IP Library › Granted Patent US 10,361,935
Granted Patent B2
US 10,361,935 · App. 15/420,248 · Granted Jul 23, 2019

Probabilistic and proactive alerting in streaming data environments

Inventors: Yathiraj B. Udupi (San Jose, CA); Aparupa Das Gupta (San Jose, CA); Rahul Ramakrishna (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L43/08H04L41/147H04L41/16H04L41/5009
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,361,935
App. No.
15/420,248
Granted
Jul 23, 2019
Kind
B2
Abstract

In one embodiment, a device in a network aggregates values for a set of key performance indicators (KPIs) for a system the network to form a plurality of KPI states. The device associates a plurality of observed performance metric values from the system with the KPI states. The device constructs a machine learning-based decision tree. Internal vertices of the decision tree represent conditions for the plurality of observed performance metric values and leaves of the tree represent the KPI states. The device predicts a KPI state by using the machine learning-based decision tree to analyze live performance metric values streamed from the system. The device generates a proactive alert based on the predicted KPI state.

Claims (46)

1. A method comprising:

aggregating, by a device in a network, values for a set of key performance indicators (KPIs) for a system the network to form a plurality of KPI states;

associating, by the device, a plurality of observed performance metric values from the system with the KPI states;

constructing, by the device, a machine learning-based decision tree by using feature vectors associated with the plurality of KPI states, wherein internal vertices of the decision tree represent conditions for the plurality of observed performance metric values and leaves of the tree represent the KPI states;

predicting, by the device, a KPI state of the plurality of KPI states by using the machine learning-based decision tree to analyze live performance metric values streamed from the system, wherein the live performance metric values are associated with the predicted KPI state; and

generating, by the device, a proactive alert based on the predicted KPI state.

2. The method as in claim 1 , wherein the KPI states correspond to low, medium, and high states.

3. The method as in claim 1 , wherein the performance metric values comprise hardware resource consumption metrics for the system.

4. The method as in claim 1 , further comprising:

sending, by the device, the proactive alert to a user interface via the network.

5. The method as in claim 1 , wherein predicting the KPI state by using the machine learning-based decision tree to analyze the live performance metric values streamed from the system comprises:

traversing, by the device, a path in the decision tree having vertices that correspond to the live performance metric values and having a leaf that corresponds to the predicted KPI state.

6. The method as in claim 5 , wherein the path comprises at least one vertex that does not correspond to at least one of the live performance metric values.

7. The method as in claim 6 , wherein the proactive alert is generated based in part on the number of vertices in the path that correspond to the live performance metric values.

8. The method as in claim 5 , further comprising:

using, by the device, the live performance metric values to predict future performance metric values; and

comparing, by the device, the predicted future performance metric values with the vertices of the path of the decision tree.

9. The method as in claim 1 , wherein the KPI indicates at least one of: a page response time, an application program interface (API) response time, or an average latency of the system.

10. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute a process; and

a memory configured to store the process executable by the processor, the process when executed operable to:

aggregate values for a set of key performance indicators (KPIs) for a system the network to form a plurality of KPI states;

associate a plurality of observed performance metric values from the system with the KPI states;

construct a machine learning-based decision tree by using feature vectors associated with the plurality of KPI states, wherein internal vertices of the decision tree represent conditions for the plurality of observed performance metric values and leaves of the tree represent the KPI states;

predict a KPI state of the plurality of KPI states by using the machine learning-based decision tree to analyze live performance metric values streamed from the system, wherein the live performance metric values are associated with the predicted KPI state; and

generate a proactive alert based on the predicted KPI state.

11. The apparatus as in claim 10 , wherein the KPI states correspond to low, medium, and high states.

12. The apparatus as in claim 10 , wherein the performance metric values comprise hardware resource consumption metrics for the system.

13. The apparatus as in claim 10 , wherein the process when executed is further operable to:

send the proactive alert to a user interface via the network.

14. The apparatus as in claim 10 , wherein the apparatus predicts the KPI state by:

traversing a path in the decision tree having vertices that correspond to the live performance metric values and having a leaf that corresponds to the predicted KPI state.

15. The apparatus as in claim 14 , wherein the path comprises at least one vertex that does not correspond to at least one of the live performance metric values.

16. The apparatus as in claim 15 , wherein the proactive alert is generated based in part on the number of vertices in the path that correspond to the live performance metric values.

17. The apparatus as in claim 14 , wherein the process when executed is further operable to:

use the live performance metric values to predict future performance metric values; and

compare the predicted future performance metric values with the vertices of the path of the decision tree.

18. The apparatus as in claim 10 , wherein the KPI indicates at least one of: a page response time, an application program interface (API) response time, or an average latency of the system.

19. A tangible, non-transitory, computer-readable medium storing program instructions that, when executed by a device in a network, cause the device to perform a process comprising:

aggregating, by the device, values for a set of key performance indicators (KPIs) a system the network to form a plurality of KPI states;

associating, by the device, a plurality of observed performance metric values from the system with the KPI states;

constructing, by the device, a machine learning-based decision tree by using feature vectors associated with the plurality of KPI states, wherein internal vertices of the decision tree represent conditions for the plurality of observed performance metric values and leaves of the tree represent the KPI states;

predicting, by the device, a KPI state of the plurality of KPI states by using the machine learning-based decision tree to analyze live performance metric values streamed from the system, wherein the live performance metric values are associated with the predicted KPI state; and

generating, by the device, a proactive alert based on the predicted KPI state.

20. The computer-readable medium as in claim 19 , wherein the KPI states correspond to low, medium, and high states.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2017
From: UDUPI, YATHIRAJ B.; DAS GUPTA, APARUPA; RAMAKRISHNA, RAHUL
To: CISCO TECHNOLOGY, INC.
Reel/Frame 041131/0147 →
Continuity (1)
Related Publication 20180219754A1 · Aug 2, 2018
Cited By (2)
US 12,212,988 US 12,713,259