IP Library Granted Patent US 12,640,979
Granted Patent B2
US 12,640,979 · App. 18/536,084 · Granted May 26, 2026

Automated alert rationalization system to increase alert value through correlation of alerts

Inventors: Anupama Jagannathan (Yorktown Heights, NY); Karthick Rajamani (Austin, TX); Christopher M. Dye (Encinitas, CA); Benjamin Luong (Toronto, CA)
Assignee: International Business Machines Corporation
H04L41/065H04L41/0627
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,640,979
App. No.
18/536,084
Granted
May 26, 2026
Kind
B2
Abstract

A computer-implemented method for incident management includes determining a plurality of groups of alert categories from an input of a plurality of alerts. A correlation for a pair of alert categories in at least one group from the plurality of groups of alert categories is determined. A cause-effect relationship or a peer relationship in the pair of alert categories is determined. A grouping rule is established based on the determined correlation, the determined cause-effect relationship, or the determined peer relationship.

Claims (49)

1 . A computer-implemented method for incident management, the computer-implemented method comprising:

determining a plurality of groups of alert categories from an input of a plurality of unstructured multimodal incident resolution data, alerts data, and start times of alerts associated with the plurality of groups of alert categories;

determining a correlation for a pair of alert categories in at least one group from the plurality of groups of alert categories;

determining a cause-effect relationship or a peer relationship in the pair of alert categories based at least in part on the plurality of unstructured multimodal incident resolution data and the start times of the alerts;

estimating a time window for grouping of alerts in the pair of alert categories, wherein

the estimating of the time window is based on a plurality of time differences in a start time of a first alert of the alerts and a start time of a second alert of the alerts, and

the estimated time window is one of: a minimum of the plurality of time differences, or a median of the plurality of time differences; and

establishing a grouping rule for the alerts in the pair of alert categories based on:

the estimated time window, and

the determined correlation that includes the determined cause-effect relationship or the determined peer relationship.

2 . The computer-implemented method of claim 1 , wherein the input includes incident data that includes one or more of an alert category, an alert description, runbooks, images of metric trends, compressed files, or work notes.

3 . The computer-implemented method of claim 1 , wherein the alerts data includes:

alerts from anomalous logs and metrics; and

one or more of alert category, an alert description, or runbooks.

4 . The computer-implemented method of claim 1 , further comprising using the grouping rule in real-time in an automated alert rationalization system.

5 . A system, comprising:

a processor;

a data bus coupled to the processor;

a memory coupled to the data bus; and

a computer-usable medium embodying a computer program code, the computer program code comprising instructions executable by the processor to cause the processor to:

determine a plurality of groups of alert categories from an input of a plurality of unstructured multimodal incident resolution data, alerts data, and start times of alerts associated with the plurality of groups of alert categories;

determine a correlation for a pair of alert categories in at least one group from the plurality of groups of alert categories based at least in part on the plurality of unstructured multimodal incident resolution data and the start times of the alerts;

determine a cause-effect relationship or a peer relationship in the pair of alert categories;

estimate a time window for grouping of alerts in the pair of alert categories, wherein

the estimation of the time window is based on a plurality of time differences in a start time of a first alert of the alerts and a start time of a second alert of the alerts, and

the estimated time window is one of: a minimum of the plurality of time differences, or a median of the plurality of time differences; and

establish a grouping rule for the alerts in the pair of alert categories based on:

the estimated time window, and

the determined correlation that includes the determined cause-effect relationship or the determined peer relationship.

6 . The system of claim 5 , wherein:

the input includes incident data that includes one or more of an alert category, an alert description, runbooks, images of metric trends, compressed files, or work notes;

the alerts data includes alerts from anomalous logs and metrics; and

the alerts data further includes one or more of the alert category, the alert description, or the runbooks.

7 . The system of claim 5 , wherein the instructions further cause the processor to update the grouping rule based on the start times of the alerts in the pair of alert categories.

8 . The system of claim 5 , wherein the instructions further cause the processor to use the grouping rule in real-time in an automated alert rationalization system.

9 . A computer program product for incident management, the computer program product comprising a non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to:

determine a plurality of groups of alert categories from an input of a plurality of unstructured multimodal incident resolution data, alerts data, and start times of alerts associated with the plurality of groups of alert categories;

determine a correlation for a pair of alert categories in at least one group from the plurality of groups of alert categories based at least in part on the plurality of unstructured multimodal incident resolution data and the start times of the alerts;

determine a cause-effect relationship or a peer relationship in the pair of alert categories;

estimate a time window for grouping of alerts in the pair of alert categories, wherein

the estimation of the time window is based on a plurality of time differences in a start time of a first alert of the alerts and a start time of a second alert of the alerts, and

the estimated time window is one of: a minimum of the plurality of time differences, or a median of the plurality of time differences; and

establish a grouping rule for the alerts in the pair of alert categories based on:

the estimated time window, and

the determined correlation that includes the determined cause-effect relationship or the determined peer relationship.

10 . The computer program product of claim 9 , wherein:

the input includes incident data that includes one or more of an alert category, an alert description, runbooks, images of metric trends, compressed files, or work notes; and

the alerts data includes alerts from anomalous logs and metrics; and

the alerts data further includes the one or more of the alert category, the alert description, and the runbooks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2023
From: JAGANNATHAN, ANUPAMA; RAJAMANI, KARTHICK; DYE, CHRISTOPHER M.; LUONG, BENJAMIN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 065833/0652 →
Continuity (1)
Related Publication 20250193067A1 · Jun 12, 2025
References Cited (14)
US 10007716B2 · Tee · 2018 [cited by applicant]
US 10346851B1 · Kapoor · 2019 [cited by applicant]
US 10447525B2 · Patrich · 2019 [cited by applicant]
US 10936822B2 · Ganesan · 2021 [cited by applicant]
US 11165631B1 · Chitalia · 2021 [cited by applicant]
US 20190340241A1 · Ganesan · 2019 [cited by examiner]
US 20200067798A1 · Kalia · 2020 [cited by applicant]
US 20200372367A1 · Ha · 2020 [cited by examiner]
US 20210326744A1 · Israel · 2021 [cited by examiner]
CN 112685247A · 2021 [cited by applicant]
WO WO2021215720A1 · 2021 [cited by examiner]
Taherizadeh, S. et al., “A Semantic Model for Interchangeable Microservices in Cloud Continuum Computing”, Information (2021), vol. 12:40, 22 pgs. [cited by applicant]
Taherizadeh, S. et al., “Monitoring self-adaptive applications within edge computing frameworks: A state-of-the-art review”, The Journal of Systems and Software (2018), vol. 136, pp. 19-38. [cited by applicant]
Corici, M. et al., “Practical Performance Degradation Mitigation Solution using Anomaly Detection for Carrier-Grade Software Networks”, 2018 IEEE Conference on Standards for Communications and Networking (CSCN) (2018), … [cited by applicant]