System and method for fault detection and root cause analysis in a network of network components
A system for error detection and troubleshooting analysis in a network consisting of a plurality of network components having software modules and communication interfaces and network nodes, which are connected to the network components by means of communication connections. The network components and/or the network nodes are designed to generate data, which are stored as a quantity of historical data, and to form event sequences from the quantity of historical data consisting of a sequence of events is provided. The system is designed to extract those event sequences from the event sequences which end with an alarm event (a), to extract relevant events in turn from said event sequences having an alarm event (a) for an error analysis and to construct reduced event sequences from the relevant events, and, for each reduced event sequence, to construct an automaton for detecting said reduced event sequence.
1. A system for fault detection and root cause analysis in a network comprising a plurality of network components with software modules and communication interfaces and network nodes which are connected to the plurality of network components by means of communication connections, wherein the plurality of network components and/or the network nodes are designed to generate data stored as a set of historical data and to form a plurality of event sequences each comprising a sequence of events from the set of historical data, wherein the system is designed:
to in turn extract event sequences which end with an alarm event from the plurality of event sequences;
to in turn extract relevant events based on a fault analysis from the event sequences with an alarm event and to construct reduced event sequences from the relevant events; and
to construct, for each of the reduced event sequences, an automaton for detecting each reduced event sequence, wherein the system is designed to combine the automaton constructed for the each of the reduced event sequences to form a common automaton for all of the reduced event sequences.
2. The system as claimed in claim 1 , wherein the system is designed to optimize the common automaton to form a deterministic automaton.
3. The system as claimed in claim 2 , wherein the system is designed to break down a state transition function of the deterministic automaton and to distribute the state transition function in the network.
4. The system as claimed in claim 3 , wherein the system is suitable for distributing a publish/subscribe protocol to one or more of the network nodes.
5. A method for fault detection and root cause analysis in a network comprising a plurality of network components with software modules and communication interfaces and network nodes which are connected to the network components by means of communication connections, wherein the network components and/or the network nodes generate data stored as a set of historical data and form general event sequences comprising a sequence of events from the set of historical data, comprising:
extracting event sequences which end with an alarm event from the general event sequences;
extracting relevant events for a fault analysis from the event sequences which end with an alarm event and constructing reduced event sequences comprising the relevant events; and
constructing, for each of the reduced event sequences, an automaton for detecting a reduced event sequence;
wherein the automation is combined to form a common automaton for all of the reduced event sequences.
6. The method as claimed in claim 5 , wherein the common automaton is optimized to form a deterministic automaton.
7. The method as claimed in claim 6 , wherein a state transition function of the deterministic automaton is broken down and is distributed in the network.
8. The method as claimed in claim 7 , wherein a publish/subscribe protocol is distributed to one or more of the network nodes.
9. A computer program product comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement the method as claimed in claim 5 .