User Interface For Network Events and Tuning
According to an aspect of the invention, a system and method is configured to generate a user interface to display information about time series outliers in network traffic.
1 . A computer program product residing on a computer readable medium for anomaly detection, the computer program product comprising instructions for causing a processor to:
generate, based on information related to monitored network traffic, a user interface for providing information about observed anomalous behavior in the monitored network traffic;
display the user interface on a display device, the user interface comprising:
a first region that provides summary information related to the identified anomalous behavior in the monitored network traffic;
a second region that includes impact details related to the anomalous behavior in the monitored network traffic, the impact details including an indication of at least some impacted network entities and the extent of the impact of the anomalous behavior in the monitored network traffic on the impacted network entities.
2 . The computer program product of claim 1 , wherein the user interface further comprises a third portion that includes impact scores for at least some of the impacted network entities, the impact scores indicating the contribution of the impacted network entity to the overall observed anomalous behavior in the monitored network traffic.
3 . The computer program product of claim 2 , wherein the user interface further comprises a fourth portion that includes one or more graphical representations of typical network traffic and the monitored network traffic as a function of time.
4 . The computer program product of claim 3 , wherein the user interface further comprises a fifth portion comprising an action portion including input options to enable the user to take action based on the anomalous behavior in the monitored network traffic.
5 . The computer program product of claim 4 , wherein the input options to enable the user to take action based on the anomalous behavior comprise an input option to suppress the alert for a period of time and an option to change the settings that resulted in the generation of the event.
6 . A method comprising:
displaying, on a problem summary portion of a user interface, summary information related to anomalous behavior in monitored network traffic;
displaying, on an impacted infrastructure and interfaces portion of the user interface, information related to changes in network traffic for one or more network entities at the time of the anomalous network traffic; and
providing, on an actions portion of the user interface, input options for a user to input desired actions in response to the anomalous behavior in monitored network traffic.
7 . A method comprising:
generating, based on information related to monitored network traffic, a user interface for providing information about observed anomalous behavior in the monitored network traffic;
displaying the user interface on a display device, the user interface comprising:
a first region that provides summary information related to the identified anomalous behavior in the monitored network traffic;
a second region that includes impact details related to the anomalous behavior in the monitored network traffic, the impact details including an indication of at least some impacted network entities and the extent of the impact of the anomalous behavior in the monitored network traffic on the impacted network entities.
8 . The method of claim 7 , wherein the user interface further comprises a third portion that includes impact scores for at least some of the impacted network entities, the impact scores indicating the contribution of the impacted network entity to the overall observed anomalous behavior in the monitored network traffic.
9 . The method of claim 7 , wherein the user interface further comprises a fourth portion that includes one or more graphical representations of typical network traffic and the monitored network traffic as a function of time.
10 . The method of claim 7 , wherein the user interface further comprises a fifth portion comprising an action portion including input options to enable the user to take action based on the anomalous behavior in the monitored network traffic.
11 . A computer program product residing on a computer readable medium for anomaly detection, the computer program product comprising instructions for causing a processor to:
generate, based on information related to monitored network traffic, a user interface for providing information about observed behavior in the monitored network traffic, the information including a time series graph including identification of anomalous behavior in the monitored network traffic;
receive an input from a user of a change in a sensitivity level, the sensitivity level being associated with a threshold for identification of anomalous behavior; and
generate, based on the information related to monitored network traffic, an updated time series graph including identification of anomalous behavior which would have been detected in the monitored network traffic based on the sensitivity level received from the user.
12 . The computer program product of claim 11 , wherein the user interface further comprises a sensitivity slider that allows a user to input the change in a sensitivity level.
13 . The computer program product of claim 11 , wherein the user interface further comprises an alert level input configured to enable a user to input an alert level.
14 . The computer program product of claim 13 , wherein the alert level input comprises a selectable alert level and threshold number of anomalies which will result in identification of an event.