IP Library Granted Patent US 10,373,094
Granted Patent B2
US 10,373,094 · App. 15/224,376 · Granted Aug 6, 2019

Automated model based root cause analysis

Inventors: Jad Naous (San Francisco, CA); Vinay Srinivasaiah (San Carlos, CA); Jonathan Newcomb Swirsky Whitney (Albany, CA)
Assignee: Cisco Technology, Inc.
G06Q10/06395G06Q10/067G06Q10/06393
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,373,094
App. No.
15/224,376
Granted
Aug 6, 2019
Kind
B2
Abstract

In one aspect, a system for providing automated root cause analysis of a monitored business transaction is disclosed. The system includes a processor; a memory; and one or more modules stored in the memory and executable by a processor to perform various operations. For example, a performance issue associated with the business transaction running in a monitored environment can be detected and automated root cause analysis can be provided to present to a user a chain of entities associated with detected performance issue. A score can be provided for each node of entity in the chain to indicate which node of entity is likelihood to be a root cause candidate for the performance issue.

Claims (40)

1. A system for providing automated root cause analysis of a monitored business transaction, including:

a processor;

a memory; and

one or more modules stored in the memory and executable by a processor to perform operations including:

detect a performance issue associated with the monitored business transaction running over a network in a monitored environment;

provide a dashboard user interface to display information regarding the detected performance issue associated with the monitored business transaction;

receive user input through the dashboard user interface that indicates an entity and data source for the entity associated with the detected performance issue based on the displayed information, wherein the entity is a node on a machine associated with the monitored business transaction;

automatically use an entity dependency model with the user indicated entity as a seed to generate entity relationship data that indicate a chain of relationships among different entities related to the user indicated entity and associated with the detected performance issue; and

display the entity relationship data using a dependency graph to illustrate the chain of relationships among the different entities related to the user indicated entity and associated with the detected performance issue, wherein the user indicated entity is a node in the chain of relationships.

2. The system of claim 1 , wherein the user input indicating the seed entity associated with the detected performance issue includes a business transaction, a tier, a node, a database, a network, a machine, or a process.

3. The system of claim 1 , wherein the dependency graph includes each of the related entities as a node in the chain of relationships and a score for each node indicating how important each entity node is to the detected performance issue.

4. The system of claim 3 , wherein the dependency graph includes an indication of whether an anomaly exists at each entity node and an identification of the anomaly if existing.

5. The system of claim 3 , wherein the one or more modules are executable by a processor to use an anomaly detection algorithm to analyze data source at each entity node to generate the score for each entity node.

6. The system of claim 3 , wherein the score indicates a likelihood of the entity node being a root cause candidate of the detected performance issue.

7. The system of claim 3 , wherein the one or more modules are executable by a processor to cluster the entity nodes or a chain of entity nodes together based on the score.

8. The system of claim 1 , wherein the data source includes metric, events, logs, snapshots, or configurations.

9. The system of claim 8 , wherein the data source is associated with data including average response time, calls per minute, load, number of slow calls, or number of very slow calls.

10. The system of claim 1 , wherein the one or more modules are executable by a processor to generate the dependency graph for multiple performance issues and group dependency graphs based on a similarity in the dependency graph to identify different performance issues with a common root cause.

11. The system of claim 10 , wherein the one or more modules are executable by a processor to visually stack the dependency graphs of the multiple performance issues to group similar graphs together.

12. A method for providing automated model based root cause analysis of a monitored business transaction, including:

detecting a performance issue associated with the monitored business transaction running over a network in a monitored environment;

providing a dashboard user interface to display information regarding the detected performance issue associated with the monitored business transaction;

receiving user input through the dashboard user interface that indicates an entity and data source for the entity associated with the detected performance issue based on the displayed information, wherein the entity is a node on a machine associated with the monitored business transaction;

automatically using an entity dependency model with the user indicated entity as a seed to generate entity relationship data that indicate a chain of relationships among different entities related to the user indicated entity and associated with the detected performance issue; and

displaying the entity relationship data using a dependency graph to illustrate the chain of relationships among the different entities related to the user indicated entity and associated with the detected performance issue, wherein the user indicated entity is a node in the chain of relationships.

13. The method of claim 12 , wherein the dependency graph includes each of the related entities as a node in the chain of relationships and a score for each node indicating how important each entity node is to the detected performance issue.

14. The method of claim 13 , wherein the dependency graph includes an indication of whether an anomaly exists at each entity node and an identification of the anomaly if existing.

15. The method of claim 13 , including using an anomaly detection algorithm to analyze data source at each entity node to generate the score for each entity node.

16. The method of claim 13 , wherein the score indicates a likelihood of the entity node being a root cause candidate of the detected performance issue.

17. The method of claim 13 , including clustering the entity nodes or a chain of entity nodes together based on the score.

18. The method of claim 12 , including generating the dependency graph for multiple performance issues and group dependency graphs based on a similarity in the dependency graph to identify different performance issues with a common root cause.

19. The method of claim 12 , including displaying a stack of the dependency graphs of the multiple performance issues to group similar graphs together.

20. A non-transitory computer readable medium embodying instructions when executed by a processor to cause operations to be performed including:

detecting a performance issue associated with a monitored business transaction running over a network in a monitored environment;

providing a dashboard user interface to display information regarding the detected performance issue associated with the monitored business transaction;

receiving user input through the dashboard user interface that indicates an entity and data source for the entity associated with the detected performance issue based on the displayed information, wherein the entity is a node on a machine associated with the monitored business transaction;

automatically using an entity dependency model with the user indicated entity as a seed to generate entity relationship data that indicate a chain of relationships among different entities related to the user indicated entity and associated with the detected performance issue; and

displaying the entity relationship data using a dependency graph to illustrate the chain of relationships among the different entities related to the user indicated entity and associated with the detected performance issue, wherein the user indicated entity is a node in the chain of relationships.

21. The non-transitory computer readable medium of claim 20 , wherein the dependency graph includes each of the related entities as a node in the chain of relationships and a score for each node indicating how important each entity node is to the detected performance issue.

22. The non-transitory computer readable medium of claim 21 , including generating the dependency graph for multiple performance issues and group dependency graphs based on a similarity in the dependency graph to identify different performance issues with a common root cause.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2017
From: APPDYNAMICS LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 044173/0050 →
CHANGE OF NAME Recorded Jun 23, 2017
From: APPDYNAMICS, INC.
To: APPDYNAMICS LLC
Reel/Frame 042964/0229 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2017
From: NAOUS, JAD; SRINIVASAIAH, VINAY; WHITNEY, JONATHAN NEWCOMB SWIRSKY
To: APPDYNAMICS, INC.
Reel/Frame 041426/0592 →
Continuity (1)
Related Publication 20180032941A1 · Feb 1, 2018
Cited By (9)
US 51,007 US 12,199,813 US 12,238,069 US 12,244,566 US 12,267,300 US 12,316,487 US 12,326,864 US 12,541,417 US 12,647,394