WO2025013003A1 - System and method for enrichment of network alarms - Google Patents
System and method for enrichment of network alarms Download PDFInfo
- Publication number
- WO2025013003A1 WO2025013003A1 PCT/IN2024/051033 IN2024051033W WO2025013003A1 WO 2025013003 A1 WO2025013003 A1 WO 2025013003A1 IN 2024051033 W IN2024051033 W IN 2024051033W WO 2025013003 A1 WO2025013003 A1 WO 2025013003A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- enrichment
- network
- alarm
- logical
- physical
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0631—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0686—Additional information in the notification, e.g. enhancement of specific meta-data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/085—Retrieval of network configuration; Tracking network configuration history
- H04L41/0853—Retrieval of network configuration; Tracking network configuration history by actively collecting configuration information or by backing up configuration information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0893—Assignment of logical groups to network elements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/069—Management of faults, events, alarms or notifications using logs of notifications; Post-processing of notifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0895—Configuration of virtualised networks or elements, e.g. virtualised network function or OpenFlow elements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/12—Discovery or management of network topologies
- H04L41/122—Discovery or management of network topologies of virtualised topologies, e.g. software-defined networks [SDN] or network function virtualisation [NFV]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/08—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
- H04L43/0805—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability
- H04L43/0817—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability by checking functioning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/20—Arrangements for monitoring or testing data switching networks the monitoring system or the monitored elements being virtualised, abstracted or software-defined entities, e.g. SDN or NFV
Definitions
- the present invention generally relates to the field of network management and, more specifically, to a system and method for alarm enrichment, in a communication network.
- alarms are generated by network nodes to signal various events or conditions that require attention from network administrators or operators. These alarms typically contain valuable information presented in the form of attributes, providing critical details about the events and the nodes involved.
- One or more embodiments of the present disclosure provide a system and method for performing enrichment of network alarms.
- a system for performing enrichment of network alarms includes a collector component configured to receive an alarm raised by a node for an event.
- the alarm comprises one or more attributes indicating a hardware, software, or network issue associated with the node.
- the system includes a fault processor configured to identify eligibility of the alarm for at least one of physical enrichment and logical enrichment. The eligibility is determined based on physical placement related attributes included in the alarm.
- the fault processor is also configured to perform, based on the eligibility, at least one of the physical enrichment and the logical enrichment of the alarm.
- the physical enrichment attributes comprise device location, device type, interface details, serial numbers, rack or cabinet number, power supply status, temperature and environmental conditions, device health and status, software and firmware versions, and connectivity information.
- the logical enrichment attributes comprise Internet Protocol (IP) address, routing protocols, virtual local area network (VLAN) configurations, network topology, virtual network configurations, network service mappings, logical relationships between network elements, network policies, and access control lists (ACLs).
- IP Internet Protocol
- the physical enrichment involves including static data of the node within the alarm
- the logical enrichment includes involves including contextual information related to network protocols, routing, virtual configurations, and logical relationships between network elements into the alarm.
- the fault processor performs the physical enrichment and the logical enrichment by collecting attributes by traversing across levels of an inventory provisioned for the node in an inventory database, and appending the attributes into the alarm.
- a Network Management System (NMS) database stores enrichment data collected during one or more of the physical enrichment and the logical enrichment.
- the fault processor checks availability of the enrichment data in the NMS database prior to performing at least one of the physical enrichment and the logical enrichment of the alarm.
- the fault processor fetches the enrichment data for performing at least one of the physical enrichment and the logical enrichment of the alarm.
- a predefined time period is associated with the enrichment data, and after expiration of the predefined time period, the enrichment data becomes unusable.
- a method of performing enrichment of network alarms includes the step of receiving an alarm raised by a node for an event.
- the alarm comprising one or more attributes indicating a hardware, software, or network issue associated with the node.
- the method further includes the step of identifying eligibility of the alarm for at least one of physical enrichment and logical enrichment. The eligibility is determined based on physical placement related attributes included in the alarm.
- the method further includes the step of performing at least one of the physical enrichment and the logical enrichment of the alarm, based on the eligibility.
- the physical enrichment attributes comprise device location, device type, interface details, serial numbers, rack or cabinet number, power supply status, temperature and environmental conditions, device health and status, software and firmware versions, and connectivity information.
- the logical enrichment attributes comprise Internet Protocol (IP) address, routing protocols, virtual local area network (VLAN) configurations, network topology, virtual network configurations, network service mappings, logical relationships between network elements, network policies, and access control lists (ACLs).
- IP Internet Protocol
- VLAN
- the physical enrichment involves including static data of the node within the alarm
- the logical enrichment includes involves including contextual information related to network protocols, routing, virtual configurations, and logical relationships between network elements into the alarm.
- the fault processor performs the physical enrichment and the logical enrichment by collecting attributes by traversing across levels of an inventory provisioned for the node in an inventory database, and appending the attributes into the alarm.
- a Network Management System (NMS) database stores enrichment data collected during one or more of the physical enrichment and the logical enrichment.
- the fault processor checks availability of the enrichment data in the NMS database prior to performing at least one of the physical enrichment and the logical enrichment of the alarm.
- the fault processor fetches the enrichment data for performing at least one of the physical enrichment and the logical enrichment of the alarm.
- a predefined time period is associated with the enrichment data, and after expiration of the predefined time period, the enrichment data becomes unusable.
- FIG. 1 illustrates a network architecture of a system for enrichment of network alarms, according to one or more embodiments of the present disclosure
- FIG. 2 illustrates a block diagram of the system for enrichment of network alarms, according to various embodiments of the present system
- FIG. 3 illustrates a block diagram of the system and a node communicating with each other for enrichment of alarms, according to various embodiments of the present system
- FIG. 4 illustrates a system operation architecture for enrichment of alarms, according to one or more embodiments of the present disclosure
- FIG. 5 illustrates a flow chart of a method of performing enrichment of alarms, according to one or more embodiments of the present disclosure.
- the proposed invention introduces a novel approach of enriching alarms received at a fault processor with both dynamic and static data.
- the static data refers to information related to the physical attributes of the network infrastructure, while the dynamic data represents the real-time aspects of the alarm event.
- Present invention exhibits technical advancement of implementing a profile-based inventory level traversal. This method involves traversing the network inventory based on predefined profiles to collect the static data for physical enrichment.
- the static data includes details such as physical placement, location, interfaces, and other relevant attributes of the network nodes.
- the invention introduces a profile-based eligibility evaluation process for logical enrichment. Based on the physical enrichment data obtained, the alarm's eligibility for logical enrichment is determined. Logical enrichment involves incorporating contextual information related to network protocols, routing, virtual configurations, and logical relationships between network elements. If the alarm is found eligible for logical enrichment, similar profile -based traversal techniques are applied to collect the necessary data. This logical enrichment data is then combined with the previously enriched alarm, further enhancing the understanding of the alarm event and its impact on the logical aspects of the network.
- the proposed invention enables more effective fault analysis, troubleshooting, and network management within the NMS.
- the comprehensive information provided by the enrichment processes allows network administrators to quickly identify the root causes of alarms, accurately assess their impact, and take appropriate actions for resolution.
- the invention can be implemented in a server-based network management system, where various modules collaborate for enrichment of the alarms.
- the inventive step lies in cache based enrichment of alarms.
- the physical and logical enrichment for an alarm is performed based on cached data corresponding to the alarm which is stored in a database (DB) of the NMS.
- DB database
- FIG. 1 illustrates a network architecture of a system for enrichment of network alarms.
- the network architecture comprises a plurality of network nodes 102-1, 102-2, ,102-n. At least one of the network nodes 102-1 through 102-n may be configured to connect to a server 105.
- a network node whose network alarm is enriched is referred as node 102.
- the node 102 may comprise a memory such as a volatile memory (e.g., RAM), a non-volatile memory (e.g., disk memory, FLASH memory, EPROMs, etc.), an unalterable memory, and/or other types of memory.
- the memory might be configured or designed to store data.
- the node 102 may connect with the server 105 for sending alarms.
- the node 102 may be configured to connect with the server 105 through a communication network 110.
- the communication network 110 may use one or more communication interfaces/protocols such as, for example, VoIP, 802.11 (Wi-Fi), 802.15 (including BluetoothTM), 802.16 (Wi-Max), 802.22, Cellular standards such as CDMA, CDMA2000, WCDMA, Radio Frequency (e.g., RFID), Infrared, laser, Near Field Magnetics, etc.
- VoIP Voice over IP
- Wi-Fi Wi-Fi
- 802.15 including BluetoothTM
- 802.16 Wi-Max
- 802.22 Cellular standards such as CDMA, CDMA2000, WCDMA, Radio Frequency (e.g., RFID), Infrared, laser, Near Field Magnetics, etc.
- RFID Radio Frequency
- the server 105 may include by way of example but not limitation, one or more of a standalone server, a server blade, a server rack, a bank of servers, a business telephony application server (BTAS), a server farm, hardware supporting a part of a cloud service or system, a home server, hardware running a virtualized server, one or more processors executing code to function as a server, one or more machines performing server-side functionality as described herein, at least a portion of any of the above, some combination thereof.
- the entity may include, but is not limited to, a vendor, a network operator, a company, an organization, a university, a lab facility, a business enterprise, a defence facility, or any other facility that provides content.
- the server 105 may be communicably connected to a system 125, via the communication network 110.
- the system 125 may be configured to access services subscribed by enterprises, and additional services as mentioned above.
- the plurality of nodes 102 may include end devices and intermediary devices.
- the end devices serve as originator of data or information flowing through the communication network 110.
- the end devices may include workstations, laptops, desktop computers, printers, scanners, servers (file servers, web Servers), mobile phones, tablets, and smart phones.
- the intermediary devices are configured to forward data from one point to another in a communication network 110.
- the intermediary devices may include hubs, modems, switches, routers, bridges, repeaters, security firewalls, and wireless access points.
- the communication network 110 includes, by way of example but not limitation, one or more of a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet-switched network, a circuit- switched network, an ad hoc network, an infrastructure network, a Public-Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.
- PSTN Public-Switched Telephone Network
- the communication network 110 may include, but is not limited to, a Third Generation (3G), a Fourth Generation (4G), a Fifth Generation (5G), a Sixth Generation (6G), a New Radio (NR), a Narrow Band Internet of Things (NB-IoT), an Open Radio Access Network (O- RAN), and the like.
- 3G Third Generation
- 4G Fourth Generation
- 5G Fifth Generation
- 6G Sixth Generation
- NR New Radio
- NB-IoT Narrow Band Internet of Things
- O- RAN Open Radio Access Network
- the communication network 110 may also include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth.
- the network may also include, by way of example but not limitation, one or more of a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet- switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public-Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, a VOIP or some combination thereof.
- PSTN Public-Switched Telephone Network
- the system 125 (alternatively referred as a Network Management system (NMS) 125) is communicably coupled to the server 105 and each of the first node 102-1, the second node 102-2, and the third node 102-n via the communication network 110.
- the system 125 is configured to handle repetitive alarms and auditing.
- the system 125 is adapted to be embedded within the server 105 or is embedded as an individual entity. However, for the purpose of description, the system 125 is described as an integral part of the server 105, without deviating from the scope of the present disclosure.
- the system 125 may be generic in nature and may be integrated with any application including a System Management Facility (SMF), an Access and Mobility Management Function (AMF), a Business Telephony Application Server (BTAS), a Converged Telephony Application Server (CTAS), any SIP (Session Initiation Protocol) Application Server which interacts with core Internet Protocol Multimedia Subsystem (IMS) on Industrial Control System (ISC) interface as defined by Third Generation Partnership Project (3 GPP) to host a wide array of cloud telephony enterprise services, a System Information Blocks (SIB)/ and a Mobility Management Entity (MME).
- SIF System Management Facility
- AMF Access and Mobility Management Function
- BTAS Business Telephony Application Server
- CAS Converged Telephony Application Server
- IMS Internet Protocol Multimedia Subsystem
- ISC Industrial Control System
- SIB System Information Blocks
- MME Mobility Management Entity
- System Management Facility is an IBM z/OS component that collects, formats, and records system and job -related information for monitoring, auditing, and performance analysis purposes. It serves as a central repository for various types of operational data generated by the z/OS operating system and related subsystems.
- Access and Mobility Management Function is a key component in 5G mobile networks, responsible for managing access to the network and handling mobility-related functions for user equipment (UE), such as smartphones, tablets, and loT devices.
- AMF works closely with other network functions to facilitate seamless connectivity, mobility, and quality of service for mobile users.
- BTAS Business Telephony Application Server
- IVR interactive voice response
- Converged Telephony Application Server is a server-based system that integrates various telephony and communication services into a single platform, enabling businesses to streamline their communication infrastructure and offer a wide range of communication features. CTAS combines traditional telephony services with advanced IP -based communication capabilities to provide a unified and cohesive communication experience.
- SIP (Session Initiation Protocol) application server is a server -based system that facilitates the establishment, management, and termination of communication sessions using the SIP protocol. SIP application servers play a central role in IPbased telecommunications networks, enabling a wide range of real-time communication services, including voice calls, video calls, instant messaging, presence, and multimedia conferencing.
- IMS Internet Protocol Multimedia Subsystem
- Cloud telephony enterprise services refer to communication solutions delivered over the cloud that cater specifically to the needs of businesses and organizations. These services leverage cloud technology to provide scalable, flexible, and cost-effective communication solutions, including voice calls, messaging, collaboration tools, and contact center capabilities.
- SIBs System Information Blocks
- a base station eNodeB in LTE, NodeB in UMTS, or eNB in 5G
- SIBs contain network-related information necessary for UEs to access and operate within the network efficiently. These blocks are periodically transmitted over broadcast channels, allowing UEs to receive and decode them even when they are not actively engaged in communication.
- the Mobility Management Entity is a key network element responsible for managing mobility-related functions for user equipment (UE) or mobile devices.
- the MME is part of the Evolved Packet Core (EPC) network in LTE and the 5G Core (5GC) network in 5G, serving as a control plane entity that handles signaling and control procedures for mobility management.
- EPC Evolved Packet Core
- 5GC 5G Core
- Operational and construction features of the system 125 will be explained in detail successively with respect to different figures.
- FIG. 2 illustrates a block diagram of the system 125 for enrichment of network alarms, according to one or more embodiments of the present disclosure.
- the system 125 includes one or more processors 205, a memory 210, and an input/output interface unit 215.
- the one or more processors 205 may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, state machines, logic circuitries, single board computers, and/or any devices that manipulate signals based on operational instructions.
- the system 125 includes the processor 205.
- the system 125 may include multiple processors as per the requirement and without deviating from the scope of the present disclosure.
- the processor 205 is configured to fetch and execute computer-readable instructions stored in the memory 210.
- the memory 210 may be configured to store one or more computer-readable instructions or routines in a non-transitory computer-readable storage medium, which may be fetched and executed to create or share data packets over a network service.
- the memory 210 may include any non-transitory storage device including, for example, volatile memory such as RAM, or non-volatile memory such as EPROM, flash memory, and the like.
- the input/output (I/O) interface unit 215 includes a variety of interfaces, for example, interfaces for data input and output devices, referred to as Input/Output (RO) devices, storage devices, and the like.
- the I/O interface unit 215 facilitates communication of the system 125.
- the I/O interface unit 215 provides a communication pathway for one or more components of the system 125. Examples of such components include, but are not limited to, the nodes 102, an NMS database 220, and a distributed cache 225.
- the NMS database 220 is one of, but is not limited to, a centralized database, a cloud-based database, a commercial database, an open-source database, a distributed database, an end-user database, a graphical database, a No-Structured Query Language (NoSQL) database, an object-oriented database, a personal database, an in-memory database, a document-based database, a time series database, a wide column database, a key value database, a search database, a cache database, and so forth.
- NoStructured Query Language (NoSQL) database No-Structured Query Language
- object-oriented database a personal database
- an in-memory database a document-based database
- a time series database a time series database
- a wide column database a key value database
- search database a cache database
- the distributed cache 225 is a pool of Random- Access Memory (RAM) of multiple networked computers into a single in-memory data store for use as a data cache to provide fast access to data.
- RAM Random- Access Memory
- the distributed cache 225 is essential for applications that need to scale across multiple servers or are distributed geographically.
- the distributed cache 225 ensures that data is available close to where it’s needed, even if the original data source is remote or under heavy load.
- the processor 205 in an embodiment, may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processor 205.
- programming for the processor 205 may be processor-executable instructions stored on a non-transitory machine-readable storage medium and the hardware for the processor 205 may comprise a processing resource (for example, one or more processors), to execute such instructions.
- the memory 210 may store instructions that, when executed by the processing resource, implement the processor 205.
- the system 125 may comprise the memory 210 storing the instructions and the processing resource to execute the instructions, or the memory 210 may be separate but accessible to the system 125 and the processing resource.
- the processor 205 may be implemented by electronic circuitry. [0050]
- the processor 205 includes a collector component 228 and a fault processor 230 communicably coupled to each other.
- the collector component 228 of the processor 205 is communicably connected to each of the first node 102-1, the second node 102-2, and the third node 102-n via the communication network 110. Accordingly, the collector component 228 is configured to receive an alarm raised by the node 102 for an event.
- the alarm comprises one or more attributes indicating a hardware, software, or network issue associated with the node 102.
- the fault processor 230 identifies eligibility of the alarm for at least one of physical enrichment and logical enrichment. The eligibility is determined based on physical placement related attributes included in the alarm. Further, the fault processor 230 performs at least one of the physical enrichment and the logical enrichment of the alarm, based on the eligibility of the alarm.
- the physical enrichment involves including static data of the node within the alarm.
- the logical enrichment includes involves including contextual information related to network protocols, routing, virtual configurations, and logical relationships between network elements into the alarm.
- the physical enrichment and the logical enrichment is performed by collecting attributes by traversing across levels of an inventory provisioned for the node in an inventory database 408, and appending the attributes into the alarm.
- the NMS database 220 of the system 125 serves as a non-structured (NoSQL) database that stores the enrichment data collected during one or more of the physical enrichment and the logical enrichment.
- NoSQL non-structured
- the database 220 plays a crucial role in persistently storing and managing the enrichment data, ensuring its availability for enrichment of the alarms.
- FIG. 3 illustrating a block diagram of the system 125 and the first node 102-1 communicating with each other for enrichment of alarms
- a preferred embodiment of the system 125 is described. It is to be noted that the embodiment with respect to FIG. 3 will be explained with respect to the first node 102-1 for the purpose of description and illustration and should nowhere be construed as limited to the scope of the present disclosure.
- the first node 102-1 includes one or more primary processors 305 communicably coupled to the processor 205 of the system 125.
- the one or more primary processors 305 are coupled with a memory unit 310 storing instructions which are executed by the one or more primary processors 305. Execution of the stored instructions by the one or more primary processors 305 enables the first node 102-1 to provide an alarm corresponding to an event.
- the first node 102-1 further includes a kernel 315 which is a core component serving as the primary interface between hardware components of the first network device 110a and the plurality of services at the NMS database 220.
- the kernel 315 is configured to provide the plurality of services on the first node 102-1 to resources available in the communication network 110.
- the resources include one of a Central Processing Unit (CPU), memory components such as Random Access Memory (RAM) and Read Only Memory (ROM).
- CPU Central Processing Unit
- RAM Random Access Memory
- ROM Read Only Memory
- the collector component 228 of the processor 205 is communicably connected to the kernel 315 of the first node 102-1.
- the collector component 228 is configured to collect the alarms corresponding to network events.
- the alarms comprise alarm comprise one or more attributes indicating a hardware, software, or network issue associated with the node first node 102-1.
- the processor 205 further include the fault processor 230 communicably connected to the collector component 228 to identify eligibility of the alarm for at least one of physical enrichment and logical enrichment. The eligibility is determined based on physical placement related attributes included in the alarm.
- the fault processor 230 performs at least one of the physical enrichment and the logical enrichment of the alarm, the physical enrichment and the logical enrichment is performed by collecting attributes by traversing across levels of an inventory provisioned for the node in an inventory database 408, and appending the attributes into the alarm.
- the physical enrichment involves including static data of the node within the alarm
- the logical enrichment includes involves including contextual information related to network protocols, routing, virtual configurations, and logical relationships between network elements into the alarm.
- the physical enrichment attributes comprise a device location, device type, interface details, serial numbers, rack or cabinet number, power supply status, temperature and environmental conditions, device health and status, software and firmware versions, and connectivity information.
- the logical enrichment attributes comprise Internet Protocol (IP) address, routing protocols, virtual local area network (VLAN) configurations, network topology, virtual network configurations, network service mappings, logical relationships between network elements, network policies, and access control lists (ACLs).
- IP Internet Protocol
- VLAN virtual local area network
- ACLs access control
- IP address is a numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication. It serves two main purposes: identifying the host or network interface and providing the location of the device in the network.
- IPv4 which consists of four sets of numbers separated by periods (e.g., 192.0.2.1)
- IPv6 which uses a longer hexadecimal format (e.g., 2001:0db8:85a3:0000:0000:8a2e:0370:7334).
- IP addresses are essential for devices to communicate with each other over the internet.
- Routing protocols are a set of rules or algorithms that determine the best path for data packets to travel from one network to another in a computer network. These protocols are essential for routers to exchange information and make decisions about how to forward data across interconnected networks. A few common routing protocols include Distance Vector Routing Protocol, Link-State Routing Protocol, Hybrid Routing Protocol, and Border Gateway Protocol.
- VLAN Virtual Local Area Network
- VLANs allow you to segment your network logically, even if devices physically connect to the same switch or router.
- Network topology refers to the physical or logical layout of a computer network. It defines how devices such as computers, servers, switches, routers, and other peripherals are interconnected and how data flows between them.
- a few common network topologies include star topology, bus topology, ring topology, mesh topology, and tree topology.
- Virtual network configurations involve setting up and managing virtual networks within a physical network infrastructure. These virtual networks operate independently of the physical hardware, allowing for greater flexibility, scalability, and resource optimization.
- Network service mapping is the process of identifying and documenting the relationships and dependencies between network services and the underlying IT infrastructure components that support them. This mapping provides a visual representation of how various services are interconnected and how they rely on specific hardware, software, and configurations within the network.
- Logical relationships between network elements refer to the connections and dependencies that exist between various components in a network at a conceptual or logical level. These relationships define how data flows, how devices communicate, and how services are delivered within the network.
- Network policies are sets of rules, guidelines, and procedures that govern how a network is managed, configured, secured, and used. These policies define the acceptable use of network resources, establish security measures, and outline procedures for network administration. A few common types of network policies include Acceptable user policy, security policy, access control policy, data retention policy, and network configuration policy.
- the NMS database 220 of the system 125 stores the enrichment data collected during one or more of the physical enrichment and the logical enrichment.
- the fault processor 230 checks availability of the enrichment data in the NMS database 220 prior to performing at least one of the physical enrichment and the logical enrichment of the alarm. In case the enrichment data is identified to be present, the fault processor 230 fetches the enrichment data for performing at least one of the physical enrichment and the logical enrichment of the alarm.
- the enrichment data can also be associated with an expiry time i.e. predefined time period so that the enrichment data cannot be used post expiration of the predefined time period.
- FIG. 4 illustrates a system operation architecture for enrichment of alarms, according to one or more embodiments of the present disclosure.
- the collector component (labelled as collector) 228 receives alarms corresponding to network events from a node 102.
- the collector component 228 passes the alarm to the fault processor 230 in a data stream.
- the fault processor 230 determines if enrich cache for the node 102 is enabled or not, at block 402. If identified to be enabled, the fault processor 230 performs cached enrichment, at block 404. To perform cached enrichment, the fault processor 230 fetches enrichment data corresponding to the node 102 from the NMS database (NMS D/B) 220.
- the enrichment data includes physical enrichment attributes and logical enrichment attributes.
- an enrichment processor 406 performs physical enrichment using a node profile or a global profile (when node profile is not available) stored in an inventory to obtain physical enrichment parameters. Subsequently, if the alarm is identified to be eligible for logical enrichment, logical enrichment is also performed using the inventory and one or more physical enrichment attributes to obtain the logical enrichment attributes.
- the physical enrichment attributes and the logical enrichment attributes are provided as enrichment data to the fault processor 230.
- the fault processor 230 uses the enrichment data to obtain an enriched alarm.
- the fault processor 230 also stores the enriched alarm in the NMS database 220.
- the enriched alarm or the enrichment data may be stored along with a timer (predefined time period) for future cached enrichment processing.
- FIG. 5 illustrates a flow chart of a method 500 of performing enrichment of alarms, according to one or more embodiments of the present disclosure.
- the method 500 is described with the embodiments as illustrated in FIGS. 1 and 4 and should nowhere be construed as limiting the scope of the present disclosure.
- the method 500 includes the step of receiving an alarm corresponding to a network event, by a processor.
- the alarm may include dynamic data and alarm data.
- the alarm data refers to information generated by network devices or systems to indicate abnormal or noteworthy events, conditions, or failures within the network infrastructure. Such alarms are generated in response to predefined conditions or thresholds being met, signaling potential issues that require attention from network administrators or automated systems.
- a collector of a network management system may receive the alarm from a node and may pass the alarm in a data stream to a fault processor.
- the method 500 includes the step of determining whether cached enrichment is enabled or not.
- the fault processor checks availability of enrichment data corresponding to the node and a related timer.
- the enrichment data may include physical enrichment attributes and logical enrichment attributes associated with a node, stored in an NMS database.
- a configurable predefined timer is used. For example, where the corresponding enrichment data is available in the NMS DB and where the timer is less than 24 hours, the method may proceed to step 515.
- the method 500 includes the step of performing physical enrichment and logical enrichment of the alarm based on cached enrichment data corresponding to the alarm stored in the NMS database.
- enrichment data including physical enrichment attributes and logical enrichment attributes corresponding to the node are fetched from a cached storage of the NMS database.
- the alarm is enriched using the enrichment data.
- the method may proceed to step 520.
- the method 500 includes the step of performing physical enrichment of the alarm using an inventory based on a set of predefined parameters to obtain physical enrichment attributes.
- the physical enrichment attributes may include device location, device type, interface details, serial numbers, rack or cabinet number, power supply status, temperature and environmental conditions, device health and status, software and firmware versions, and connectivity information.
- the inventory may include a plurality of node profiles associated with a plurality of nodes that are registered with the NMS.
- the profile configurations can be changed in runtime and are readily applicable.
- the profiles which define the specific criteria and rules for inventory level traversal, can be modified dynamically during system operation.
- the ability to change profiles in runtime allows for immediate adjustments to the alarm processing flow based on evolving network conditions or management requirements.
- the changes made to the profiles take effect immediately, ensuring that the system adapts swiftly to varying scenarios.
- index and record type particulars for each level traversal in the inventory database are also maintained.
- the system traverses each inventory level during the alarm processing flow, it maintains the necessary information about the index and record types associated with that particular level. This information is crucial for efficient retrieval and processing of the relevant data during traversal.
- the value of a known attribute that needs to be searched is configurable against the attribute of the index of the current level traversal. This flexibility allows the system to adapt to different inventory structures and search requirements. Administrators can configure which attribute of the inventory index corresponds to the known attribute they are searching for. By defining this mapping between attributes, the system can effectively retrieve the desired data during traversal, enabling efficient data processing and analysis.
- the inventory also includes a global profile, for cases where a node cannot be recognized.
- physical enrichment of the alarm is performed based on the corresponding profile or a global profile, to obtain one or more physical enrichment attributes.
- the method 500 includes the step of performing logical enrichment of the alarm based on the one or more physical enrichment attributes and the inventory to obtain logical enrichment attributes.
- the logical enrichment attributes may include IP addressing, routing protocols, VLAN configurations, network topology, virtual network configurations, network service mappings, logical relationships between network elements, network policies, and access control lists (ACLs).
- ACLs access control lists
- For performing the logical enrichment all levels of the inventory may be traversed, and the responses obtained from each level traversal are stored in a map, with the key being the name of the corresponding level. As the system progresses through the inventory levels, responses and associated data is collected from each traversal.
- the method 500 includes the step of appending the physical enrichment attributes and the logical enrichment attributes to the alarm for its enrichment.
- the enriched alarm is also sent to the NMS database for storing and a timer is associated with it.
- the present invention further discloses a non-transitory computer-readable medium having stored thereon computer-readable instructions.
- the computer- readable instructions are executed by the processor 205.
- the processor 205 is configured to receive an alarm raised by a node for an event.
- the alarm comprises one or more attributes indicating a hardware, software, or network issue associated with the node.
- the processor 205 is further configured to identify eligibility of the alarm for at least one of physical enrichment and logical enrichment. The eligibility is determined based on physical placement related attributes included in the alarm.
- the processor 205 is further configured to perform at least one of the physical enrichment and the logical enrichment of the alarm, based on the eligibility.
- the processor 205 is further configured to store enrichment data collected during one or more of the physical enrichment and the logical enrichment in an NMS database 220.
- the above described techniques (of enriching alarms) of the present disclosure provide multiple advantages, including enhancing the alarm processing flow within the NMS by incorporating dynamic and static data enrichment, configurable attribute search, and cached storage mechanisms. It improves efficiency, scalability, and adaptability, leading to streamlined network management, efficient fault analysis, and improved operational performance within the NMS. Further, the described techniques leverage cached storage of enrichment data within the NMS database, resulting in an advantage of improved processing efficiency. By utilizing previously stored enrichment data, the system minimizes the need for redundant data retrieval during alarm processing. This reduces the overall processing time and resource utilization, enhancing the system's performance and enabling faster response to alarms. The utilization of cached enrichment data ensures that alarms are enriched with relevant information more quickly and effectively, contributing to streamlined network management and enhanced operational efficiency.
- the present invention offers multiple advantages over the prior art and the above listed are a few examples to emphasize on some of the advantageous features.
- the listed advantages are to be read in a non-limiting manner.
- a server may include or comprise, by way of example but not limitation, one or more of a standalone server, a server blade, a server rack, a bank of servers, a server farm, hardware supporting a part of a cloud service or system, a home server, hardware running a virtualized server, one or more processors executing code to function as a server, one or more machines performing server-side functionality as described herein, at least a portion of any of the above, some combination thereof.
- the entity may include, but is not limited to, a vendor, a network operator, a company, an organization, a university, a lab facility, a business enterprise, a defence facility, or any other facility that provides content.
- a network may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth.
- the network may also include, by way of example but not limitation, one or more of a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet-switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public- Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.
- PSTN Public- Switched Telephone Network
- a wireless device or a user equipment may include, but are not limited to, a handheld wireless communication device (e.g., a mobile phone, a smart phone, a phablet device, and so on), a wearable computer device (e.g., a head-mounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and/or any other type of computer device with wireless communication capabilities, and the like.
- the UEs may communicate with the system via set of executable instructions residing on any operating system.
- the UEs may include, but are not limited to, any electrical, electronic, electro -mechanical or an equipment or a combination of one or more of the above devices such as virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general -purpose computer, desktop, personal digital assistant, tablet computer, mainframe computer, or any other computing device, wherein the computing device may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as camera, audio aid, a microphone, a keyboard, input devices for receiving input from a user such as touch pad, touch enabled screen, electronic pen and the like. It may be appreciated that the UEs may not be restricted to the mentioned devices and various other devices may be used.
- a system may include one or more processors coupled with a memory, wherein the memory may store instructions which when executed by the one or more processors may cause the system to perform offloading/onloading of broadcasting or multicasting content in networks.
- the system may include one or more processor(s).
- the one or more processor(s) may be implemented as one or more microprocessors, microcomputers, microcontrollers, edge or fog microcontrollers, digital signal processors, central processing units, logic circuitries, and/or any devices that process data based on operational instructions.
- the one or more processor(s) may be configured to fetch and execute computer-readable instructions stored in a memory of the system.
- the memory may be configured to store one or more computer-readable instructions or routines in a non-transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service.
- the memory may comprise any non-transitory storage device including, for example, volatile memory such as Random-Access Memory (RAM), or non-volatile memory such as Electrically Erasable Programmable Read-only Memory (EPROM), flash memory, and the like.
- the system may include an interface(s).
- the interface(s) may comprise a variety of interfaces, for example, interfaces for data input and output devices, referred to as input/output (RO) devices, storage devices, and the like.
- the interface(s) may facilitate communication for the system.
- the interface(s) may also provide a communication pathway for one or more components of the system. Examples of such components include, but are not limited to, processing unit/engine(s) and a database.
- the processing unit/engine(s) may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s). In examples described herein, such combinations of hardware and programming may be implemented in several different ways.
- the programming for the processing engine(s) may be processor executable instructions stored on a non-transitory machine-readable storage medium and the hardware for the processing engine(s) may comprise a processing resource (for example, one or more processors), to execute such instructions.
- the machine- readable storage medium may store instructions that, when executed by the processing resource, implement the processing engine(s).
- the system may include the machine -readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system and the processing resource.
- the processing engine(s) may be implemented by electronic circuitry.
- the database may comprise data that may be either stored or generated as a result of functionalities implemented by any of the components of the processor or the processing engines.
- a computer system may include an external storage device, a bus, a main memory, a read-only memory, a mass storage device, communication port(s), and a processor.
- the communication port(s) may be any of an RS-232 port for use with a modem-based dialup connection, a 10/100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports.
- the communication port(s) may be chosen depending on a network, such a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system connects.
- LAN Local Area Network
- WAN Wide Area Network
- the main memory may be random access memory (RAM), or any other dynamic storage device commonly known in the art.
- the readonly memory may be any static storage device(s) including, but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or basic input/output system (BIOS) instructions for the processor.
- the mass storage device may be any current or future mass storage solution, which may be used to store information and/or instructions.
- the bus communicatively couples the processor with the other memory, storage, and communication blocks.
- the bus can be, e.g.
- PCI Peripheral Component Interconnect
- PCLX PCI Extended
- SCSI Small Computer System Interface
- USB universal serial bus
- operator and administrative interfaces e.g. a display, keyboard, and a cursor control device, may also be coupled to the bus to support direct operator interaction with the computer system.
- Other operator and administrative interfaces may be provided through network connections connected through the communication port(s).
- One or more processors -205 are included in the central processing unit -205 ;
- Input/ output interface unit - 215 [0094] Input/ output interface unit - 215 ;
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP24839116.1A EP4740382A1 (en) | 2023-07-09 | 2024-07-03 | System and method for enrichment of network alarms |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| IN202321046098 | 2023-07-09 | ||
| IN202321046098 | 2023-07-09 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025013003A1 true WO2025013003A1 (en) | 2025-01-16 |
Family
ID=94215080
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/IN2024/051033 Ceased WO2025013003A1 (en) | 2023-07-09 | 2024-07-03 | System and method for enrichment of network alarms |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP4740382A1 (en) |
| WO (1) | WO2025013003A1 (en) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20170155539A1 (en) * | 2015-01-26 | 2017-06-01 | CENX, Inc. | Systems and methods for correlating alarms in a network |
| US10797938B2 (en) * | 2018-06-08 | 2020-10-06 | Accenture Global Solutions Limited | Automatic monitoring, correlation, and resolution of network alarm conditions |
| US20220086036A1 (en) * | 2019-05-25 | 2022-03-17 | Huawei Technologies Co., Ltd. | Alarm Analysis Method and Related Device |
| CN110798348B (en) * | 2019-10-28 | 2022-12-16 | 海南电网有限责任公司 | Power distribution communication network failure alarm method, server and system |
-
2024
- 2024-07-03 WO PCT/IN2024/051033 patent/WO2025013003A1/en not_active Ceased
- 2024-07-03 EP EP24839116.1A patent/EP4740382A1/en active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20170155539A1 (en) * | 2015-01-26 | 2017-06-01 | CENX, Inc. | Systems and methods for correlating alarms in a network |
| US10797938B2 (en) * | 2018-06-08 | 2020-10-06 | Accenture Global Solutions Limited | Automatic monitoring, correlation, and resolution of network alarm conditions |
| US20220086036A1 (en) * | 2019-05-25 | 2022-03-17 | Huawei Technologies Co., Ltd. | Alarm Analysis Method and Related Device |
| CN110798348B (en) * | 2019-10-28 | 2022-12-16 | 海南电网有限责任公司 | Power distribution communication network failure alarm method, server and system |
Also Published As
| Publication number | Publication date |
|---|---|
| EP4740382A1 (en) | 2026-05-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11683618B2 (en) | Application performance monitoring and management platform with anomalous flowlet resolution | |
| US10768970B2 (en) | System and method of flow source discovery | |
| US11159386B2 (en) | Enriched flow data for network analytics | |
| US20220038353A1 (en) | Technologies for annotating process and user information for network flows | |
| US10425302B2 (en) | Scalable end-to-end quality of service monitoring and diagnosis in software defined networks | |
| US10484265B2 (en) | Dynamic update of virtual network topology | |
| US20180278496A1 (en) | Predicting Application And Network Performance | |
| CN110247784A (en) | Method and device for determining network topology | |
| US20200106671A1 (en) | Non-invasive diagnosis of configuration errors in distributed system | |
| US20190124162A1 (en) | Automatic server cluster discovery | |
| CN113867885A (en) | Method, computing system, and computer-readable medium for application flow monitoring | |
| US12443414B2 (en) | System and method to statistically determine and recommend bounce-able machines to improve user experience | |
| US20120218893A1 (en) | Method and apparatus for analyzing a network | |
| EP4740382A1 (en) | System and method for enrichment of network alarms | |
| CN110677303A (en) | Network management system | |
| EP4740383A1 (en) | System and method for automated inter intra node domain alarm correlation | |
| Deri et al. | Realtime MicroCloud-based flow aggregation for fixed and mobile networks | |
| CN120856595B (en) | Method, system, equipment, medium and product for generating detection task of virtual network | |
| WO2025013005A1 (en) | System and method for ticket management of planned events in a network | |
| EP4740418A1 (en) | Method and system of handling session initiation protocol packets distribution in a network | |
| WO2025017661A1 (en) | System and method for creating a dynamic uniform resource locator (url) | |
| WO2025013046A1 (en) | Method and system for monitoring a network | |
| WO2025022436A1 (en) | Method and system for monitoring network functions in a network | |
| WO2025013067A1 (en) | System and method for mapping user equipment identifiers in a telecommunication network | |
| WO2025017635A1 (en) | System and method for identifying network entities causing errors and timeouts |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24839116 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2024839116 Country of ref document: EP Effective date: 20260209 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024839116 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWP | Wipo information: published in national office |
Ref document number: 2024839116 Country of ref document: EP |