IP Library Granted Patent US 7,444,263
Granted Patent B2
US 7,444,263 · App. 11/832,319 · Granted Oct 28, 2008

Performance metric collection and automated analysis

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,444,263
App. No.
11/832,319
Granted
Oct 28, 2008
Kind
B2
Abstract

A metric monitoring and analysis system including dynamic sampling agents located in monitored system elements and a service management platform. Each sampling agent includes a data adapter collecting metric data in a common format, a threshold generator for determining dynamic metric threshold ranges, an alarm detector generating an indicator when a metric deviates outside a dynamic threshold range or a static threshold, and a deviation tracker generating an alarm severity scores. The service platform includes an alarm analyzer identifying root causes of system alarm conditions by correlation of grouped metrics or forensic analysis of temporally or statistically correlated secondary forensic data or data items from a service model of the system.

Claims (75)

1. A method for performing system metric analysis, comprising the steps of:

collecting metric data representing system operations from a plurality of system sources,

determining a dynamic metric threshold range for each metric over successive time periods,

indicating a metric alarm event by

generating a metric threshold alarm indicator when a corresponding metric value deviates outside the dynamic threshold range,

generating an alarm severity score for each metric alarm event, and

performing a root cause analysis identifying a basic cause of a system alarm condition by at least one of

correlation of grouped metrics with alarm conditions, and

forensic analysis of selected secondary forensic data items recorded upon the occurrence of at least selected alarm conditions.

2. The method for performing system metric analysis of claim 1 , wherein the step of collecting metric data from system sources further includes the steps of:

collecting the metric data from each source in a source format, and

transforming the metric data from the corresponding source format into at least one common format.

3. The method for performing system metric analysis of claim 1 , wherein the step of determining a dynamic metric threshold range for each metric further includes the steps of:

generating an empirical estimate of an actual distribution of values of the metric,

determining a trend in the actual distribution of the values of the metric,

determining an expected range of the values of the metric over the time periods, and

determining a dynamic threshold range for each metric based on the expected range of values of the metric.

4. The method for performing system metric analysis of claim 1 , wherein the step of indicating a metric alarm event further includes the steps of:

generating a metric threshold alarm indicator when a corresponding metric value deviates outside a static threshold range.

5. The method for performing system metric analysis of claim 1 , wherein the step of generating an alarm severity score for each metric alarm further includes the step of:

determining the severity score as a ratio of a time and magnitude of the metric value deviation outside the threshold range to a width of the threshold range.

6. The method for performing system metric analysis of claim 1 , wherein the step of correlation and grouping of metrics with alarm indicators further includes at least one of the steps of:

performing a temporal alarm correlation process by identifying metrics having values resulting in alarm conditions that are correlated in time, and

performing a statistical metric correlation process by correlating pairs of metrics having values resulting in an alarm condition according to the relative ranks of the values of the metrics.

7. The method for performing system metric analysis of claim 1 , wherein the step of analysis of recorded secondary forensic data items and alarm indicators further includes at least one of the steps of:

upon occurrence of each of at least one of the selected alarm indicators,

recording selected key metrics defined as bounding the data items with at least one of temporal and statistical correlation of the metrics and

recording data items selected from a service model of the system representing system operations associated with an alarm condition.

8. The method for performing system metric analysis of claim 1 , wherein the secondary forensic data items comprise non-metric information pertaining to system conditions at occurrence of an alarm condition.

9. The method for performing system metric analysis of claim 1 , wherein:

the steps of

collecting metric data representing system operations from a plurality of system sources,

determining a dynamic metric threshold range for each metric over successive time periods,

indicating a metric alarm event by generating a metric threshold alarm indicator when a corresponding metric value deviates outside the dynamic threshold range, and

generating an alarm severity score for each metric alarm event,

are performed in dynamic sampling agents located at each data source, the step of performing a root cause analysis identifying a basic cause of a system alarm condition is performed

in a central service management platform, and

the method further includes the step of

communicating each metric alarm event and each alarm severity score for each metric alarm event from the dynamic sampling agent to the service management platform.

10. The method for performing system metric analysis of claim 2 , wherein:

the step of collecting metric data from system sources is performed by dynamic sampling agents located at each data source, and

the steps of

collecting the metric data from a source in a source format, and

transforming the metric data from the corresponding source format into at least one common format,

are performed in each dynamic sampling agent by a data adapter.

11. A metric monitoring and analysis system, comprising:

a plurality of dynamic sampling agents, each dynamic sampling agent being located in a system element containing a metric of interest for monitoring and analysis and including

at least one plurality of data collectors for collecting metric data representing system operations from a plurality of system sources,

a threshold generator for determining a dynamic metric threshold range for each metric over successive time periods,

an alarm condition detector indicating a metric alarm event by

generating a metric threshold alarm indicator when a corresponding metric value deviates outside the dynamic threshold range, and

a deviation tracker for generating an alarm severity score for each metric alarm event, and

a single service management platform receiving alarm indicators and severity scores from the dynamic sampling agents and including

an alarm analyzer performing a root cause analysis identifying a basic cause of a system alarm condition by at least one of

correlation of grouped metrics with alarm conditions, and

forensic analysis of selected secondary forensic data items recorded upon the occurrence of at least one or more selected alarm conditions.

12. The metric monitoring and analysis system of claim 11 , wherein each dynamic sampling agent further includes:

at least one data adapter for transforming the metric data from a corresponding source format into at least one common format.

13. The metric monitoring and analysis system of claim 11 , wherein:

for each metric, the threshold generator

generates an empirical estimate of an actual distribution of values of the metric,

determines a trend in the actual distribution of the values of the metric,

determines an expected range of the values of the metric over the time periods, and

determines a dynamic threshold range for each metric based on the expected range of values of the metric.

14. The metric monitoring and analysis system of claim 11 , wherein:

the alarm condition generator generates a metric threshold alarm indicator when a corresponding metric value deviates outside a static threshold range.

15. The metric monitoring and analysis system of claim 11 , wherein:

the deviation tracker generates an alarm severity score for each metric alarm by determining the severity score as a ratio of a time and magnitude of the metric value deviation outside the threshold range to a width of the threshold range.

16. The metric monitoring and analysis system of claim 11 , wherein the alarm analyzer performs a con-elation of grouped metrics by at least one of

a temporal alarm correlation process identifying metrics having values resulting in alarm conditions that are correlated in time, and

a statistical metric correlation process correlating pairs of metrics having values resulting in an alarm condition according to the relative ranks of the values of the metrics.

17. The metric monitoring and analysis system of claim 11 , wherein the alarm analyzer records secondary forensic data items on the occurrence of at least selected alarm indicators by at least one of

recording selected key metrics defined as bounding the data items with at least one of temporal and statistical correlation of the metrics, and

recording data items selected from a service model of the system representing system operations associated with an alarm condition.

18. The metric monitoring and analysis system of claim 12 , wherein the secondary forensic data items comprise non-metric information pertaining to system conditions at occurrence of an alarm condition.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 10, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059009/0906 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2020
From: RIVERBED TECHNOLOGY, INC.
To: ATERNITY LLC
Reel/Frame 054778/0540 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2013
From: OPNET TECHNOLOGIES LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 030462/0135 →
CHANGE OF NAME Recorded May 14, 2013
From: OPNET TECHNOLOGIES, INC.
To: OPNET TECHNOLOGIES LLC
Reel/Frame 030411/0273 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2007
From: WHITE, DAVID RONALD; MACOMBER, EDWARD W.; LABATT, EARL CHARLES, JR.; MCGEE, JOHN J.; BARON, STEVEN J.
To: OPNET TECHNOLOGIES, INC.
Reel/Frame 019890/0317 →