IP Library Granted Patent US 10,887,158
Granted Patent B2
US 10,887,158 · App. 16/264,224 · Granted Jan 5, 2021

Alert dependency checking

Inventors: Gurjeet S. Arora (Palo Alto, CA); Karan Jayesh Bavishi (San Francisco, CA); Daniel Talamas Cano (Palo Alto, CA); John Louie (Redwood City, CA); Chetas Joshi (Mountain City, CA); Matthew Edward Noe (San Francisco, CA)
Assignee: Rubrik, Inc.
H04L41/0631H04L41/069G06F9/45558G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,887,158
App. No.
16/264,224
Granted
Jan 5, 2021
Kind
B2
Abstract

Various embodiments provide for alert generation based on alert dependency. For some embodiments, the alert dependency checking facilitates alert noise reduction. Various embodiments described herein dynamically find or discover alert dependencies based on one or more alerts currently active, one or more active alerts generated in the past, or some combination of both. Various embodiments described herein provide alert monitoring that adapts based on an alert state of a machine. Various embodiments described herein generate a health score for a machine based on an alert state of the machine. Various embodiments described herein provide a tool for managing definitions of one or more alerts that can be identified as an active alert for a machine.

Claims (57)

1. A method comprising:

accessing, by one or more hardware processors, telemetry data associated with a computing node the computing node operating one or more software services that can trigger one or more alerts;

evaluating, by the one or more hardware processors, the telemetry data to identify a set of triggered alerts triggered by the computing node, the telemetry data comprising log data generated by the computing node, the evaluating the telemetry data comprising:

obtaining, from the log data, alert data for a set of identifiable alerts; and

generating time-series alert data based on the alert data to identify the set of triggered alerts, the generating the time-series alert data comprising:

for a given identifiable alert described in the alert data, recording a time for each time a given metric, associated with the given identifiable alert, surpasses a threshold value;

accessing, by the one or more hardware processors, alert dependency data that describes a set of dependencies between a plurality of alerts; and

filtering, by the one or more hardware processors, the set of triggered alerts based on the alert dependency data to generate a set of active alerts.

2. The method of claim 1 , wherein the filtering the set of triggered alerts based on the alert dependency data to generate the set of active alerts comprises:

determining, based on the alert dependency data; whether a first triggered alert in the set of triggered alerts is dependent upon any other triggered alert in the set of triggered alerts; and

in response to determining that the first triggered alert is dependent upon a second triggered alert in the set of triggered alerts, generating the set of active alerts to exclude the first triggered alert.

3. The method of claim 1 , wherein the filtering the set of triggered alerts based on the alert dependency data to generate a set of active alerts comprises:

determining, based on the alert dependency data; whether a first triggered alert in the set of triggered alerts is dependent upon any other triggered alert in the set of triggered alerts; and

in response to determining that the first triggered alert is not dependent upon any other triggered alert in the set of triggered alerts, generating the set of active alerts to include the first triggered alert.

4. The method of claim 1 , wherein the plurality of alerts comprises a first alert and a second alert, and the set of dependencies comprises a particular dependency that describes that an occurrence of the first alert is dependent upon an occurrence of the second alert.

5. The method of claim 1 , wherein the alert dependency data is generated based on historical active alert data or correlation data between at least two alerts.

6. The method of claim 1 , wherein the generating the time-series alert data based on the alert further comprises:

for an individual identifiable alert described in the alert data, in response to each time an individual metric, associated with the individual identifiable alert, surpasses the threshold value, recording an amount by which the individual metric surpasses the threshold value.

7. The method of claim 1 , wherein the telemetry data comprises at least one of metric data regarding operation of the computing node or log data generated by the computing node.

8. The method of claim 1 , further comprising storing, by the one or more hardware processors, the set of active alerts as historical active alert data.

9. The method of claim 1 , further comprising performing, by the one or more hardware processors, alert dependency analysis, based on the set of active alerts and historical active alert data, to update the alert dependency data.

10. The method of claim 1 , wherein the alert dependency data is generated based on user-provided dependency mapping between two or more alerts.

11. The method of claim 1 , wherein the evaluating the telemetry data to identify the set of triggered alerts for the computing node comprises:

performing a set of searches with respect to the telemetry data, the set of searches corresponding to a set of identifiable alerts.

12. A system comprising:

a memory storing instructions; and

one or more hardware processors communicatively coupled to the memory and configured by the instructions to perform operations comprising:

accessing telemetry data associated with a computing node, the computing node operating one or more software services that can trigger one or more alerts;

evaluating the telemetry data to identify a set of triggered alerts triggered by the computing node the telemetry data comprising log data generated by the computing node, the evaluating the telemetry data comprising:

obtaining, from the log data, alert data for a set of identifiable alerts; and

generating time-series alert data based on the alert data to identify the set of triggered alerts, the generating the time-series alert data comprising:

for a given identifiable alert described in the alert data, recording a time for each time a given metric, associated with the given identifiable alert, surpasses a threshold value;

accessing alert dependency data that describes a set of dependencies between a plurality of alerts; and

filtering the set of triggered alerts based on the alert dependency data to generate a set of active alerts.

13. The system of claim 12 , wherein the operations further comprise;

storing the set of active alerts as historical active alert data.

14. The system of claim 12 , wherein the operations further comprise;

performing alert dependency analysis, based on the set of active alerts and historical active alert data, to update the alert dependency data.

15. The system of claim 12 , wherein the filtering the set of triggered alerts based on the alert dependency data to generate the set of active alerts comprises:

determining, based on the alert dependency data; whether a first triggered alert in the set of triggered alerts is dependent upon any other triggered alert in the set of triggered alerts; and

in response to determining that the first triggered alert is dependent upon a second triggered alert in the set of triggered alerts, generating the set of active alerts to exclude the first triggered alert.

16. The system of claim 12 , wherein the filtering the set of triggered alerts based on the alert dependency data to generate the set of active alerts comprises:

determining, based on the alert dependency data; whether a first triggered alert in the set of triggered alerts is dependent upon any other triggered alert in the set of triggered alerts; and

in response to determining that the first triggered alert is not dependent upon any other triggered alert in the set of triggered alerts, generating the set of active alerts to include the first triggered alert.

17. The system of claim 12 , wherein the plurality of alerts comprises a first alert and a second alert, and the set of dependencies comprises a particular dependency that describes that an occurrence of the first alert is dependent upon an occurrence of the second alert.

18. A non-transitory computer-readable storage medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:

accessing telemetry data associated with a computing node, the computing node operating one or more software services that can trigger one or more alerts;

evaluating the telemetry data to identify a set of triggered alerts triggered by the computing node, the telemetry data comprising log data generated by the computing node, the evaluating the telemetry data comprising:

obtaining, from the log data, alert data for a set of identifiable alerts; and

generating time-series alert data based on the alert data to identify the set of triggered alerts, the generating the time-series alert data comprising:

for a given identifiable alert described in the alert data, recording a time for each time a given metric, associated with the given identifiable alert, surpasses a threshold value;

accessing alert dependency data that describes a set of dependencies between a plurality of alerts; and

filtering the set of triggered alerts based on the alert dependency data to generate a set of active alerts.

19. The non-transitory computer-readable storage medium of claim 18 , wherein the operations further comprise:

storing the set of active alerts as historical active alert data.

20. The non-transitory computer-readable storage medium of claim 18 , wherein the operations further comprise:

performing alert dependency analysis, based on the set of active alerts and historical active alert data, to update the alert dependency data.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 60333/0323 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071565/0602 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 10, 2022
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 060333/0323 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NAME OF LAST NAME OF DANIEL TALAMAS CANO FROM "CANO" TO TALAMAS CANO" AND EXECUTION DATE OF CHETAS JOSHI TO "02/14/2020" PREVIOUSLY RECORDED AT REEL: 051848 FRAME: 0420. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 4, 2020
From: ARORA, GURJEET S.; BAVISHI, KARAN JAYESH; TALAMAS CANO, DANIEL; LOUIE, JOHN; JOSHI, CHETAS; NOE, MATTHEW EDWARD
To: RUBRIK, INC.
Reel/Frame 052091/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2020
From: ARORA, GURJEET S.; BAVISHI, KARAN JAYESH; CANO, DANIEL TALAMAS; LOUIE, JOHN; JOSHI, CHETAS; NOE, MATTHEW EDWARD
To: RUBRIK, INC.
Reel/Frame 051848/0420 →
Continuity (1)
Related Publication 20200252264A1 · Aug 6, 2020