings; and,

(5) relative weightings of monitored elements.

2. The method defined in claim 1 wherein one of the plurality of events comprises one of a selected group consisting of a performance abnormality, a threshold alert, and a software change.

3. The method defined in claim 1 further comprising performing statistical correlation on the performance abnormalities to generate a list of possible candidate abnormalities.

4. The method defined in claim 3 further comprising:

performing isolation filtering to eliminate a set of abnormalities; and

performing scoring and categorization on a filtered set of abnormalities to pinpoint the probable cause.

5. The method of claim 1 further comprising displaying the cause of the specific alarm.

6. The method of claim 1 , wherein the monitored elements include network devices.

7. The method of claim 1 , wherein the monitored elements include network systems.

8. The method of claim 1 , wherein the monitored elements include network applications.

9. The method of claim 1 , wherein the specific alarm consists of a notification of an occurrence of the plurality of events.

10. The method of claim 1 , wherein the specific alarm is associated with a fault.

11. The method of claim 1 , wherein the specific alarm is not associated with a fault.

12. The method of claim 1 , wherein the automatically identifying the possible cause includes classifying the events based on functional groups.

13. The method of claim 12 , wherein the functional groups are comprised of specific device types within the system of monitored elements.

14. The method of claim 12 , wherein the classifying the events based on functional groups includes using a Graphical User Interface (GUI).

15. The method of claim 12 , wherein the classifying the events based on functional groups includes a meta-data definition of the functional groups.

16. The method of claim 12 , wherein the classifying the events based on functional groups includes creating default functional groups.

17. The method of claim 12 , wherein the classifying the events based on functional groups includes creating additional functional groups.

18. The method of claim 12 , wherein the classifying the events based on functional groups includes creating a probability value to represent an inter-relationship between a functional group and other functional groups.

19. The method of claim 18 , wherein the probability value is between 0 and 1.

20. The method of claim 1 , wherein the automatically identifying the possible cause includes classifying the events based on attribute groups.

21. The method of claim 20 , wherein the attribute groups are comprised of specific performance statistics within the system of the monitored elements.

22. The method of claim 20 , wherein the attribute groups include a Response Time type of attribute group.

23. The method of claim 20 , wherein the attribute groups include an Availability type of attribute group.

24. The method of claim 20 , wherein the attribute groups include a System type of attribute group.

25. The method of claim 20 , wherein the classifying the events based on attribute groups includes a meta-data definition of the attribute groups.

26. The method of claim 20 , wherein the classifying the events based on attribute groups includes creating attribute scores for the events.

27. The method of claim 26 , wherein the attribute scores are between 0 to 5.

28. The method of claim 1 , wherein the automatically identifying the possible cause includes filtering the events mandatorily.

29. The method of claim 1 , wherein the automatically identifying the possible cause includes filtering the events optionally.

30. The method of claim 29 , wherein the filtering the events optionally can be turn on/off selectively.

31. The method of claim 1 , wherein the automatically identifying the possible cause includes sorting the events to separate filter-pass events from filter-fail events.

32. The method of claim 31 , wherein the filter-pass events satisfy filtering rules.

33. The method of claim 31 , wherein the filter-fail events do not satisfy the filtering rules.

34. The method of claim 1 , wherein the automatically identifying the possible cause includes computing event scores for the plurality of events.

35. The method of claim 1 , wherein the event scores are values between 0 to 100.

36. The method of claim 35 , wherein the event scores indicate possibilities of the plurality of events being causes of the specific alarm.

37. A network performance monitor comprising:

a database maintenance module to maintain a database of alarms and events from a system of monitored elements;

an alarm cause identification module coupled to the database maintenance module, wherein the alarm cause identification module is configured to automatically identify a possible cause of a specific alarm by correlating the specific alarm with a plurality of events using the database, wherein the alarm cause identification module automatically identifies a possible cause based on (1) analysis of performance abnormalities and at least one of an event or alert, (2) statistical correlation, (3) elimination of unrelated causes, (4) user defined groupings and (5) relative weightings of monitored elements.

38. The monitor defined in claim 37 wherein one of the plurality of events comprises one of a selected group consisting of a performance abnormality, a threshold alert, and a software change.

39. The monitor defined in claim 37 wherein the alarm cause identification module performs statistical correlation on the performance abnormalities to generate a list of possible candidate abnormalities.

40. The monitor defined in claim 39 wherein the alarm cause identification module performs isolation filtering to eliminate a set of problems and performs scoring and categorization on a filtered set of abnormalities to pinpoint the probable cause.

41. The network performance monitor of claim 37 further including a display module to display the cause of the specific alarm.

42. The network performance monitor of claim 37 wherein the monitored elements include network devices, network systems, and network applications.

43. The network performance monitor of claim 37 wherein the specific alarm consists of a notification of an occurrence of the plurality of events.

44. A network performance monitor comprising:

means for maintaining a database of alarms and events from a system of monitored elements; and

means for automatically identifying a possible cause of a specific alarm by correlating the specific alarm with a plurality of events using the database, wherein the means for automatically identifying a possible cause comprises means for (1) analysis of performance abnormalities and at least one of an event or alert, (2) statistical correlation, (3) elimination of unrelated causes, (4) user defined groupings and (5) relative weightings of monitored elements.

45. The monitor defined in claim 44 wherein one of the plurality of events comprises one of a selected group consisting of a performance abnormality, a threshold alert, and a software change.

46. The monitor defined in claim 44 further comprising means for performing statistical correlation on the performance abnormalities to generate a list of possible candidate abnormalities.

47. The monitor defined in claim 46 further comprising means for performing isolation filtering to eliminate a set of abnormalities problems and means for performing scoring and categorization to pinpoint the probable cause.

48. The network performance monitor of claim 44 further including means for displaying the cause of the specific alarm.

49. The network performance monitor of claim 44 wherein the monitored elements include network devices, network systems, and network applications.

50. The network performance monitor of claim 44 wherein the specific alarm consists of a notification of an occurrence of the plurality of events.

51. A computer readable medium, the medium having stored thereon a sequence of instructions which, when executed by a processor, cause the processor to:

collect a database of alarms and events from a system of monitored elements; and

automatically identify a possible cause of a specific alarm by correlating the specific alarm with a plurality of events using the database, wherein automatically identifying a possible cause comprises (1) analysis of performance abnormalities and at least one of an event or alert, (2) statistical correlation, (3) elimination of unrelated causes, (4) user defined groupings and (5) relative weightings of monitored elements.

52. The computer software product defined in claim 51 wherein one of the plurality of events comprises one of a selected group consisting of a performance abnormality, a threshold alert, and a software change.

53. The computer software product defined in claim 51 further comprising performing statistical correlation on the performance abnormalities to generate a list of possible candidate abnormalities.

54. The computer software product defined in claim 53 further comprising performing isolation filtering to eliminate a set of problems; and

performing scoring categorization to pinpoint the probable cause.

55. The computer software product of claim 51 further including a sequence of instructions which, when executed by the processor, cause the processor to display the cause of the specific alarm.

56. The computer software product of claim 51 wherein the monitored elements include network devices, network systems and network applications.

57. The computer software product of claim 51 wherein the specific alarm consists of a notification of an occurrence of the plurality of events.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2025
From: BMC SOFTWARE, INC.
To: BMC HELIX, INC.
Reel/Frame 070442/0197 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052844/0646) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0408 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052854/0139) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0617 →
OMNIBUS ASSIGNMENT OF SECURITY INTERESTS IN PATENT COLLATERAL Recorded Mar 4, 2024
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING COLLATERAL AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 066729/0889 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 1, 2024
From: ALTER DOMUS (US) LLC
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 066567/0283 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Sep 30, 2021
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 057683/0582 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052844/0646 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052854/0139 →
RELEASE OF PATENTS Recorded Oct 5, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.; BMC ACQUISITION L.L.C.
Reel/Frame 047198/0468 →
SECURITY INTEREST Recorded Oct 2, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047185/0744 →
SECURITY AGREEMENT Recorded Sep 11, 2013
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 031204/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2009
From: PROACTIVENET, INC.
To: BMC SOFTWARE, INC.
Reel/Frame 023379/0981 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2002
From: LEFAIVE, RONALD ALEXANDER; SODEM, SRIDHAR; SCARPELLI, JOE; KETCHAM, DANIEL; GARG, ATUL
To: PROACTIVENET, INC.
Reel/Frame 013508/0333 →