CA2343370C

Root cause analysis in a distributed network management architecture

Abstract

A method of determining the root cause of an event in a computer network having a distributed network management architecture including detecting an event at at least one device component (DC) in the network, for each source DC at which an event is detected, finding a data path within the network from the source DC's underlying network element to that of its acquaintance DC where present, identifying as the root cause any of the source DC and the subject DCs in the data path that have detected an event and either do not have an acquaintance or do not have a valid operational state with respect to its acquaintance whereas all other DCs along the data path at lower network layers than the source or subject DC have valid operational states with respect to their acquaintances.

CA2343370C, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 6 April 2021, 5.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

2 claims: 2 independent, 0 dependent

  1. 1
    CA 02343370 2007-04-25 CLAIMS What is claimed is:1. A method for determining a root cause in a computer network having a plurality of network elements and a network management architecture having a plurality of agents, each of the agents corresponding to a different one of the network elements, and a plurality of device components (DC), each of the device components modeling at least one aspect of one of the network elements, the aspect being either of a physical and a functional characteristic of the network element, wherein each of the agents includes a plurality of the device components, and wherein at least two of the device components within at least one of the agents are logically interconnected, each logical interconnection corresponding to either of a physical and a functional interconnection found among any of the network elements, the method comprising the steps of: a) detecting an event at at least one DC in said network, each DC at which an event is detected now referred to as a source DC;b) if any of said source DCs does not have an acquaintance DC, where an acquaintance DC to said source DC is a DC that is of the same type as said source DC or performs the same function as said source DC, then determining said root cause of said event to be within said source DC’s area of responsibility;c) if any of said source DCs does have an acquaintance DC, then finding a data path within said network from any of said source DC's underlying network element to said acquaintance DC's underlying network element, identifying those DCs whose area of responsibility lay along said data path, each DC in said data path now referred to as a subject DC, and performing any of the following steps d), e), and f) for any of said subject DCs at which an event is detected: CA 02343370 2007-04-25 d) if said subject DC has an acquaintance DC, and said subject DC does not have a valid operational state with respect to its acquaintance DC, and all other DCs along said data path at lower network layers than said subject DC have valid operational states with respect to their acquaintance DCs, then determining said root cause of said event to be within the area of responsibility of said subject DC;e) if said subject DC has an acquaintance DC, and said subject DC has a valid operational state with respect to its acquaintance DC and all other DCs along said data path at lower network layers than said subject DC have valid operational states with respect to their acquaintance DCs, then determining said root cause of said event to be within the area of responsibility of said source DC;and f) if said subject DC does not have an acquaintance DC, then determining said root cause of said event to be within the area of responsibility of said subject DC.
  2. 2
    A method of determining a root cause of an event in a computer network having a distributed network management architecture, the method comprising:detecting an event at at least one device component (DC) in said network;for each source DC at which an event is detected, finding a data path within said network from the source DC's underlying network element to that of its acquaintance DC where present, where an acquaintance DC to said source DC is a DC that is of the same type as said source DC or performs the same function as said source DC;and identifying as said root cause any of said source DC and any subject DCs in said data path that have detected an event and either of a) do not have an acquaintance and b) do not have a valid operational state with respect to its acquaintance whereas all other DCs along the data path at lower network layers than the source or subject DC have valid operational states with respect to their acquaintances.