IP Library Granted Patent US 11,184,220
Granted Patent B2
US 11,184,220 · App. 16/231,028 · Granted Nov 23, 2021

Automated remediation of information technology events

Inventors: Frank Nitsch (Böblingen, DE); Stefan Bergstein (Böblingen, DE)
Assignee: MICRO FOCUS LLC
H04L41/0654G06F11/079G06F11/0793G06F11/3006H04L41/069H04L41/0631H04L41/16H04L41/5074G06F2201/88
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,184,220
App. No.
16/231,028
Granted
Nov 23, 2021
Kind
B2
Abstract

A computing device includes a processor and a medium storing instructions. The instructions are executable by the processor to: detect an information technology (IT) event associated with an IT system; determine an event class for the IT event; identify a plurality of event-procedure relations associated with the determined event class, each of the plurality of event-procedure relations having an associated success score; select a first event-procedure relation having a highest success score, wherein the first event-procedure relation specifies a relation between the determined event class and a first remediation procedure; and execute the selected first remediation procedure to remediate the IT event.

Claims (62)

1. A computing device comprising:

a hardware processor; and

a machine-readable storage medium storing instructions, the instructions executable by the hardware processor to:

detect an information technology (IT) event associated with an IT system;

determine a particular event class for the IT event;

identify a plurality of event-procedure relations associated with the particular event class using a relation data structure, wherein the relation data structure comprises a plurality of records, wherein each record of the relation data structure identifies a unique event-procedure relation between a single event class and a single remediation procedure that remediates events in the single event class, and wherein each record of the relation data structure includes a single relation identifier identifying the unique event-procedure relation, a single event class identifier identifying the single event class, a single procedure identifier identifying the single remediation procedure, and a success score indicating a degree of success of past executions of the single remediation procedure to remediate the events in the single event class;

select, among the plurality of event-procedure relations, a first event-procedure relation according to a weighted formula based on a number of keywords in the first event-procedure relation that match the IT event and the success score of the first event-procedure relation, wherein the first event-procedure relation specifies a relation between the particular event class and a first remediation procedure; and

responsive to the selection of the first event-procedure relation, execute the first remediation procedure to remediate the IT event.

2. The computing device of claim 1 , wherein, to determine the particular event class for the IT event, the instructions cause the hardware processor to:

compare keywords of the IT event to keywords of each of a plurality of event classes, and

based on the comparison, identify one of the plurality of event classes that has a largest number of keywords that match the keywords of the IT event as the particular event class for the IT event.

3. The computing device of claim 1 , wherein the instructions are executable by the hardware processor to:

determine a level of success of the execution of the first remediation procedure to remediate the IT event; and

update the success score of the first event-procedure relation based on the level of success of the execution.

4. The computing device of claim 1 , wherein the first remediation procedure is defined in a stored procedure library, and comprises at least one script.

5. The computing device of claim 1 , wherein the instructions are executable by the hardware processor to:

determine a plurality of counts of executions of the first remediation procedure associated with the particular event class, wherein each count of the plurality of counts is associated with a particular success level of a plurality of success levels; and

calculate the success score of the first event-procedure relation based on the plurality of counts.

6. The computing device of claim 5 , wherein the plurality of counts of executions of the first remediation procedure comprises a successful count, a helpful count, and an unhelpful count, wherein:

the successful count indicates a count of executions of the first remediation procedure that resolved IT events in the particular event class,

the helpful count indicates a count of executions of the first remediation procedure that improved hut did not resolve the IT events in the particular event class, and

the unhelpful count indicates a count of executions of the first remediation procedure that did not improve or resolve the IT events in the particular event class.

7. A non-transitory machine-readable storage medium storing instructions that upon execution cause a processor to:

receive an indication of an event associated with an information technology (IT) system;

identify a particular event class associated with the event;

identify a plurality of event-procedure relations associated with the particular event class using a relation data structure, Wherein the relation data structure comprises a plurality of records, wherein each record of the relation data structure identifies a unique event-procedure relation between a single event class and a single remediation procedure that remediates events in the single event class, and wherein each record of the relation data structure comprises a single relation identifier identifying the unique event-procedure relation, a single event class identifier identifying the single event class, and a single procedure identifier identifying the single remediation procedure;

determine a plurality of success scores associated with the plurality of event-procedure relations, wherein each success score corresponds to one of the plurality of event-procedure relations;

select, among the plurality of event-procedure relations, a first event-procedure relation according to a weighted formula based on a number of keywords in the first event-procedure relation that match the event and a first success score of the first event-procedure relation, wherein the first event-procedure relation specifies a relation between the particular event class and a first remediation procedure; and

execute the first remediation procedure to remediate the event.

8. The non-transitory machine-readable storage medium of claim 7 , wherein the instructions further cause the processor to:

determine a level of success of the execution of the first remediation procedure to remediate the event; and

update the first success score based on the level of success of the execution of the first remediation procedure.

9. The non-transitory machine-readable storage medium of claim 7 , wherein each record further comprises a success score indicating a degree of success of past executions of the single remediation procedure identified by the single procedure identifier.

10. The non-transitory machine-readable storage medium of claim 7 , wherein the instructions cause the processor to;

determine a plurality of counts of executions of the first remediation procedure associated with the particular event class, wherein each count of the plurality of counts is associated with a particular success level of a plurality of success levels: and

calculate the first success score based on the plurality of counts of executions.

11. The non-transitory machine-readable storage medium of claim 10 , wherein the plurality of counts of executions of the first remediation procedure comprises a successful count, a helpful count, and an unhelpful count, wherein:

the successful count indicates a count of executions of the first remediation procedure that resolved events in the particular event class,

the helpful count indicates a count of executions of the first remediation procedure that improved but did not resolve the events in the particular event class, and

the unhelpful count indicates a count of executions of the first remediation procedure that did not improve or resolve the events in the particular event class.

12. The non-transitory machine-readable storage medium of claim 7 , wherein the first remediation procedure is defined in a stored procedure library, and comprises at least one script.

13. A computer implemented method, comprising:

receiving an indication of an event associated with an information technology (IT) system:

in response to a receipt of the indication of the event, identifying a particular event class associated with the event;

determining a plurality of event-procedure relations associated with the particular event class using a relation data structure, wherein determining the plurality of event-procedure relations comprises accessing a stored relation data structure comprising a plurality of records, wherein each record of the stored relation data structure identifies a unique event-procedure relation between a single event class and a single remediation procedure, and wherein each record of the stored relation data structure comprises a single relation identifier identifying the unique event-procedure relation, a single event class identifier identifying the single event class, a single procedure identifier identifying the single remediation procedure, and a success score indicating a degree of success of past executions of the single remediation procedure to remediate events in the single event class;

selecting among the plurality of event-procedure relations, a first event-procedure relation according to a weighted formula based on a number of keywords in the first event-procedure relation that match the event and the success score of the first event-procedure relation, wherein the first event-procedure relation is associated with a first remediation procedure; and

responsive to selecting the first event-procedure relation, executing the first remediation procedure to resolve the event.

14. The computer implemented method of claim 13 , further comprising:

determining a level of success of the execution of the first remediation procedure to resolve the event; and

updating the success score of the first event-procedure relation based on the level of success of the execution.

15. The computer implemented method of claim 13 wherein identifying the particular event class associated with the event comprises:

comparing keywords of the event to keywords of each of a plurality of event classes, and

based on the comparison, identifying one of the plurality of event classes that has a largest number of keywords that match the keywords of the event as the particular event class associated with the event.

16. The computer implemented method of claim 13 , wherein the first remediation procedure is defined by procedure data stored in a procedure library, wherein executing the first remediation procedure comprises executing a script included in the procedure data.

17. The computer implemented method of claim 13 , the method further comprising:

determining a plurality of counts of executions of the first remediation procedure, wherein each count of the plurality of counts is associated with a particular success level of a plurality of success levels; and

calculating the success score of the first event-procedure relation based on the plurality of counts.

18. The computer implemented method of claim 17 , wherein the event is one selected from a hardware issue and a software issue.

19. The computer implemented method of claim 17 , wherein the plurality of counts of execution of the first remediation procedure comprises a successful count, a helpful count, and an unhelpful count, wherein:

the successful count indicates a count of executions of the first remediation procedure that resolved events in the particular event class,

the helpful count indicates a count of executions of the first remediation procedure that improved but did not resolve the events in the particular event class, and

the unhelpful count indicates a count of executions of the first remediation procedure that did not improve or resolve the events in the particular event class.

Assignments (6)
RELEASE OF SECURITY INTEREST REEL/FRAME 052294/0522 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062624/0449 →
RELEASE OF SECURITY INTEREST REEL/FRAME 052295/0041 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062625/0754 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: MICRO FOCUS LLC; BORLAND SOFTWARE CORPORATION; MICRO FOCUS SOFTWARE INC.; NETIQ CORPORATION; MICRO FOCUS (US), INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052294/0522 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: MICRO FOCUS LLC; BORLAND SOFTWARE CORPORATION; MICRO FOCUS SOFTWARE INC.; NETIQ CORPORATION; MICRO FOCUS (US), INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 052295/0041 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2018
From: NITSCH, FRANK; BERGSTEIN, STEFAN
To: ENTIT SOFTWARE LLC
Reel/Frame 047846/0975 →