Automated alert rationalization system to increase alert value through correlation of alerts
A computer-implemented method for incident management includes determining a plurality of groups of alert categories from an input of a plurality of alerts. A correlation for a pair of alert categories in at least one group from the plurality of groups of alert categories is determined. A cause-effect relationship or a peer relationship in the pair of alert categories is determined. A grouping rule is established based on the determined correlation, the determined cause-effect relationship, or the determined peer relationship.
1 . A computer-implemented method for incident management, the computer-implemented method comprising:
determining a plurality of groups of alert categories from an input of a plurality of unstructured multimodal incident resolution data, alerts data, and start times of alerts associated with the plurality of groups of alert categories;
determining a correlation for a pair of alert categories in at least one group from the plurality of groups of alert categories;
determining a cause-effect relationship or a peer relationship in the pair of alert categories based at least in part on the plurality of unstructured multimodal incident resolution data and the start times of the alerts;
estimating a time window for grouping of alerts in the pair of alert categories, wherein
the estimating of the time window is based on a plurality of time differences in a start time of a first alert of the alerts and a start time of a second alert of the alerts, and
the estimated time window is one of: a minimum of the plurality of time differences, or a median of the plurality of time differences; and
establishing a grouping rule for the alerts in the pair of alert categories based on:
the estimated time window, and
the determined correlation that includes the determined cause-effect relationship or the determined peer relationship.
2 . The computer-implemented method of claim 1 , wherein the input includes incident data that includes one or more of an alert category, an alert description, runbooks, images of metric trends, compressed files, or work notes.
3 . The computer-implemented method of claim 1 , wherein the alerts data includes:
alerts from anomalous logs and metrics; and
one or more of alert category, an alert description, or runbooks.
4 . The computer-implemented method of claim 1 , further comprising using the grouping rule in real-time in an automated alert rationalization system.
5 . A system, comprising:
a processor;
a data bus coupled to the processor;
a memory coupled to the data bus; and
a computer-usable medium embodying a computer program code, the computer program code comprising instructions executable by the processor to cause the processor to:
determine a plurality of groups of alert categories from an input of a plurality of unstructured multimodal incident resolution data, alerts data, and start times of alerts associated with the plurality of groups of alert categories;
determine a correlation for a pair of alert categories in at least one group from the plurality of groups of alert categories based at least in part on the plurality of unstructured multimodal incident resolution data and the start times of the alerts;
determine a cause-effect relationship or a peer relationship in the pair of alert categories;
estimate a time window for grouping of alerts in the pair of alert categories, wherein
the estimation of the time window is based on a plurality of time differences in a start time of a first alert of the alerts and a start time of a second alert of the alerts, and
the estimated time window is one of: a minimum of the plurality of time differences, or a median of the plurality of time differences; and
establish a grouping rule for the alerts in the pair of alert categories based on:
the estimated time window, and
the determined correlation that includes the determined cause-effect relationship or the determined peer relationship.
6 . The system of claim 5 , wherein:
the input includes incident data that includes one or more of an alert category, an alert description, runbooks, images of metric trends, compressed files, or work notes;
the alerts data includes alerts from anomalous logs and metrics; and
the alerts data further includes one or more of the alert category, the alert description, or the runbooks.
7 . The system of claim 5 , wherein the instructions further cause the processor to update the grouping rule based on the start times of the alerts in the pair of alert categories.
8 . The system of claim 5 , wherein the instructions further cause the processor to use the grouping rule in real-time in an automated alert rationalization system.
9 . A computer program product for incident management, the computer program product comprising a non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to:
determine a plurality of groups of alert categories from an input of a plurality of unstructured multimodal incident resolution data, alerts data, and start times of alerts associated with the plurality of groups of alert categories;
determine a correlation for a pair of alert categories in at least one group from the plurality of groups of alert categories based at least in part on the plurality of unstructured multimodal incident resolution data and the start times of the alerts;
determine a cause-effect relationship or a peer relationship in the pair of alert categories;
estimate a time window for grouping of alerts in the pair of alert categories, wherein
the estimation of the time window is based on a plurality of time differences in a start time of a first alert of the alerts and a start time of a second alert of the alerts, and
the estimated time window is one of: a minimum of the plurality of time differences, or a median of the plurality of time differences; and
establish a grouping rule for the alerts in the pair of alert categories based on:
the estimated time window, and
the determined correlation that includes the determined cause-effect relationship or the determined peer relationship.
10 . The computer program product of claim 9 , wherein:
the input includes incident data that includes one or more of an alert category, an alert description, runbooks, images of metric trends, compressed files, or work notes; and
the alerts data includes alerts from anomalous logs and metrics; and
the alerts data further includes the one or more of the alert category, the alert description, and the runbooks.