Sign In to Follow Application
View All Documents & Correspondence

“Method And System For Generating One Or More Rules For A Root Cause Analysis System”

Abstract: The present subject matter is related in general to root cause analysis system that discloses method and system for generating rules for a root cause analysis system. A rules generation system retrieves first events and process flow of the first events from existing source codes and generates rules automatically. The rules are generated by clustering the first events that are linked through the process flow in a predefined data structure format. Since the process of generating the rules is automatic, the rules generation system enables use of minimum resources and increases overall speed. Further, the rules generation system also caters the need of dynamically occurring events by linking them to the existing events by determining a correlation factor and thus updating the predefined data structure format to generate rules. The generated rules are verified and fed to the root cause analysis system. FIG.2A

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
28 July 2016
Publication Number
05/2018
Publication Type
INA
Invention Field
PHYSICS
Status
Email
ipo@knspartners.com
Parent Application

Applicants

HITACHI, LTD.
6-6, Marunouchi 1-chome, Chiyoda-ku, Tokyo, Japan.

Inventors

1. Pranay Verma
M/s Hitachi India Private Limited, Unit No. S 704, 7th floor, World Trade Center, Brigade Gateway Campus, No.26/1, Dr. Rajkumar Road, Malleswaram-Rajajinagar, Bangalore-560055, Karnataka, India.
2. Remish Leonard Minz
M/s Hitachi India Private Limited, Unit No. S 704, 7th floor, World Trade Center, Brigade Gateway Campus, No.26/1, Dr. Rajkumar Road, Malleswaram-Rajajinagar, Bangalore-560055, Karnataka, India.

Claims

1. A method for generating one or more rules for a root cause analysis system 113, the method comprising: retrieving, by a rules generation system 113, one or more first events 105 and process flow of the one or more first events 105 from one or more first data sources 103; representing, by the rules generation system 113, the process flow of the one or more first events 106 in a predefined data structure format; grouping, by the rules generation system 113, the one or more first events 105 represented in the predefined data structure format into one or more first clusters; determining, by the rules generation system 113, availability of one or more second events 109 in one or more second data sources 104; updating dynamically, by the rules generation system 113, the predefined data structure format by linking the one or more second events 109 to the one or more first events 105 if the one or more second events 109 are available, wherein the one or more first events 105 and the one or more second events 109 are grouped into one or more second clusters; and generating, by the rules generation system 113, one or more rules based on at least one of the one or more first clusters or the one or more second clusters.

2. The method as claimed in claim 1 further comprises: providing, by the rules generation system 113, the one or more rules to a rules verification system 121 associated with the rules generation system 113 for identifying one or more faults in the one or more rules; receiving, by the rules generation system 113, the one or more faults in the one or more rules from the rules verification system 121; and updating dynamically, by the rules generation system 113, the predefined data structure format based on the one or more faults in the one or more rules.

3. The method as claimed in claim 1, wherein the one or more second events 109 are distinct from the one or more first events 105.

4. The method as claimed in claim 1, wherein linking the one or more second events 109 to the one or more first events 105 comprises: determining, by the rules generation system 113, a relationship and a level of the relationship of each of the one or more second events 109 with each of the one or more first events 105, wherein the relationship is at least one of a positive relationship and a negative relationship; and linking, by the rules generation system 113, the one or more second events 109 to one of the one or more first events 105 based on the level of the relationship when the relationship is determined to be the positive relationship.

5. The method as claimed in claim 1, wherein the one or more rules are generated based on at least one of order of occurrence of the one or more first events 105 in the one or more first clusters or order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters.

6. The method as claimed in claim 5 further comprises determining, by the rules generation system 113, last event in the order of occurrence of the one or more first events 105 and the one or more second events 109, wherein the last event is root cause event of the one or more rules.

7. A rules generation system 113 for generating one or more rules for a root cause analysis system 123, the rules generation system 113 comprising: a processor 115; and a memory 119 communicatively coupled to the processor 115, wherein the memory 119 stores the processor-executable instructions, which, on execution, causes the processor 115 to: retrieve one or more first events 105 and process flow of the one or more first events 105 from one or more first data sources 103; represent the process flow of the one or more first events 105 in a predefined data structure format; group the one or more first events 105 represented in the predefined data structure format into one or more first clusters; determine availability of one or more second events 109 in one or more second data sources 104; update dynamically, the predefined data structure format by linking the one or more second events 109 to the one or more first events 105 if the one or more second events 109 are available, wherein the one or more first events 105 and the one or more second events 109 are grouped into one or more second clusters; and generate one or more rules based on at least one of the one or more first clusters or the one or more second clusters.

8. The rules generation system 113 as claimed in claim 7, wherein the processor 115 is further configured to: provide the one or more rules to a rules verification system 121 associated with the rules generation system 113 for identifying one or more faults in the one or more rules; receive the one or more faults in the one or more rules from the rules verification system 121; and update the predefined data structure format based on the one or more faults in the one or more rules.

9. The rules generation system 113 as claimed in claim 7, wherein the one or more second events 109 are distinct from the one or more first events 105.

10. The rules generation system 113 as claimed in claim 7, wherein the processor 115 links the one or more second events 109 to the one or more first events 105 by: determine a relationship and a level of the relationship of each of the one or more second events 109 with each of the one or more first events 105, wherein the relationship is at least one of a positive relationship and a negative relationship; and link the one or more second events 109 to one of the one or more first events 105 based on the level of the relationship when the relationship is determined to be the positive relationship.

11. The rules generation system 113 as claimed in claim 7, wherein the processor 115 generates the one or more rules based on at least one of order of occurrence of the one or more first events 105 in the one or more first clusters or order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters.

12. The rules generation system 113 as claimed in claim 11 wherein the processor 115 is further configured to determine last event in the order of occurrence of the one or more first events 105 and the one or more second events 109, wherein the last event is root cause event of the one or more rules. , Description:TECHNICAL FIELD The present subject matter is related, in general to root cause analysis system and more particularly, but not exclusively to a method and a system for generating one or more rules for a root cause analysis system. BACKGROUND A root cause analysis system is used to troubleshoot all the errors occurring in any environment and identifies ultimate source of the problem based on one or more rules. As an example, in a cloud computing environment a fault might have occurred while providing resources to one or more computing devices connected in the cloud computing environment. The root cause analysis system configured in the cloud computing environment may identify the fault or a root cause event causing the fault and indicates a source of the problem. The root cause analysis system accepts one or more rules as input data. The one or more rules define relationship among failing conditions in the environment. Further, the one or more rules define reason for root cause failure for a set of failure conditions. However, existing root cause analysis systems currently have three major problems. Firstly, the time taken to manually create the one or more rules as input data for the root cause analysis system is more due to which there may be significant delay in productizing the root cause analysis system. Secondly, amount of human effort required to manually create the one or more rules for the root cause analysis system is high. Thirdly, the root cause analysis system may face the problem of having incomplete rules as the input data due to unaccounted events that may have occurred, thus leaving the user with insufficient information to troubleshoot complex scenarios. Currently, conventional rules generation methods generate validation rules for a particular column data of a table i.e. the system may generate few rules per each column. A few other conventional methods only generate a method flow of events. But the existing techniques are limited only for a few systems and particularly only for certain data present in the few systems. Further, the existing techniques have manual intervention to a large extent that may risk in reliability of the one or more rules generated. Also, due to the manual intervention, time taken to generate the one or more rules and efforts involved in generating the one or more rules may be high, thereby decreasing the rate at which the rules may be generated for a root cause analysis system. SUMMARY One or more shortcomings of the prior art are overcome and additional advantages are provided through the present disclosure. Additional features and advantages are realized through the techniques of the present disclosure. Other embodiments and aspects of the disclosure are described in detail herein and are considered a part of the claimed disclosure. Disclosed herein are a method and a system for generating one or more rules for a root cause analysis system. A rules generation system retrieves one or more first events and process flow of the one or more first events from existing source codes and generates one or more rules automatically for use in the root cause analysis system. The rules generation system generates the one or more rules by clustering the one or more first events that are linked through the process flow in a predefined data structure format. Therefore, the rules generation system enables use of minimum resources to generate the one or more rules as the process of generating the one or more rules is automatic and increases overall speed of deploying root cause analysis system. Further, the rules generation system also caters the need of dynamically occurring events. The dynamically occurring events are linked to the existing events by determining a correlation factor and thus updating the predefined data structure format to generate one or more rules. Further, the rules generating system is adaptive and is capable of generating one or more rules automatically for any rules based system. Accordingly, the present disclosure provides a method for generating one or more rules for a root cause analysis system. The method comprises retrieving by a rules generation system, one or more first events and process flow of the one or more first events from one or more first data sources. Further, the rules generation system represents the process flow of the one or more first events in a predefined data structure format. Upon representing the process flow, the rules generation system groups the one or more first events represented in the predefined data structure format into one or more first clusters. Thereafter, the rules generation system determines availability of one or more second events in one or more second data sources. Upon determining the availability, the rules generation system dynamically updates the predefined data structure format by linking the one or more second events to the one or more first events if the one or more second events are available. The one or more first events and the one or more second events are grouped into one or more second clusters. Finally, the rules generation system generates one or more rules based on at least one of the one or more first clusters or the one or more second clusters. Further, the present disclosure comprises a rules generation system for generating one or more rules for a root cause analysis system. The rules generation system comprises a processor and a memory communicatively coupled to the processor, wherein the memory stores the processor-executable instructions, which, on execution, causes the processor to retrieve one or more first events and process flow of the one or more first events from one or more first data sources. Further, the processor is configured to represent the process flow of the one or more first events in a predefined data structure format. Upon representing the process flow, the processor is configured to group the one or more first events represented in the predefined data structure format into one or more first clusters. Further, the processor is configured to determine availability of one or more second events in one or more second data sources. Thereafter, the processor is configured to update dynamically, the predefined data structure format by linking the one or more second events to the one or more first events if the one or more second events are available. The one or more first events and the one or more second events are grouped into one or more second clusters. Finally, the processor is configured to generate one or more rules based on at least one of the one or more first clusters or the one or more second clusters. The foregoing summary is illustrative only and is not intended to be in any way limiting. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features will become apparent by reference to the drawings and the following detailed description. BRIEF DESCRIPTION OF THE ACCOMPANYING DIAGRAMS The accompanying drawings, which are incorporated in and constitute a part of this disclosure, illustrate exemplary embodiments and, together with the description, serve to explain the disclosed principles. In the figures, the left-most digit(s) of a reference number identifies the figure in which the reference number first appears. The same numbers are used throughout the figures to reference like features and components. Some embodiments of system and/or methods in accordance with embodiments of the present subject matter are now described, by way of example only, and with reference to the accompanying figures, in which: FIG.1A shows an exemplary architecture for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure; FIG.1B shows an exemplary architecture illustrating an environment involving a rules generation system and a rules verification system in accordance with some embodiments of the present disclosure; FIG.2A shows a detailed block diagram of a rules generation system for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure; FIG.2B shows an exemplary predefined data structure format representing the one or more events in accordance with some embodiments of the present disclosure; FIG.2C shows exemplary clusters formed by grouping one or more exemplary events in accordance with some embodiments of the present disclosure; FIG.2D shows an exemplary predefined data structure format representing one or more first events as illustrated in scenario 1 in accordance with some embodiments of the present disclosure; FIG.2E shows exemplary one or more first clusters formed by grouping one or more first events as illustrated in scenario 1 in accordance with some embodiments of the present disclosure; FIG.2F shows a graph of exemplary vector space representing relationship of the one or more first events with one or more second events in accordance with some embodiments of the present disclosure; FIG.2G shows exemplary one or more second clusters formed by linking one or more second events in accordance with some embodiments of the present disclosure; FIG.2H and FIG.2I shows exemplary clusters illustrating correction and modification of the one or more rules to resolve redundancy in accordance with some embodiments of the present disclosure; FIG.3 illustrates a flowchart showing method for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure; and FIG.4 is a block diagram of an exemplary computer system for implementing embodiments consistent with the present disclosure. It should be appreciated by those skilled in the art that any block diagrams herein represent conceptual views of illustrative systems embodying the principles of the present subject matter. Similarly, it will be appreciated that any flow charts, flow diagrams, state transition diagrams, pseudo code, and the like represent various processes which may be substantially represented in computer readable medium and executed by a computer or processor, whether or not such computer or processor is explicitly shown. DETAILED DESCRIPTION In the present document, the word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the present subject matter described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments. While the disclosure is susceptible to various modifications and alternative forms, specific embodiment thereof has been shown by way of example in the drawings and will be described in detail below. It should be understood, however that it is not intended to limit the disclosure to the particular forms disclosed, but on the contrary, the disclosure is to cover all modifications, equivalents, and alternative falling within the scope of the disclosure. The terms “comprises”, “comprising”, or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a setup, device or method that comprises a list of components or steps does not include only those components or steps but may include other components or steps not expressly listed or inherent to such setup or device or method. In other words, one or more elements in a system or apparatus proceeded by “comprises… a” does not, without more constraints, preclude the existence of other elements or additional elements in the system or method. The present disclosure provides a method for generating one or more rules for a root cause analysis system. A rules generation system retrieves one or more first events and process flow of the one or more first events from one or more first data sources. Upon retrieving the one or more first events and process flow of the one or more first events, the rules generation system represents the process flow of the one or more first events in a predefined data structure format. Further, the rules generation system groups the one or more first events represented in the predefined data structure format into one or more first clusters. Thereafter, the rules generation system determines availability of one or more second events in one or more second data sources. Upon determining the availability, the rules generation system dynamically updates the predefined data structure format by linking the one or more second events to the one or more first events if the one or more second events are available. The one or more first events and the one or more second events are grouped into one or more second clusters. Finally, the rules generation system generates one or more rules based on at least one of the one or more first clusters or the one or more second clusters. The rules generating system disclosed in the present disclosure is adaptive and is capable of generating one or more rules automatically for any rules based system. Since the generation of the one or more rules is automatic, the present disclosure reduces cost for deploying the root cause analysis system. Further, the present disclosure enhances reliability of the root cause analysis system by performing automatic verification of the one or more rules and removing errors from the one or more rules based on the automatic verification. In the following detailed description of the embodiments of the disclosure, reference is made to the accompanying drawings that form a part hereof, and in which are shown by way of illustration specific embodiments in which the disclosure may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the disclosure, and it is to be understood that other embodiments may be utilized and that changes may be made without departing from the scope of the present disclosure. The following description is, therefore, not to be taken in a limiting sense. FIG.1A shows an exemplary architecture for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure. The architecture 100 comprises one or more first data sources, first data source 1 1031 to first data source n 103n (collectively referred to as one or more first data sources 103), one or more second data sources, second data source 1 1041 to second data source n 104n (collectively referred to as one or more second data sources 104), a communication network 111 and a rules generation system 113. As an example, the one or more first data sources 103 may include, but not limited to, source codes of one or more applications. As an example, one or more second data sources 104 may include, but not limited to, a cloud environment, a monitoring system and an external system. The one or more first data sources 103 and the one or more second data sources 104 communicate with the rules generation system 113 through the communication network 111. As an example, the communication network 111 may be at least one of a wired communication network and a wireless communication network. The rules generation system 113 comprises a processor 115, an Input/output (I/O) interface 117 and a memory 119. In an embodiment, the processor 115 extracts one or more first events 105 and process flow data 106 from the one or more first data sources 103 i.e. the source codes of the one or more applications. The process flow data 106 comprises process flow of the one or more first events 105. In an embodiment, the process flow of the one or more events 105 is a systematic flow linking the one or more first events 105 in the source code. The I/O interface 117 retrieves the extracted one or more first events 105 and the process flow data 106 from the one or more first data sources 103. The one or more first events 105 may be any part of the source code comprising useful information such as Log information, monitoring information and one or more system generated events. In an alternative embodiment, the I/O interface 117 may directly retrieve pre-stored one or more first events and pre-stored process flow data 106 from the one or more first data sources 103. The received one or more first events 105 and the process flow data 106 are stored in the memory 119. The memory 119 is communicatively coupled to the processor 115. Upon receiving the one or more first events 105 the processor 115 represents the process flow data 106 in a predefined data structure format. As an example, the predefined data structure format may include, but not limited to, a tree. Further, the processor 115 groups the one or more events 105 represented in the predefined data structure format into one or more first clusters. Upon forming the one or more first clusters, the processor 115 checks for the availability of one or more second events 109 in the one or more second data sources 104. The one or more second events 109 are dynamically occurring events that are distinct from the one or more first events 105. If, the one or more second events 109 are available, the processor 109 determines relationship of the one or more second events 109 with the one or more first events 105 and updates the predefined data structure based on the determined relationship. The processor 115 further groups the one or more first events 105 and the one or more second events 109 into one or more second clusters based on the updated predefined data structure format. Thereafter, the processor 115 generates one or more rules based on either the one or more first clusters or the one or more second clusters. In an embodiment, upon generating the one or more rules, the rules generation system 113 transmits the one or more rules to a rules verification system 121 through the I/O interface 117 as shown in the FIG.1B. The rules verification system 121 identifies the one or more faults in the one or more rules and provides the one or more faults to the rules generation system 113. The one or more faults may be manually corrected by a user. In an alternative embodiment, the processor 115 automatically corrects and updates the predefined data structure format based on the one or more faults identified by the rules verification system 121. Upon updating the predefined data structure format, the rules generation system 113, may continue with the process of generating the one or more rules based on the updated predefined data structure format. In an embodiment, the one or more rules may be provided to the root cause analysis system 123 as shown in the FIG.1B. FIG.2A shows a detailed block diagram of a rules generation system for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure. In one implementation, the rules generation system 113 receives data from the one or more first data sources 103 and one or more second data sources 104 associated with the rules generation system 113. As an example, the data 203 may be stored in the memory 119 configured in the rules generation system 113. In one embodiment, the data 203 comprises one or more first events 105, process flow data 106, one or more second events 109, a cluster data 209, data related to a predefined data structure format 211, a relationship data 213, rules data 215 and other data 219. In the illustrated Fig.2, modules 205 are described here in detail. In one embodiment, the data 203 may be stored in the memory 119 in the form of various data structures. Additionally, the aforementioned data 203 can be organized using data models, such as relational or hierarchical data models. The other data 219 may store data, including temporary data and temporary files, generated by modules 205 for performing the various functions of the rules generation system 113. In an embodiment, one or more first events 105 are retrieved from the one or more first data sources 103. The one or more first events 105 may be any part of the source code comprising useful information such as Log information, monitoring information and information related to one or more system generated events. In an embodiment, the useful information may comprise one or more predefined keywords based on which the rules generation system 113 may recognize the one or more first events 105 from the one or more first data sources 103 using a predefined technique which may include, but not limited to, Natural Language Processing (NLP) technique. As an example, the one or more predefined keywords may be “Exception”, “Error”, “Not found”, “Notify”, “Log” etc. The one or more first data sources 103 may include, but not limited to, source codes of one or more applications. As an example consider a source code 1 as shown below: Throw event("User not authorized") If event== logarithmic_error: Print "we are handling error now" Throw event("system error") Throw event("Unknown exception") In the above source code 1, the one or more first events 105 are "User not authorized", “Logarithmic error”, “System error” and “Unknown exception”. In an embodiment, the process flow data 106 comprises process flow of the one or more first events 105. The process flow data 106 is retrieved from the one or more first data sources 103. The process flow is a systematic flow that links the one or more first events 105 in the source code. As an example, consider source code 2, source code 3 and source code 4 as shown in the below Table 1. Source code 2 Method 1: If Event A Event B Method 2 Event C Else if Event D Event E Method 3 Event F Else Event G Event P Source code 3 Method 2: If Event H Event I Else if Event J Event K Source code 4 Method 3: If Event L Event M Else if Event N Event O Table 1 The process flow of the source code 2, source code 3 and source code 4 is as shown below: Method 1 Method 2 Method 3 In an embodiment, the one or more second events 109 are dynamically occurring events. In an embodiment, the dynamically occurring events are the events, related to one or more applications, which are generated at the one or more second data sources. As an example, the one or more second data sources 104 may include, but not limited to, a cloud environment, a monitoring system and an external system. In an embodiment, the cluster data 209 comprises one or more first clusters formed by grouping the one or more first events 105 represented in a predefined data structure format such as a tree. The cluster data 209 further comprises the one or more second clusters formed by grouping the one or more first events and the one or more second events together in various combinations. In an embodiment, the data related to the predefined data structure format 211 comprises a predefined data structure format such as a tree representing the one or more first events 105 based on the process flow data 106. Further, the data related to the predefined data structure format 211 also comprises the predefined data structure representing the one or more second events 109 linked to the one or more first events 105. In an embodiment, the relationship data 213 comprises a value specifying relationship of the one or more second events 106 with one or more first events 105. The relationship data 213 defines correlation of related events based on properties of the one or more first events 105 and one or more second events 106 such as “Event type” and “Resource type”. “Event type” indicates types of the one or more first events 105 and the one or more second events 109 that are categorized based on effects of the one or more first events 105 and the one or more second events 109 on the one or more applications. An “Event type value” is associated with each “Event type”, wherein the “Event type value” is predefined. As an example, the “Event type” may include, but not limited to, the types as shown in the below Table 2. Event type Event type value Less than threshold value 243a 1 Normal 243b 2 Greater than threshold value 243c 3 Table 2 In an embodiment, the threshold value may be predefined in the rules generation system 113. “Resource type” indicates type of one or more resources associated with the one or more first events 105 and the one or more second events 109. A “Resource type value” is associated with each “Resource type”. As an example, the “Resource type” may include, but not limited to, the types as shown in the below Table 3. Resource type Resource type value Central Processing Unit (CPU) 241a 1 Network 241b 2 Storage 241c 3 Table 3 In an embodiment, the rules data 215 comprises one or more rules that are generated based on the one or more first clusters and the one or more second clusters. The one or more rules define relationship among failing conditions and define root cause for a set of failure conditions. In an embodiment, the data stored in the memory 119 is processed by the modules 205 of the rules generation system 113. The modules 205 may be stored within the memory 113. In an example, the modules 205, communicatively coupled to a processor 115 configured in the rules generation system 113, may also be present outside the memory 119 as shown in FIG.2A and implemented as hardware. As used herein, the term module refers to an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group) and memory that execute one or more software or firmware programs, a combinational logic circuit, and/or other suitable components that provide the described functionality. In an embodiment, the modules 205 may include, for example, a retrieving module 223, a first analysis module 225, an event clustering module 227, a second analysis module 229, an event relationship determining module 231, an event linking module 233, a rules generation module 237, fault correction module 238 and other modules 239. The other modules 239 may be used to perform various miscellaneous functionalities of the rules generation system 113. It will be appreciated that such aforementioned modules 205 may be represented as a single module or a combination of different modules. In an embodiment, the retrieving module 223 retrieves the one or more first events 105 and the process flow data 106 from the one or more first data sources 103. In an embodiment, the first analysis module 225 represents the process flow data 106 in the predefined data structure format. The predefined data structure format indicates link between the one or more first events 105 corresponding to the process flow data 106. In an embodiment, the event clustering module 227 groups the one or more first events 105 into one or more first clusters based on the representation in the predefined data structure format. In an embodiment, the one or more first events 105 can be grouped in one or more combinations. As an example, consider that the predefined data structure format is a tree, the one or more first events 105 may be nodes of the tree as shown in the FIG.2B. “Node A” is the root node of the tree and rest of the one or more first events 105 represented by “Node B”, “Node C”, “Node D”, “Node E”, “Node F”, “Node G”, “Node H”, “Node I”, “Node J” and “Node K” are the child nodes of the root node “Node A”. “Node A” is a parent node of child nodes “Node B”, “Node C” and “Node D”. “Node B” is the parent node of the child nodes “Node E” and “Node F”. “Node C” is the parent node of child nodes “Node G”, “Node H” and “Node I”. And “Node I” is the parent node of the child nodes “Node J” and “Node K”. The one or more first events 105 are grouped in the one or more combinations such as parent node-child node combination, parent node-parent node combination, child node-child node combination etc. at any depth of the tree. As shown in FIG.2C, Cluster 1 represents the parent node-child node combination between “Node B”, “Node E” and “Node F” that are present at the same depth i.e. depth 2. Similarly, Cluster 2 represents the child node-child node combination between “Node G” and “Node H” that are present at two different depths of the tree i.e. “Node G” and “Node H” at depth 2. Similarly, Cluster 3 represents the parent node-child node combination between “Node D”, “Node I” and “Node K” that are present at three different depths of the tree i.e. “Node D” at depth 1, “Node I” at depth 2 and “Node K” at depth 3. In an embodiment, the second analysis module 229 determines availability of the one or more second events 109 in one or more second data sources 104. In an embodiment, the second analysis module 229 receives all the dynamically occurring events from the one or more second data sources 104 through the I/O interface 117 and stores in the memory 119. Upon receiving all the dynamically occurring events, the second analysis module 229 activates a predefined filter to select only the dynamically occurring events i.e. the one or more second events 109 that are different from the one or more first events 105. In an embodiment, the predefined filter is a condition based on which the dynamically occurring events which resemble the one or more first events 105 are removed or not considered for further operations. Therefore, the second analysis module 229 compares each of the dynamically occurring events with the one or more first events 105 based on the predefined filter. Based on the comparison, the second analysis module 229 eliminates the dynamically occurring events that are same as the one or more first events 105 and retains the one or more second events 109 in the memory 119. In an alternative embodiment, the second analysis module 229 directly compares each of the dynamically occurring events with the one or more first events 105 based on the predefined filter at the one or more second data sources 104. Based on the comparison, the retrieving module 223 retrieves only the one or more second events 109 from the one or more second data sources 104. If the second analysis module 229 determines that the one or more second events 109 are available, the second analysis module 229 activates the event relationship determining module 231. If the second analysis module 229 determines that the one or more second events 109 are not available, then the second analysis module 229 activates the rule generation module 237. In an embodiment, the event relationship determining module 231 determines relationship and level of the relationship of the one or more second events 109 with each of the one or more first events 105 using one or more predefined techniques. As an example, the one or more predefined techniques may include, but not limited to, K-Means clustering algorithm and K-Nearest neighbour algorithm. In an embodiment, the relationship may be a positive relationship or a negative relationship. As an example, consider two events “Event 1” and “Event 2”. If there exists a possibility that “Event 1” may occur if the “Event 2” occurs and the vice-versa, then the relationship between “Event 1” and “Event 2” is determined to be the positive relationship. If there exists no possibility that “Event 1” may occur if the “Event 2” occurs and the vice-versa i.e. if “Event 1” and “Event 2” can never occur together, then the relationship between “Event 1” and “Event 2” is determined to be the negative relationship. The relationship and the level of relationship is determined by plotting the relationship data 213 corresponding to the one or more first events 105 and the one or more second events 109 in a vector space. The relationship data 213 corresponding to the one or more first events 105 and the one or more second events 109 provides dimensions for the vector space. The relationship data 213 comprising the event type along with the event type value and the resource type along with the resource type value corresponding to each of the one or first events 105 and each of the one or more second events 109 generates Event vectors of the one or more first events 105 and each of the one or more second events 109. The Event vectors are plotted in the vector space. An exemplary vector space indicating exemplary Event vectors are shown in FIG.2F. Upon plotting the Event vectors, the relationship and the level of the relationship of the one or more second events 109 with the one or more first events 105 is determined using at least one of the one or more predefined techniques. In an embodiment, the event linking module 233 updates the predefined data structure format representing the process flow data 106 to incorporate the one or more second events 109. The event linking module 233 updates the predefined data structure format by linking the one or more second events 109 to the one or more first events 105 based on the level of the relationship, if the relationship is determined to be the positive relationship. Upon updating the predefined data structure format, the event clustering module 227 groups the one or more first events 105 and the one or more second events 109 into one or more second clusters. Thereafter, the event clustering module 227 activates the rule generation module 237. In an embodiment, if the relationship between the one or more first events 105 and the one or more second events 109 is determined to be the negative relationship, then event linking module 233 discards the one or more second events 109. In an embodiment, the rules generation module 237 generates the one or more rules based on the one or more first clusters or the one or more second clusters. If the rules generation module 237 considers the one or more first clusters, then the rules generation module 237 generates the one or more rules based on order of occurrence of the one or more first events 105 in the one or more first clusters. Accordingly, last event in the order of occurrence of the one or more first events 105 in the one or more first clusters is said to be root cause identified in the one or more rules. If the rules generation module 237 considers the one or more second clusters, then the rules generation module 237 generates the one or more rules based on order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters. Accordingly, last event in the order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters is said to be root cause identified in the one or more rules. Upon generating the one or more rules, the rules generation module 237 provides the one or more rules to rules verification system 121 associated with the rules generation system 113 for verifying the one or more rules. In an embodiment, the rules verification system 121 may use a verification technique disclosed in the Indian Patent Application: 6303/CHE/2015 to verify the one or more rules. Entire content of the Indian Patent Application: 6303/CHE/2015 is incorporated by reference herein. In an alternative embodiment, the rules verification system 121 may use other verification techniques to verify the one or more rules. Upon verifying the one or more rules, the rules verification system 121 identifies the one or more faults in the one or more rules and provides the one or more faults to the rules generation system 113. The one or more faults can be manually corrected as illustrated in the Indian Patent Application: 6303/CHE/2015. The faults may arise due to parameters related to rules such as redundancy, incorrectness, incompleteness, inconsistency, non-satisfactory etc. In an embodiment, the fault correction module 238 in association with the event linking module 233 automatically corrects and updates the predefined data structure format based on the one or more faults identified by the rules verification system 121. Upon updating the predefined data structure format, the rules generation module 237 may continue with the process of generating the one or more rules based on the updated predefined data structure format. Further, in an embodiment, the one or more rules may be provided to the root cause analysis system 123. Scenario 1 Consider source code 2, source code 3 and source code 4 as shown in the below Table 1. Source code 2 Method 1: If Event A Event B Method 2 Event C Else if Event D Event E Method 3 Event F Else Event G Event P Source code 3 Method 2: If Event H Event I Else if Event J Event K Source code 4 Method 3: If Event L Event M Else if Event N Event O Table 1 The process flow of the one or more first events 106 of the source code 2, source code 3 and source code 4 is as shown below: Method 1 Method 2 Method 3 The one or more first events 105 extracted from the source code 2, source code 3 and source code 4 are as shown in the below Table 4a, Table 4b and Table 4c respectively. Method 1 Event A Event B Method 2 Event C Event D Event E Method 3 Event F Event G Event P Table 4a Method 2 Event H Event I Event J Event K Table 4b Method 3 Event L Event M Event N Event O Table 4c The one or more first events 105 extracted as shown in the above tables Table 4a, Table 4b and Table 4c are represented in a predefined data structure format as shown in the FIG.2D based on the process flow data 106. In this scenario, the predefined data structure format used is a tree. Upon representing the one or more first events 105 in the predefined data structure format, the one or more first events 105 are grouped into one or more first clusters as shown in the FIG.2E. The FIG.2E represents first cluster 1 comprising the events “Event A”, “Event B”, “Event C”, “Event H” and “Event I” and first cluster 2 comprising “Event F”, “Event N” and “Event O”. Upon grouping the one or more first events 105 into one or more first clusters, the availability of the one or more second events 109 is determined, wherein availability of a second event “Event X” is determined. The resource data 213 of the one or more first events 105 of the first cluster 1 and the first cluster 2 is obtained based on the above tables Table 2 and Table 3. “Event A” belongs to the resource type “storage 241c” and event type “greater than threshold value 243c”. Therefore, the resource type value of the “Event A” is 3 and the event type value of the “Event A” is 3. Based on the resource type value and the event type value, an Event vector is obtained. The Event vector of “Event A” is as shown below as Event Vector 1. Event A = ----------------- Event Vector 1 Similarly, the Event vectors of each of the one or more first events 105 of the first cluster 1 and the first cluster 2 are: Event B = ----------------- Event Vector 2 Event C = ----------------- Event Vector 3 Event H = ----------------- Event Vector 4 Event I = ----------------- Event Vector 5 Event N = ----------------- Event Vector 6 Event O = ----------------- Event Vector 7 Event F = ----------------- Event Vector 8 Based on the Event vectors obtained, the one or more first events 105 of the first cluster 1 and the first cluster 2 are plotted in the vector space along X-axis 241 and Y-axis 243 as shown in the FIG.2F. In FIG.2F, the event vectors 1, 2, 3, 4 and 5 lie on the same point (3, 3), but for clarity in representation of all the Event vectors in the vector space, they are scattered around the point (3, 3). Similarly, Event vectors 6 and 9 lie on the same point (1, 1). In an embodiment, based on the plotting in the vector space the event relationship determining module 231 determines squared Euclidean distance of the “Event X” with each of the one or more first events 105 of the first cluster 1 and the first cluster 2. Further, the event relationship determining module 231 determines the relationship of “Event X” with each of the one or more first events 105 of the first cluster 1 and the first cluster 2. The event relationship determining module 231 determines that the “Event X” has the minimum squared Euclidean distance with “Event N” and the relationship of the “Event X” and “Event N” is the positive relationship. Therefore, the “Event X” is linked with the “Event N” by the Event linking module 233. Upon linking the “Event X” with “Event N”, the event clustering module 229 groups the one or more first events 105 with the “Event X” to form a second cluster 1 as shown in the FIG.2G. Upon forming the one or more second clusters, the rules generation module 237 generates one or more rules based on the one or more second clusters. As an example, the one or more rules generated based on the one or more second clusters are as shown in the below Table 5. Rule number Rules Root cause Rule 1 Event A and Event B and Event H and Event I and Event C Event C Rule 2 Event F and Event N and Event O Event F Rule 3 Event N and Event O and Event X Event O Table 5 In the above Table 5, consider the Rule 1 “Event A and Event B and Event H and Event I and Event C”. In Rule 1, the order of occurrence of events is “Event A”, “Event B”, “Event H”, “Event I” and “Event C”. Accordingly, last event in the order of occurrence is “Event C”. Therefore, the root cause event of the Rule 1 is “Event C”. Similarly, the order of occurrence of events in Rule 2 is “Event N”, “Event O” and “Event F”. Therefore, the root cause event of the Rule 2 is “Event F”. Similarly, the order of occurrence of events in Rule 3 is “Event N”, “Event X” and “Event O”. Therefore, the root cause event of the Rule 3 is “Event O”. Upon generating the one or more rules, the one or more rules are provided to the rules verification system 121 for verification and identifying one or more faults in the one or more rules. The one or more faults are provided to the rules generation system 113, wherein the fault correction module 238 in association with the event linking module 233 automatically corrects and updates the predefined data structure format based on the one or more faults identified by the rules verification system 121. As an example, consider a scenario as illustrated in the FIG.2H. Rule 100 and Rule 103 are derived from the First cluster 3 and First cluster 4 respectively as shown in the below Table 6. Rule number Rules Root cause Rule 100 Event A and Event B and Event H and Event I and Event C Event C Rule 103 Event B and Event H and Event I and Event C Event C Table 6 Upon verifying the Rule 100 and Rule 103 as shown in the above Table 6, the rules verification system 121 identifies the fault that Rule 100 and Rule 103 are redundant. The identified fault is provided by the rules verification system 121 to the rules generation system 113. Upon receiving the identified fault, the fault correction module 239 traverses through the predefined data structure format. Based on the traversal, the fault correction module 238 learns that leaf nodes Event H and Event I are common to both Rule 100 and Rule 103. Therefore, the fault correction module 238 discards Event H and Event I as these two events can be considered as cascaded events due to Event C and thus resolves redundancy. Therefore, Rule 103 is removed and Rule 100 is modified to remove Event H and Event I. Upon discarding the Event H and Event I to resolve redundancy, the event linking module 233 updates the predefined data structure format to reflect the corrections made by the fault correction module 238 as shown in First cluster 5 of the FIG.2I. Upon updation of the predefined data structure format, the process of generation of the one or more rules may be further iterated. FIG.3 illustrates a flowchart showing method for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure. As illustrated in FIG.3, the method 300 comprises one or more blocks illustrating method for generating one or more rules for a root cause analysis system 123. The method 300 may be described in the general context of computer executable instructions. Generally, computer executable instructions can include routines, programs, objects, components, data structures, procedures, modules, and functions, which perform particular functions or implement particular abstract data types. The order in which the method 300 is described is not intended to be construed as a limitation, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks may be deleted from the methods without departing from the spirit and scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or combination thereof. At block 301, one or more first events 105 and process flow data 106 is retrieved from one or more first data sources 103. The process flow data 106 comprises process flow of the one or more first events 105. In an embodiment, the process flow of the one or more events 105 is a systematic flow linking the one or more first events 105 in the source code. The one or more first data sources 103 may include, but not limited to, source codes of one or more applications. At block 303, the process flow data 106 is represented by a processor 115 associated with the rules generation system 113 in a predefined data structure format. The predefined data structure format indicates link between the one or more first events 105 corresponding to the process flow of the one or more first events 106. At block 305, the one or more first events 105 are grouped into one or more first clusters. In an embodiment, the processor 115 groups the one or more first events 105 into one or more first clusters based on the representation in the predefined data structure format. In an embodiment, the one or more first events 105 can be grouped in one or more combinations. At block 307, availability of one or more second events 109 is determined. In an embodiment, the processor 115 determines availability of the one or more second events 109 in one or more second data sources 104. The one or more second events 109 are dynamically occurring events in source codes of the one or more applications present in the one or more second data sources 104 that are distinct from the one or more first events 105. At block 309, a condition is checked to determine the availability of the one or more second events 109. If the processor 115 determines that the one or more second events 109 are available, the method proceeds to block 311 via “Yes”. If the processor 115 determines that the one or more second events 109 are not available, then the method proceeds to block 313 via “No”. At block 311, relationship and level of the relationship of the one or more second events 109 with each of the one or more first events 105 is determined. In an embodiment, the processor 115 determines relationship and level of the relationship of the one or more second events 109 with each of the one or more first events 105 using one or more predefined techniques. As an example, the one or more predefined techniques may include, but not limited to, K-Means clustering algorithm and K-Nearest neighbour algorithm. At block 315, a condition is checked to determine if the relationship of the one or more second events 109 with the one or more first events 105 is positive relationship. If the processor 115 determines that the relationship of the one or more second events 109 with the one or more first events 105 is the positive relationship, the method proceeds to block 319 via “Yes”. If the processor 115 determines that the relationship of the one or more second events 109 with the one or more first events 105 is a negative relationship instead of the positive relationship, the method proceeds to block 317 via “No”. At block 317, the processor 115 discards the one or more second events 109 that are determined to have the negative relationship with the one or more first events 105. At block 319, the one or more second events 109 are linked to the one or more first events 105 based on the level of the relationship. The predefined data structure format is updated upon linking the one or more second events 109 to the one or more first events 105. Upon updating the predefined data structure format, the processor 115 groups the one or more second events 109 and the one or more first events 105 into one or more second clusters. At block 321, one or more rules are generated based on the one or more second clusters. The processor 115 generates the one or more rules based on order of occurrence of the one or more second events 109 in the one or more second clusters. Accordingly, last event in the order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters is said to be root cause identified in the one or more rules. At block 323, the one or more rules are provided to rules verification system 121 associated with the rules generation system 113 for verifying the one or more rules. In an embodiment, the rules verification system 121 may verify the one or more rules and identify one or more faults in the one or more rules using a verification technique disclosed in the Indian Patent Application: 6303/CHE/2015. In an alternative embodiment, the one or more rules may be verified using other verification techniques. Upon verifying the one or more rules, the rules verification system 121 may identify one or more faults and provides the one or more faults to the rules generation system 113. In an embodiment, the one or more faults may be manually corrected by a user. In an alternative embodiment, the processor 115 automatically corrects and updates the predefined data structure format based on the one or more faults identified by the rules verification system 121. Upon updating the predefined data structure format, the rules generation module 237 may continue with the process of generating the one or more rules based on the updated predefined data structure format and the one or more rules may be provided to the root cause analysis system 123. At block 313, the one or more rules are generated based on the one or more first clusters. The processor 115 generates the one or more rules based on order of occurrence of the one or more first events 105 in the one or more first clusters. Accordingly, last event in the order of occurrence of the one or more first events 105 in the one or more first clusters is said to be root cause identified in the one or more rules. Upon generating the one or more rules, the method proceeds to the block 323 for verifying the one or more rules generated. FIG.4 is a block diagram of an exemplary computer system for implementing embodiments consistent with the present disclosure. In an embodiment, the rules generating system 400 is used for generating one or more rules for a root cause analysis system. The rules generating system 400 may comprise a central processing unit (“CPU” or “processor”) 402. The processor 402 may comprise at least one data processor for executing program components for executing user- or system-generated business processes. A user may include a person, a person using a device such as such as those included in this invention, or such a device itself. The processor 402 may include specialized processing units such as integrated system (bus) controllers, memory management control units, floating point units, graphics processing units, digital signal processing units, etc. The processor 402 may be disposed in communication with one or more input/output (I/O) devices (411 and 412) via I/O interface 401. The I/O interface 401 may employ communication protocols/methods such as, without limitation, audio, analog, digital, stereo, IEEE-1394, serial bus, Universal Serial Bus (USB), infrared, PS/2, BNC, coaxial, component, composite, Digital Visual Interface (DVI), high-definition multimedia interface (HDMI), Radio Frequency (RF) antennas, S-Video, Video Graphics Array (VGA), IEEE 802.n /b/g/n/x, Bluetooth, cellular (e.g., Code-Division Multiple Access (CDMA), High-Speed Packet Access (HSPA+), Global System For Mobile Communications (GSM), Long-Term Evolution (LTE), WiMax, or the like), etc. Using the I/O interface 401, the rules generating system 400 may communicate with one or more I/O devices (411 and 412). In some embodiments, the processor 402 may be disposed in communication with a communication network 409 via a network interface 403. The network interface 403 may communicate with the communication network 409. The network interface 403 may employ connection protocols including, without limitation, direct connect, Ethernet (e.g., twisted pair 10/100/1000 Base T), Transmission Control Protocol/Internet Protocol (TCP/IP), token ring, IEEE 802.11a/b/g/n/x, etc. Using the network interface 403 and the communication network 409, the rules generating system 400 may communicate with one or more data sources 410 (a,..,n). The communication network 409 can be implemented as one of the different types of networks, such as intranet or Local Area Network (LAN) and such within the organization. The communication network 409 may either be a dedicated network or a shared network, which represents an association of the different types of networks that use a variety of protocols, for example, Hypertext Transfer Protocol (HTTP), Transmission Control Protocol/Internet Protocol (TCP/IP), Wireless Application Protocol (WAP), etc., to communicate with each other. Further, the communication network 409 may include a variety of network devices, including routers, bridges, servers, computing devices, storage devices, etc. The one or more data sources 410 (a,…,n) may be sources codes of one or more applications or cloud environment, monitoring environment, external systems or the like which generates events.. In some embodiments, the processor 402 may be disposed in communication with a memory 405 (e.g., RAM, ROM, etc. not shown in Fig.4) via a storage interface 404. The storage interface 404 may connect to memory 405 including, without limitation, memory drives, removable disc drives, etc., employing connection protocols such as Serial Advanced Technology Attachment (SATA), Integrated Drive Electronics (IDE), IEEE-1394, Universal Serial Bus (USB), fiber channel, Small Computer Systems Interface (SCSI), etc. The memory drives may further include a drum, magnetic disc drive, magneto-optical drive, optical drive, Redundant Array of Independent Discs (RAID), solid-state memory devices, solid-state drives, etc. The memory 405 may store a collection of program or database components, including, without limitation, user interface application 406, an operating system 407, web server 408 etc. In some embodiments, rules generating system 400 may store user/application data 406, such as the data, variables, records, etc. as described in this invention. Such databases may be implemented as fault-tolerant, relational, scalable, secure databases such as Oracle or Sybase. The operating system 407 may facilitate resource management and operation of the rules generating system 400. Examples of operating systems include, without limitation, Apple Macintosh OS X, UNIX, Unix-like system distributions (e.g., Berkeley Software Distribution (BSD), FreeBSD, NetBSD, OpenBSD, etc.), Linux distributions (e.g., Red Hat, Ubuntu, Kubuntu, etc.), International Business Machines (IBM) OS/2, Microsoft Windows (XP, Vista/7/8, etc.), Apple iOS, Google Android, Blackberry Operating System (OS), or the like. User interface 406 may facilitate display, execution, interaction, manipulation, or operation of program components through textual or graphical facilities. For example, user interfaces may provide computer interaction interface elements on a display system operatively connected to the rules generating system 400, such as cursors, icons, check boxes, menus, scrollers, windows, widgets, etc. Graphical User Interfaces (GUIs) may be employed, including, without limitation, Apple Macintosh operating systems’ Aqua, IBM OS/2, Microsoft Windows (e.g., Aero, Metro, etc.), Unix X-Windows, web interface libraries (e.g., ActiveX, Java, Javascript, AJAX, HTML, Adobe Flash, etc.), or the like. In some embodiments, the rules generating system 400 may implement a web browser 408 stored program component. The web browser may be a hypertext viewing application, such as Microsoft Internet Explorer, Google Chrome, Mozilla Firefox, Apple Safari, etc. Secure web browsing may be provided using Secure Hypertext Transport Protocol (HTTPS) secure sockets layer (SSL), Transport Layer Security (TLS), etc. Web browsers may utilize facilities such as AJAX, DHTML, Adobe Flash, JavaScript, Java, Application Programming Interfaces (APIs), etc. In some embodiments, the rules generating system 400 may implement a mail server stored program component. The mail server may be an Internet mail server such as Microsoft Exchange, or the like. The mail server may utilize facilities such as Active Server Pages (ASP), ActiveX, American National Standards Institute (ANSI) C++/C#, Microsoft .NET, CGI scripts, Java, JavaScript, PERL, PHP, Python, WebObjects, etc. The mail server may utilize communication protocols such as Internet Message Access Protocol (IMAP), Messaging Application Programming Interface (MAPI), Microsoft Exchange, Post Office Protocol (POP), Simple Mail Transfer Protocol (SMTP), or the like. In some embodiments, the rules generating system 400 may implement a mail client stored program component. The mail client may be a mail viewing application, such as Apple Mail, Microsoft Entourage, Microsoft Outlook, Mozilla Thunderbird, etc. Furthermore, one or more computer-readable storage media may be utilized in implementing embodiments consistent with the present invention. A computer-readable storage medium refers to any type of physical memory on which information or data readable by a processor may be stored. Thus, a computer-readable storage medium may store instructions for execution by one or more processors, including instructions for causing the processor(s) to perform steps or stages consistent with the embodiments described herein. The term “computer-readable medium” should be understood to include tangible items and exclude carrier waves and transient signals, i.e., non-transitory. Examples include Random Access Memory (RAM), Read-Only Memory (ROM), volatile memory, non-volatile memory, hard drives, Compact Disc (CD) ROMs, Digital Video Disc (DVDs), flash drives, disks, and any other known physical storage media. Advantages of the embodiment of the present disclosure are illustrated herein. In an embodiment, the present disclosure provides a method and a system for generating one or more rules for a root cause analysis system. The present disclosure provides a feature wherein the rules generating system is adaptive and is capable of generating one or more rules automatically for any rules based system. The present disclosure enables use of minimum resources to generate the one or more rules for the root cause analysis system. The present disclosure reduces cost for deploying the root cause analysis system. The present disclosure provides enhances reliability of the root cause analysis system by performing automatic verification of the one or more rules and removing errors from the one or more rules based on the automatic verification. A description of an embodiment with several components in communication with each other does not imply that all such components are required. On the contrary a variety of optional components are described to illustrate the wide variety of possible embodiments of the invention. When a single device or article is described herein, it will be readily apparent that more than one device/article (whether or not they cooperate) may be used in place of a single device/article. Similarly, where more than one device or article is described herein (whether or not they cooperate), it will be readily apparent that a single device/article may be used in place of the more than one device or article or a different number of devices/articles may be used instead of the shown number of devices or programs. The functionality and/or the features of a device may be alternatively embodied by one or more other devices which are not explicitly described as having such functionality/features. Thus, other embodiments of the invention need not include the device itself. The specification has described a method and a system for generating one or more rules for a root cause analysis system. The illustrated steps are set out to explain the exemplary embodiments shown, and it should be anticipated that on-going technological development will change the manner in which particular functions are performed. These examples are presented herein for purposes of illustration, and not limitation. Further, the boundaries of the functional building blocks have been arbitrarily defined herein for the convenience of the description. Alternative boundaries can be defined so long as the specified functions and relationships thereof are appropriately performed. Alternatives (including equivalents, extensions, variations, deviations, etc., of those described herein) will be apparent to persons skilled in the relevant art(s) based on the teachings contained herein. Such alternatives fall within the scope and spirit of the disclosed embodiments. Also, the words "comprising," "having," "containing," and "including," and other similar forms are intended to be equivalent in meaning and be open ended in that an item or items following any one of these words is not meant to be an exhaustive listing of such item or items, or meant to be limited to only the listed item or items. It must also be noted that as used herein and in the appended claims, the singular forms “a,” “an,” and “the” include plural references unless the context clearly dictates otherwise. Finally, the language used in the specification has been principally selected for readability and instructional purposes, and it may not have been selected to delineate or circumscribe the inventive subject matter. It is therefore intended that the scope of the invention be limited not by this detailed description, but rather by any claims that issue on an application based here on. Accordingly, the embodiments of the present invention are intended to be illustrative, but not limiting, of the scope of the invention, which is set forth in the following claims. Referral numerals Reference Number Description 100 Architecture 103 One or more first data sources 104 One or more second data sources 105 One or more first events 106 Process flow data 109 One or more second events 111 Communication network 113 Rules generation system 115 Processor 117 I/O interface 119 Memory 121 Rules verification system 123 Root cause analysis system 203 Data 205 Modules 209 Cluster data 211 Data related to predefined data structure 213 Relationship data 215 Rules data 219 Other data 223 Retrieving module 225 First analysis module 227 Event clustering module 229 Second analysis module 231 Event relationship determining module 233 Event linking module 237 Rules generation module 238 Fault correction module 239 Other modules 241 X-axis (denoting Resource type) 241a Central Processing Unit 241b Network 241c Storage 243 Y-axis (denoting Event type) 243a Less than threshold value 243b Normal value 243c Greater than threshold value

Specification

Claims:1. A method for generating one or more rules for a root cause analysis system 113, the method comprising:
retrieving, by a rules generation system 113, one or more first events 105 and process flow of the one or more first events 105 from one or more first data sources 103;
representing, by the rules generation system 113, the process flow of the one or more first events 106 in a predefined data structure format;
grouping, by the rules generation system 113, the one or more first events 105 represented in the predefined data structure format into one or more first clusters;
determining, by the rules generation system 113, availability of one or more second events 109 in one or more second data sources 104;
updating dynamically, by the rules generation system 113, the predefined data structure format by linking the one or more second events 109 to the one or more first events 105 if the one or more second events 109 are available, wherein the one or more first events 105 and the one or more second events 109 are grouped into one or more second clusters; and
generating, by the rules generation system 113, one or more rules based on at least one of the one or more first clusters or the one or more second clusters.
2. The method as claimed in claim 1 further comprises:

providing, by the rules generation system 113, the one or more rules to a rules verification system 121 associated with the rules generation system 113 for identifying one or more faults in the one or more rules;

receiving, by the rules generation system 113, the one or more faults in the one or more rules from the rules verification system 121; and

updating dynamically, by the rules generation system 113, the predefined data structure format based on the one or more faults in the one or more rules.

3. The method as claimed in claim 1, wherein the one or more second events 109 are distinct from the one or more first events 105.

4. The method as claimed in claim 1, wherein linking the one or more second events 109 to the one or more first events 105 comprises:
determining, by the rules generation system 113, a relationship and a level of the relationship of each of the one or more second events 109 with each of the one or more first events 105, wherein the relationship is at least one of a positive relationship and a negative relationship; and
linking, by the rules generation system 113, the one or more second events 109 to one of the one or more first events 105 based on the level of the relationship when the relationship is determined to be the positive relationship.
5. The method as claimed in claim 1, wherein the one or more rules are generated based on at least one of order of occurrence of the one or more first events 105 in the one or more first clusters or order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters.

6. The method as claimed in claim 5 further comprises determining, by the rules generation system 113, last event in the order of occurrence of the one or more first events 105 and the one or more second events 109, wherein the last event is root cause event of the one or more rules.

7. A rules generation system 113 for generating one or more rules for a root cause analysis system 123, the rules generation system 113 comprising:

a processor 115; and
a memory 119 communicatively coupled to the processor 115, wherein the memory 119 stores the processor-executable instructions, which, on execution, causes the processor 115 to:
retrieve one or more first events 105 and process flow of the one or more first events 105 from one or more first data sources 103;

represent the process flow of the one or more first events 105 in a predefined data structure format;

group the one or more first events 105 represented in the predefined data structure format into one or more first clusters;

determine availability of one or more second events 109 in one or more second data sources 104;

update dynamically, the predefined data structure format by linking the one or more second events 109 to the one or more first events 105 if the one or more second events 109 are available, wherein the one or more first events 105 and the one or more second events 109 are grouped into one or more second clusters; and

generate one or more rules based on at least one of the one or more first clusters or the one or more second clusters.

8. The rules generation system 113 as claimed in claim 7, wherein the processor 115 is further configured to:

provide the one or more rules to a rules verification system 121 associated with the rules generation system 113 for identifying one or more faults in the one or more rules;

receive the one or more faults in the one or more rules from the rules verification system 121; and

update the predefined data structure format based on the one or more faults in the one or more rules.

9. The rules generation system 113 as claimed in claim 7, wherein the one or more second events 109 are distinct from the one or more first events 105.

10. The rules generation system 113 as claimed in claim 7, wherein the processor 115 links the one or more second events 109 to the one or more first events 105 by:

determine a relationship and a level of the relationship of each of the one or more second events 109 with each of the one or more first events 105, wherein the relationship is at least one of a positive relationship and a negative relationship; and

link the one or more second events 109 to one of the one or more first events 105 based on the level of the relationship when the relationship is determined to be the positive relationship.

11. The rules generation system 113 as claimed in claim 7, wherein the processor 115 generates the one or more rules based on at least one of order of occurrence of the one or more first events 105 in the one or more first clusters or order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters.

12. The rules generation system 113 as claimed in claim 11 wherein the processor 115 is further configured to determine last event in the order of occurrence of the one or more first events 105 and the one or more second events 109, wherein the last event is root cause event of the one or more rules.
, Description:TECHNICAL FIELD

The present subject matter is related, in general to root cause analysis system and more particularly, but not exclusively to a method and a system for generating one or more rules for a root cause analysis system.

BACKGROUND

A root cause analysis system is used to troubleshoot all the errors occurring in any environment and identifies ultimate source of the problem based on one or more rules. As an example, in a cloud computing environment a fault might have occurred while providing resources to one or more computing devices connected in the cloud computing environment. The root cause analysis system configured in the cloud computing environment may identify the fault or a root cause event causing the fault and indicates a source of the problem. The root cause analysis system accepts one or more rules as input data. The one or more rules define relationship among failing conditions in the environment. Further, the one or more rules define reason for root cause failure for a set of failure conditions. However, existing root cause analysis systems currently have three major problems. Firstly, the time taken to manually create the one or more rules as input data for the root cause analysis system is more due to which there may be significant delay in productizing the root cause analysis system. Secondly, amount of human effort required to manually create the one or more rules for the root cause analysis system is high. Thirdly, the root cause analysis system may face the problem of having incomplete rules as the input data due to unaccounted events that may have occurred, thus leaving the user with insufficient information to troubleshoot complex scenarios.

Currently, conventional rules generation methods generate validation rules for a particular column data of a table i.e. the system may generate few rules per each column. A few other conventional methods only generate a method flow of events. But the existing techniques are limited only for a few systems and particularly only for certain data present in the few systems. Further, the existing techniques have manual intervention to a large extent that may risk in reliability of the one or more rules generated. Also, due to the manual intervention, time taken to generate the one or more rules and efforts involved in generating the one or more rules may be high, thereby decreasing the rate at which the rules may be generated for a root cause analysis system.
SUMMARY
One or more shortcomings of the prior art are overcome and additional advantages are provided through the present disclosure. Additional features and advantages are realized through the techniques of the present disclosure. Other embodiments and aspects of the disclosure are described in detail herein and are considered a part of the claimed disclosure.
Disclosed herein are a method and a system for generating one or more rules for a root cause analysis system. A rules generation system retrieves one or more first events and process flow of the one or more first events from existing source codes and generates one or more rules automatically for use in the root cause analysis system. The rules generation system generates the one or more rules by clustering the one or more first events that are linked through the process flow in a predefined data structure format. Therefore, the rules generation system enables use of minimum resources to generate the one or more rules as the process of generating the one or more rules is automatic and increases overall speed of deploying root cause analysis system. Further, the rules generation system also caters the need of dynamically occurring events. The dynamically occurring events are linked to the existing events by determining a correlation factor and thus updating the predefined data structure format to generate one or more rules. Further, the rules generating system is adaptive and is capable of generating one or more rules automatically for any rules based system.

Accordingly, the present disclosure provides a method for generating one or more rules for a root cause analysis system. The method comprises retrieving by a rules generation system, one or more first events and process flow of the one or more first events from one or more first data sources. Further, the rules generation system represents the process flow of the one or more first events in a predefined data structure format. Upon representing the process flow, the rules generation system groups the one or more first events represented in the predefined data structure format into one or more first clusters. Thereafter, the rules generation system determines availability of one or more second events in one or more second data sources. Upon determining the availability, the rules generation system dynamically updates the predefined data structure format by linking the one or more second events to the one or more first events if the one or more second events are available. The one or more first events and the one or more second events are grouped into one or more second clusters. Finally, the rules generation system generates one or more rules based on at least one of the one or more first clusters or the one or more second clusters.
Further, the present disclosure comprises a rules generation system for generating one or more rules for a root cause analysis system. The rules generation system comprises a processor and a memory communicatively coupled to the processor, wherein the memory stores the processor-executable instructions, which, on execution, causes the processor to retrieve one or more first events and process flow of the one or more first events from one or more first data sources. Further, the processor is configured to represent the process flow of the one or more first events in a predefined data structure format. Upon representing the process flow, the processor is configured to group the one or more first events represented in the predefined data structure format into one or more first clusters. Further, the processor is configured to determine availability of one or more second events in one or more second data sources. Thereafter, the processor is configured to update dynamically, the predefined data structure format by linking the one or more second events to the one or more first events if the one or more second events are available. The one or more first events and the one or more second events are grouped into one or more second clusters. Finally, the processor is configured to generate one or more rules based on at least one of the one or more first clusters or the one or more second clusters.

The foregoing summary is illustrative only and is not intended to be in any way limiting. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features will become apparent by reference to the drawings and the following detailed description.
BRIEF DESCRIPTION OF THE ACCOMPANYING DIAGRAMS
The accompanying drawings, which are incorporated in and constitute a part of this disclosure, illustrate exemplary embodiments and, together with the description, serve to explain the disclosed principles. In the figures, the left-most digit(s) of a reference number identifies the figure in which the reference number first appears. The same numbers are used throughout the figures to reference like features and components. Some embodiments of system and/or methods in accordance with embodiments of the present subject matter are now described, by way of example only, and with reference to the accompanying figures, in which:
FIG.1A shows an exemplary architecture for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure;
FIG.1B shows an exemplary architecture illustrating an environment involving a rules generation system and a rules verification system in accordance with some embodiments of the present disclosure;
FIG.2A shows a detailed block diagram of a rules generation system for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure;
FIG.2B shows an exemplary predefined data structure format representing the one or more events in accordance with some embodiments of the present disclosure;
FIG.2C shows exemplary clusters formed by grouping one or more exemplary events in accordance with some embodiments of the present disclosure;
FIG.2D shows an exemplary predefined data structure format representing one or more first events as illustrated in scenario 1 in accordance with some embodiments of the present disclosure;
FIG.2E shows exemplary one or more first clusters formed by grouping one or more first events as illustrated in scenario 1 in accordance with some embodiments of the present disclosure;
FIG.2F shows a graph of exemplary vector space representing relationship of the one or more first events with one or more second events in accordance with some embodiments of the present disclosure;
FIG.2G shows exemplary one or more second clusters formed by linking one or more second events in accordance with some embodiments of the present disclosure;
FIG.2H and FIG.2I shows exemplary clusters illustrating correction and modification of the one or more rules to resolve redundancy in accordance with some embodiments of the present disclosure;
FIG.3 illustrates a flowchart showing method for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure; and
FIG.4 is a block diagram of an exemplary computer system for implementing embodiments consistent with the present disclosure.
It should be appreciated by those skilled in the art that any block diagrams herein represent conceptual views of illustrative systems embodying the principles of the present subject matter. Similarly, it will be appreciated that any flow charts, flow diagrams, state transition diagrams, pseudo code, and the like represent various processes which may be substantially represented in computer readable medium and executed by a computer or processor, whether or not such computer or processor is explicitly shown.
DETAILED DESCRIPTION
In the present document, the word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the present subject matter described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments.
While the disclosure is susceptible to various modifications and alternative forms, specific embodiment thereof has been shown by way of example in the drawings and will be described in detail below. It should be understood, however that it is not intended to limit the disclosure to the particular forms disclosed, but on the contrary, the disclosure is to cover all modifications, equivalents, and alternative falling within the scope of the disclosure.
The terms “comprises”, “comprising”, or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a setup, device or method that comprises a list of components or steps does not include only those components or steps but may include other components or steps not expressly listed or inherent to such setup or device or method. In other words, one or more elements in a system or apparatus proceeded by “comprises… a” does not, without more constraints, preclude the existence of other elements or additional elements in the system or method.
The present disclosure provides a method for generating one or more rules for a root cause analysis system. A rules generation system retrieves one or more first events and process flow of the one or more first events from one or more first data sources. Upon retrieving the one or more first events and process flow of the one or more first events, the rules generation system represents the process flow of the one or more first events in a predefined data structure format. Further, the rules generation system groups the one or more first events represented in the predefined data structure format into one or more first clusters. Thereafter, the rules generation system determines availability of one or more second events in one or more second data sources. Upon determining the availability, the rules generation system dynamically updates the predefined data structure format by linking the one or more second events to the one or more first events if the one or more second events are available. The one or more first events and the one or more second events are grouped into one or more second clusters. Finally, the rules generation system generates one or more rules based on at least one of the one or more first clusters or the one or more second clusters. The rules generating system disclosed in the present disclosure is adaptive and is capable of generating one or more rules automatically for any rules based system. Since the generation of the one or more rules is automatic, the present disclosure reduces cost for deploying the root cause analysis system. Further, the present disclosure enhances reliability of the root cause analysis system by performing automatic verification of the one or more rules and removing errors from the one or more rules based on the automatic verification.

In the following detailed description of the embodiments of the disclosure, reference is made to the accompanying drawings that form a part hereof, and in which are shown by way of illustration specific embodiments in which the disclosure may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the disclosure, and it is to be understood that other embodiments may be utilized and that changes may be made without departing from the scope of the present disclosure. The following description is, therefore, not to be taken in a limiting sense.

FIG.1A shows an exemplary architecture for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure.
The architecture 100 comprises one or more first data sources, first data source 1 1031 to first data source n 103n (collectively referred to as one or more first data sources 103), one or more second data sources, second data source 1 1041 to second data source n 104n (collectively referred to as one or more second data sources 104), a communication network 111 and a rules generation system 113. As an example, the one or more first data sources 103 may include, but not limited to, source codes of one or more applications. As an example, one or more second data sources 104 may include, but not limited to, a cloud environment, a monitoring system and an external system. The one or more first data sources 103 and the one or more second data sources 104 communicate with the rules generation system 113 through the communication network 111. As an example, the communication network 111 may be at least one of a wired communication network and a wireless communication network.
The rules generation system 113 comprises a processor 115, an Input/output (I/O) interface 117 and a memory 119. In an embodiment, the processor 115 extracts one or more first events 105 and process flow data 106 from the one or more first data sources 103 i.e. the source codes of the one or more applications. The process flow data 106 comprises process flow of the one or more first events 105. In an embodiment, the process flow of the one or more events 105 is a systematic flow linking the one or more first events 105 in the source code. The I/O interface 117 retrieves the extracted one or more first events 105 and the process flow data 106 from the one or more first data sources 103. The one or more first events 105 may be any part of the source code comprising useful information such as Log information, monitoring information and one or more system generated events. In an alternative embodiment, the I/O interface 117 may directly retrieve pre-stored one or more first events and pre-stored process flow data 106 from the one or more first data sources 103. The received one or more first events 105 and the process flow data 106 are stored in the memory 119. The memory 119 is communicatively coupled to the processor 115.
Upon receiving the one or more first events 105 the processor 115 represents the process flow data 106 in a predefined data structure format. As an example, the predefined data structure format may include, but not limited to, a tree. Further, the processor 115 groups the one or more events 105 represented in the predefined data structure format into one or more first clusters. Upon forming the one or more first clusters, the processor 115 checks for the availability of one or more second events 109 in the one or more second data sources 104. The one or more second events 109 are dynamically occurring events that are distinct from the one or more first events 105. If, the one or more second events 109 are available, the processor 109 determines relationship of the one or more second events 109 with the one or more first events 105 and updates the predefined data structure based on the determined relationship. The processor 115 further groups the one or more first events 105 and the one or more second events 109 into one or more second clusters based on the updated predefined data structure format. Thereafter, the processor 115 generates one or more rules based on either the one or more first clusters or the one or more second clusters.
In an embodiment, upon generating the one or more rules, the rules generation system 113 transmits the one or more rules to a rules verification system 121 through the I/O interface 117 as shown in the FIG.1B. The rules verification system 121 identifies the one or more faults in the one or more rules and provides the one or more faults to the rules generation system 113. The one or more faults may be manually corrected by a user. In an alternative embodiment, the processor 115 automatically corrects and updates the predefined data structure format based on the one or more faults identified by the rules verification system 121. Upon updating the predefined data structure format, the rules generation system 113, may continue with the process of generating the one or more rules based on the updated predefined data structure format. In an embodiment, the one or more rules may be provided to the root cause analysis system 123 as shown in the FIG.1B.
FIG.2A shows a detailed block diagram of a rules generation system for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure.
In one implementation, the rules generation system 113 receives data from the one or more first data sources 103 and one or more second data sources 104 associated with the rules generation system 113. As an example, the data 203 may be stored in the memory 119 configured in the rules generation system 113. In one embodiment, the data 203 comprises one or more first events 105, process flow data 106, one or more second events 109, a cluster data 209, data related to a predefined data structure format 211, a relationship data 213, rules data 215 and other data 219. In the illustrated Fig.2, modules 205 are described here in detail.
In one embodiment, the data 203 may be stored in the memory 119 in the form of various data structures. Additionally, the aforementioned data 203 can be organized using data models, such as relational or hierarchical data models. The other data 219 may store data, including temporary data and temporary files, generated by modules 205 for performing the various functions of the rules generation system 113.
In an embodiment, one or more first events 105 are retrieved from the one or more first data sources 103. The one or more first events 105 may be any part of the source code comprising useful information such as Log information, monitoring information and information related to one or more system generated events. In an embodiment, the useful information may comprise one or more predefined keywords based on which the rules generation system 113 may recognize the one or more first events 105 from the one or more first data sources 103 using a predefined technique which may include, but not limited to, Natural Language Processing (NLP) technique. As an example, the one or more predefined keywords may be “Exception”, “Error”, “Not found”, “Notify”, “Log” etc. The one or more first data sources 103 may include, but not limited to, source codes of one or more applications.
As an example consider a source code 1 as shown below:
Throw event("User not authorized")
If event== logarithmic_error:
Print "we are handling error now"
Throw event("system error")
Throw event("Unknown exception")
In the above source code 1, the one or more first events 105 are "User not authorized", “Logarithmic error”, “System error” and “Unknown exception”. In an embodiment, the process flow data 106 comprises process flow of the one or more first events 105. The process flow data 106 is retrieved from the one or more first data sources 103. The process flow is a systematic flow that links the one or more first events 105 in the source code.
As an example, consider source code 2, source code 3 and source code 4 as shown in the below Table 1.
Source code 2
Method 1:
If Event A
Event B
Method 2
Event C
Else if Event D
Event E
Method 3
Event F
Else
Event G
Event P Source code 3
Method 2:
If Event H
Event I
Else if Event J
Event K
Source code 4
Method 3:
If Event L
Event M
Else if Event N
Event O

Table 1
The process flow of the source code 2, source code 3 and source code 4 is as shown below:
Method 1 Method 2 Method 3
In an embodiment, the one or more second events 109 are dynamically occurring events. In an embodiment, the dynamically occurring events are the events, related to one or more applications, which are generated at the one or more second data sources. As an example, the one or more second data sources 104 may include, but not limited to, a cloud environment, a monitoring system and an external system.
In an embodiment, the cluster data 209 comprises one or more first clusters formed by grouping the one or more first events 105 represented in a predefined data structure format such as a tree. The cluster data 209 further comprises the one or more second clusters formed by grouping the one or more first events and the one or more second events together in various combinations.
In an embodiment, the data related to the predefined data structure format 211 comprises a predefined data structure format such as a tree representing the one or more first events 105 based on the process flow data 106. Further, the data related to the predefined data structure format 211 also comprises the predefined data structure representing the one or more second events 109 linked to the one or more first events 105.
In an embodiment, the relationship data 213 comprises a value specifying relationship of the one or more second events 106 with one or more first events 105. The relationship data 213 defines correlation of related events based on properties of the one or more first events 105 and one or more second events 106 such as “Event type” and “Resource type”. “Event type” indicates types of the one or more first events 105 and the one or more second events 109 that are categorized based on effects of the one or more first events 105 and the one or more second events 109 on the one or more applications. An “Event type value” is associated with each “Event type”, wherein the “Event type value” is predefined. As an example, the “Event type” may include, but not limited to, the types as shown in the below Table 2.

Event type Event type value
Less than threshold value 243a 1
Normal 243b 2
Greater than threshold value 243c 3
Table 2
In an embodiment, the threshold value may be predefined in the rules generation system 113.
“Resource type” indicates type of one or more resources associated with the one or more first events 105 and the one or more second events 109. A “Resource type value” is associated with each “Resource type”. As an example, the “Resource type” may include, but not limited to, the types as shown in the below Table 3.
Resource type Resource type value
Central Processing Unit (CPU) 241a 1
Network 241b 2
Storage 241c 3

Table 3
In an embodiment, the rules data 215 comprises one or more rules that are generated based on the one or more first clusters and the one or more second clusters. The one or more rules define relationship among failing conditions and define root cause for a set of failure conditions. In an embodiment, the data stored in the memory 119 is processed by the modules 205 of the rules generation system 113. The modules 205 may be stored within the memory 113. In an example, the modules 205, communicatively coupled to a processor 115 configured in the rules generation system 113, may also be present outside the memory 119 as shown in FIG.2A and implemented as hardware. As used herein, the term module refers to an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group) and memory that execute one or more software or firmware programs, a combinational logic circuit, and/or other suitable components that provide the described functionality.
In an embodiment, the modules 205 may include, for example, a retrieving module 223, a first analysis module 225, an event clustering module 227, a second analysis module 229, an event relationship determining module 231, an event linking module 233, a rules generation module 237, fault correction module 238 and other modules 239. The other modules 239 may be used to perform various miscellaneous functionalities of the rules generation system 113. It will be appreciated that such aforementioned modules 205 may be represented as a single module or a combination of different modules.
In an embodiment, the retrieving module 223 retrieves the one or more first events 105 and the process flow data 106 from the one or more first data sources 103.
In an embodiment, the first analysis module 225 represents the process flow data 106 in the predefined data structure format. The predefined data structure format indicates link between the one or more first events 105 corresponding to the process flow data 106.
In an embodiment, the event clustering module 227 groups the one or more first events 105 into one or more first clusters based on the representation in the predefined data structure format. In an embodiment, the one or more first events 105 can be grouped in one or more combinations. As an example, consider that the predefined data structure format is a tree, the one or more first events 105 may be nodes of the tree as shown in the FIG.2B. “Node A” is the root node of the tree and rest of the one or more first events 105 represented by “Node B”, “Node C”, “Node D”, “Node E”, “Node F”, “Node G”, “Node H”, “Node I”, “Node J” and “Node K” are the child nodes of the root node “Node A”. “Node A” is a parent node of child nodes “Node B”, “Node C” and “Node D”. “Node B” is the parent node of the child nodes “Node E” and “Node F”. “Node C” is the parent node of child nodes “Node G”, “Node H” and “Node I”. And “Node I” is the parent node of the child nodes “Node J” and “Node K”. The one or more first events 105 are grouped in the one or more combinations such as parent node-child node combination, parent node-parent node combination, child node-child node combination etc. at any depth of the tree. As shown in FIG.2C, Cluster 1 represents the parent node-child node combination between “Node B”, “Node E” and “Node F” that are present at the same depth i.e. depth 2. Similarly, Cluster 2 represents the child node-child node combination between “Node G” and “Node H” that are present at two different depths of the tree i.e. “Node G” and “Node H” at depth 2. Similarly, Cluster 3 represents the parent node-child node combination between “Node D”, “Node I” and “Node K” that are present at three different depths of the tree i.e. “Node D” at depth 1, “Node I” at depth 2 and “Node K” at depth 3.
In an embodiment, the second analysis module 229 determines availability of the one or more second events 109 in one or more second data sources 104. In an embodiment, the second analysis module 229 receives all the dynamically occurring events from the one or more second data sources 104 through the I/O interface 117 and stores in the memory 119. Upon receiving all the dynamically occurring events, the second analysis module 229 activates a predefined filter to select only the dynamically occurring events i.e. the one or more second events 109 that are different from the one or more first events 105. In an embodiment, the predefined filter is a condition based on which the dynamically occurring events which resemble the one or more first events 105 are removed or not considered for further operations. Therefore, the second analysis module 229 compares each of the dynamically occurring events with the one or more first events 105 based on the predefined filter. Based on the comparison, the second analysis module 229 eliminates the dynamically occurring events that are same as the one or more first events 105 and retains the one or more second events 109 in the memory 119.
In an alternative embodiment, the second analysis module 229 directly compares each of the dynamically occurring events with the one or more first events 105 based on the predefined filter at the one or more second data sources 104. Based on the comparison, the retrieving module 223 retrieves only the one or more second events 109 from the one or more second data sources 104. If the second analysis module 229 determines that the one or more second events 109 are available, the second analysis module 229 activates the event relationship determining module 231. If the second analysis module 229 determines that the one or more second events 109 are not available, then the second analysis module 229 activates the rule generation module 237.
In an embodiment, the event relationship determining module 231 determines relationship and level of the relationship of the one or more second events 109 with each of the one or more first events 105 using one or more predefined techniques. As an example, the one or more predefined techniques may include, but not limited to, K-Means clustering algorithm and K-Nearest neighbour algorithm. In an embodiment, the relationship may be a positive relationship or a negative relationship. As an example, consider two events “Event 1” and “Event 2”. If there exists a possibility that “Event 1” may occur if the “Event 2” occurs and the vice-versa, then the relationship between “Event 1” and “Event 2” is determined to be the positive relationship. If there exists no possibility that “Event 1” may occur if the “Event 2” occurs and the vice-versa i.e. if “Event 1” and “Event 2” can never occur together, then the relationship between “Event 1” and “Event 2” is determined to be the negative relationship. The relationship and the level of relationship is determined by plotting the relationship data 213 corresponding to the one or more first events 105 and the one or more second events 109 in a vector space. The relationship data 213 corresponding to the one or more first events 105 and the one or more second events 109 provides dimensions for the vector space. The relationship data 213 comprising the event type along with the event type value and the resource type along with the resource type value corresponding to each of the one or first events 105 and each of the one or more second events 109 generates Event vectors of the one or more first events 105 and each of the one or more second events 109. The Event vectors are plotted in the vector space. An exemplary vector space indicating exemplary Event vectors are shown in FIG.2F. Upon plotting the Event vectors, the relationship and the level of the relationship of the one or more second events 109 with the one or more first events 105 is determined using at least one of the one or more predefined techniques.
In an embodiment, the event linking module 233 updates the predefined data structure format representing the process flow data 106 to incorporate the one or more second events 109. The event linking module 233 updates the predefined data structure format by linking the one or more second events 109 to the one or more first events 105 based on the level of the relationship, if the relationship is determined to be the positive relationship. Upon updating the predefined data structure format, the event clustering module 227 groups the one or more first events 105 and the one or more second events 109 into one or more second clusters. Thereafter, the event clustering module 227 activates the rule generation module 237. In an embodiment, if the relationship between the one or more first events 105 and the one or more second events 109 is determined to be the negative relationship, then event linking module 233 discards the one or more second events 109.
In an embodiment, the rules generation module 237 generates the one or more rules based on the one or more first clusters or the one or more second clusters. If the rules generation module 237 considers the one or more first clusters, then the rules generation module 237 generates the one or more rules based on order of occurrence of the one or more first events 105 in the one or more first clusters. Accordingly, last event in the order of occurrence of the one or more first events 105 in the one or more first clusters is said to be root cause identified in the one or more rules. If the rules generation module 237 considers the one or more second clusters, then the rules generation module 237 generates the one or more rules based on order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters. Accordingly, last event in the order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters is said to be root cause identified in the one or more rules. Upon generating the one or more rules, the rules generation module 237 provides the one or more rules to rules verification system 121 associated with the rules generation system 113 for verifying the one or more rules.

In an embodiment, the rules verification system 121 may use a verification technique disclosed in the Indian Patent Application: 6303/CHE/2015 to verify the one or more rules. Entire content of the Indian Patent Application: 6303/CHE/2015 is incorporated by reference herein. In an alternative embodiment, the rules verification system 121 may use other verification techniques to verify the one or more rules. Upon verifying the one or more rules, the rules verification system 121 identifies the one or more faults in the one or more rules and provides the one or more faults to the rules generation system 113. The one or more faults can be manually corrected as illustrated in the Indian Patent Application: 6303/CHE/2015. The faults may arise due to parameters related to rules such as redundancy, incorrectness, incompleteness, inconsistency, non-satisfactory etc.

In an embodiment, the fault correction module 238 in association with the event linking module 233 automatically corrects and updates the predefined data structure format based on the one or more faults identified by the rules verification system 121. Upon updating the predefined data structure format, the rules generation module 237 may continue with the process of generating the one or more rules based on the updated predefined data structure format. Further, in an embodiment, the one or more rules may be provided to the root cause analysis system 123.

Scenario 1

Consider source code 2, source code 3 and source code 4 as shown in the below Table 1.
Source code 2
Method 1:
If Event A
Event B
Method 2
Event C
Else if Event D
Event E
Method 3
Event F
Else
Event G
Event P Source code 3
Method 2:
If Event H
Event I
Else if Event J
Event K
Source code 4
Method 3:
If Event L
Event M
Else if Event N
Event O

Table 1
The process flow of the one or more first events 106 of the source code 2, source code 3 and source code 4 is as shown below:
Method 1 Method 2 Method 3
The one or more first events 105 extracted from the source code 2, source code 3 and source code 4 are as shown in the below Table 4a, Table 4b and Table 4c respectively.
Method 1
Event A Event B Method 2 Event C
Event D Event E Method 3 Event F
Event G Event P

Table 4a
Method 2
Event H Event I
Event J Event K

Table 4b
Method 3
Event L Event M
Event N Event O

Table 4c

The one or more first events 105 extracted as shown in the above tables Table 4a, Table 4b and Table 4c are represented in a predefined data structure format as shown in the FIG.2D based on the process flow data 106. In this scenario, the predefined data structure format used is a tree. Upon representing the one or more first events 105 in the predefined data structure format, the one or more first events 105 are grouped into one or more first clusters as shown in the FIG.2E. The FIG.2E represents first cluster 1 comprising the events “Event A”, “Event B”, “Event C”, “Event H” and “Event I” and first cluster 2 comprising “Event F”, “Event N” and “Event O”.

Upon grouping the one or more first events 105 into one or more first clusters, the availability of the one or more second events 109 is determined, wherein availability of a second event “Event X” is determined. The resource data 213 of the one or more first events 105 of the first cluster 1 and the first cluster 2 is obtained based on the above tables Table 2 and Table 3.

“Event A” belongs to the resource type “storage 241c” and event type “greater than threshold value 243c”. Therefore, the resource type value of the “Event A” is 3 and the event type value of the “Event A” is 3. Based on the resource type value and the event type value, an Event vector is obtained. The Event vector of “Event A” is as shown below as Event Vector 1.

Event A = ----------------- Event Vector 1

Similarly, the Event vectors of each of the one or more first events 105 of the first cluster 1 and the first cluster 2 are:

Event B = ----------------- Event Vector 2
Event C = ----------------- Event Vector 3

Event H = ----------------- Event Vector 4

Event I = ----------------- Event Vector 5

Event N = ----------------- Event Vector 6

Event O = ----------------- Event Vector 7

Event F = ----------------- Event Vector 8
Based on the Event vectors obtained, the one or more first events 105 of the first cluster 1 and the first cluster 2 are plotted in the vector space along X-axis 241 and Y-axis 243 as shown in the FIG.2F. In FIG.2F, the event vectors 1, 2, 3, 4 and 5 lie on the same point (3, 3), but for clarity in representation of all the Event vectors in the vector space, they are scattered around the point (3, 3). Similarly, Event vectors 6 and 9 lie on the same point (1, 1). In an embodiment, based on the plotting in the vector space the event relationship determining module 231 determines squared Euclidean distance of the “Event X” with each of the one or more first events 105 of the first cluster 1 and the first cluster 2. Further, the event relationship determining module 231 determines the relationship of “Event X” with each of the one or more first events 105 of the first cluster 1 and the first cluster 2. The event relationship determining module 231 determines that the “Event X” has the minimum squared Euclidean distance with “Event N” and the relationship of the “Event X” and “Event N” is the positive relationship. Therefore, the “Event X” is linked with the “Event N” by the Event linking module 233. Upon linking the “Event X” with “Event N”, the event clustering module 229 groups the one or more first events 105 with the “Event X” to form a second cluster 1 as shown in the FIG.2G. Upon forming the one or more second clusters, the rules generation module 237 generates one or more rules based on the one or more second clusters. As an example, the one or more rules generated based on the one or more second clusters are as shown in the below Table 5.

Rule number Rules Root cause
Rule 1 Event A and Event B and Event H and Event I and Event C Event C
Rule 2 Event F and Event N and Event O Event F
Rule 3 Event N and Event O and Event X Event O

Table 5
In the above Table 5, consider the Rule 1 “Event A and Event B and Event H and Event I and Event C”. In Rule 1, the order of occurrence of events is “Event A”, “Event B”, “Event H”, “Event I” and “Event C”. Accordingly, last event in the order of occurrence is “Event C”. Therefore, the root cause event of the Rule 1 is “Event C”.
Similarly, the order of occurrence of events in Rule 2 is “Event N”, “Event O” and “Event F”. Therefore, the root cause event of the Rule 2 is “Event F”.

Similarly, the order of occurrence of events in Rule 3 is “Event N”, “Event X” and “Event O”. Therefore, the root cause event of the Rule 3 is “Event O”.

Upon generating the one or more rules, the one or more rules are provided to the rules verification system 121 for verification and identifying one or more faults in the one or more rules. The one or more faults are provided to the rules generation system 113, wherein the fault correction module 238 in association with the event linking module 233 automatically corrects and updates the predefined data structure format based on the one or more faults identified by the rules verification system 121.
As an example, consider a scenario as illustrated in the FIG.2H. Rule 100 and Rule 103 are derived from the First cluster 3 and First cluster 4 respectively as shown in the below Table 6.

Rule number Rules Root cause
Rule 100 Event A and Event B and Event H and Event I and Event C Event C
Rule 103 Event B and Event H and Event I and Event C Event C

Table 6
Upon verifying the Rule 100 and Rule 103 as shown in the above Table 6, the rules verification system 121 identifies the fault that Rule 100 and Rule 103 are redundant. The identified fault is provided by the rules verification system 121 to the rules generation system 113. Upon receiving the identified fault, the fault correction module 239 traverses through the predefined data structure format. Based on the traversal, the fault correction module 238 learns that leaf nodes Event H and Event I are common to both Rule 100 and Rule 103. Therefore, the fault correction module 238 discards Event H and Event I as these two events can be considered as cascaded events due to Event C and thus resolves redundancy. Therefore, Rule 103 is removed and Rule 100 is modified to remove Event H and Event I.

Upon discarding the Event H and Event I to resolve redundancy, the event linking module 233 updates the predefined data structure format to reflect the corrections made by the fault correction module 238 as shown in First cluster 5 of the FIG.2I. Upon updation of the predefined data structure format, the process of generation of the one or more rules may be further iterated.

FIG.3 illustrates a flowchart showing method for generating one or more rules for a root cause analysis system in accordance with some embodiments of the present disclosure.
As illustrated in FIG.3, the method 300 comprises one or more blocks illustrating method for generating one or more rules for a root cause analysis system 123. The method 300 may be described in the general context of computer executable instructions. Generally, computer executable instructions can include routines, programs, objects, components, data structures, procedures, modules, and functions, which perform particular functions or implement particular abstract data types.

The order in which the method 300 is described is not intended to be construed as a limitation, and any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks may be deleted from the methods without departing from the spirit and scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or combination thereof.

At block 301, one or more first events 105 and process flow data 106 is retrieved from one or more first data sources 103. The process flow data 106 comprises process flow of the one or more first events 105. In an embodiment, the process flow of the one or more events 105 is a systematic flow linking the one or more first events 105 in the source code. The one or more first data sources 103 may include, but not limited to, source codes of one or more applications.
At block 303, the process flow data 106 is represented by a processor 115 associated with the rules generation system 113 in a predefined data structure format. The predefined data structure format indicates link between the one or more first events 105 corresponding to the process flow of the one or more first events 106.

At block 305, the one or more first events 105 are grouped into one or more first clusters. In an embodiment, the processor 115 groups the one or more first events 105 into one or more first clusters based on the representation in the predefined data structure format. In an embodiment, the one or more first events 105 can be grouped in one or more combinations.

At block 307, availability of one or more second events 109 is determined. In an embodiment, the processor 115 determines availability of the one or more second events 109 in one or more second data sources 104. The one or more second events 109 are dynamically occurring events in source codes of the one or more applications present in the one or more second data sources 104 that are distinct from the one or more first events 105.

At block 309, a condition is checked to determine the availability of the one or more second events 109. If the processor 115 determines that the one or more second events 109 are available, the method proceeds to block 311 via “Yes”. If the processor 115 determines that the one or more second events 109 are not available, then the method proceeds to block 313 via “No”.

At block 311, relationship and level of the relationship of the one or more second events 109 with each of the one or more first events 105 is determined. In an embodiment, the processor 115 determines relationship and level of the relationship of the one or more second events 109 with each of the one or more first events 105 using one or more predefined techniques. As an example, the one or more predefined techniques may include, but not limited to, K-Means clustering algorithm and K-Nearest neighbour algorithm.

At block 315, a condition is checked to determine if the relationship of the one or more second events 109 with the one or more first events 105 is positive relationship. If the processor 115 determines that the relationship of the one or more second events 109 with the one or more first events 105 is the positive relationship, the method proceeds to block 319 via “Yes”. If the processor 115 determines that the relationship of the one or more second events 109 with the one or more first events 105 is a negative relationship instead of the positive relationship, the method proceeds to block 317 via “No”.

At block 317, the processor 115 discards the one or more second events 109 that are determined to have the negative relationship with the one or more first events 105.

At block 319, the one or more second events 109 are linked to the one or more first events 105 based on the level of the relationship. The predefined data structure format is updated upon linking the one or more second events 109 to the one or more first events 105. Upon updating the predefined data structure format, the processor 115 groups the one or more second events 109 and the one or more first events 105 into one or more second clusters.

At block 321, one or more rules are generated based on the one or more second clusters. The processor 115 generates the one or more rules based on order of occurrence of the one or more second events 109 in the one or more second clusters. Accordingly, last event in the order of occurrence of the one or more first events 105 and the one or more second events 109 in the one or more second clusters is said to be root cause identified in the one or more rules.

At block 323, the one or more rules are provided to rules verification system 121 associated with the rules generation system 113 for verifying the one or more rules. In an embodiment, the rules verification system 121 may verify the one or more rules and identify one or more faults in the one or more rules using a verification technique disclosed in the Indian Patent Application: 6303/CHE/2015. In an alternative embodiment, the one or more rules may be verified using other verification techniques. Upon verifying the one or more rules, the rules verification system 121 may identify one or more faults and provides the one or more faults to the rules generation system 113. In an embodiment, the one or more faults may be manually corrected by a user. In an alternative embodiment, the processor 115 automatically corrects and updates the predefined data structure format based on the one or more faults identified by the rules verification system 121. Upon updating the predefined data structure format, the rules generation module 237 may continue with the process of generating the one or more rules based on the updated predefined data structure format and the one or more rules may be provided to the root cause analysis system 123.

At block 313, the one or more rules are generated based on the one or more first clusters. The processor 115 generates the one or more rules based on order of occurrence of the one or more first events 105 in the one or more first clusters. Accordingly, last event in the order of occurrence of the one or more first events 105 in the one or more first clusters is said to be root cause identified in the one or more rules. Upon generating the one or more rules, the method proceeds to the block 323 for verifying the one or more rules generated.

FIG.4 is a block diagram of an exemplary computer system for implementing embodiments consistent with the present disclosure.
In an embodiment, the rules generating system 400 is used for generating one or more rules for a root cause analysis system. The rules generating system 400 may comprise a central processing unit (“CPU” or “processor”) 402. The processor 402 may comprise at least one data processor for executing program components for executing user- or system-generated business processes. A user may include a person, a person using a device such as such as those included in this invention, or such a device itself. The processor 402 may include specialized processing units such as integrated system (bus) controllers, memory management control units, floating point units, graphics processing units, digital signal processing units, etc.

The processor 402 may be disposed in communication with one or more input/output (I/O) devices (411 and 412) via I/O interface 401. The I/O interface 401 may employ communication protocols/methods such as, without limitation, audio, analog, digital, stereo, IEEE-1394, serial bus, Universal Serial Bus (USB), infrared, PS/2, BNC, coaxial, component, composite, Digital Visual Interface (DVI), high-definition multimedia interface (HDMI), Radio Frequency (RF) antennas, S-Video, Video Graphics Array (VGA), IEEE 802.n /b/g/n/x, Bluetooth, cellular (e.g., Code-Division Multiple Access (CDMA), High-Speed Packet Access (HSPA+), Global System For Mobile Communications (GSM), Long-Term Evolution (LTE), WiMax, or the like), etc.

Using the I/O interface 401, the rules generating system 400 may communicate with one or more I/O devices (411 and 412).

In some embodiments, the processor 402 may be disposed in communication with a communication network 409 via a network interface 403. The network interface 403 may communicate with the communication network 409. The network interface 403 may employ connection protocols including, without limitation, direct connect, Ethernet (e.g., twisted pair 10/100/1000 Base T), Transmission Control Protocol/Internet Protocol (TCP/IP), token ring, IEEE 802.11a/b/g/n/x, etc. Using the network interface 403 and the communication network 409, the rules generating system 400 may communicate with one or more data sources 410 (a,..,n). The communication network 409 can be implemented as one of the different types of networks, such as intranet or Local Area Network (LAN) and such within the organization. The communication network 409 may either be a dedicated network or a shared network, which represents an association of the different types of networks that use a variety of protocols, for example, Hypertext Transfer Protocol (HTTP), Transmission Control Protocol/Internet Protocol (TCP/IP), Wireless Application Protocol (WAP), etc., to communicate with each other. Further, the communication network 409 may include a variety of network devices, including routers, bridges, servers, computing devices, storage devices, etc. The one or more data sources 410 (a,…,n) may be sources codes of one or more applications or cloud environment, monitoring environment, external systems or the like which generates events..

In some embodiments, the processor 402 may be disposed in communication with a memory 405 (e.g., RAM, ROM, etc. not shown in Fig.4) via a storage interface 404. The storage interface 404 may connect to memory 405 including, without limitation, memory drives, removable disc drives, etc., employing connection protocols such as Serial Advanced Technology Attachment (SATA), Integrated Drive Electronics (IDE), IEEE-1394, Universal Serial Bus (USB), fiber channel, Small Computer Systems Interface (SCSI), etc. The memory drives may further include a drum, magnetic disc drive, magneto-optical drive, optical drive, Redundant Array of Independent Discs (RAID), solid-state memory devices, solid-state drives, etc.

The memory 405 may store a collection of program or database components, including, without limitation, user interface application 406, an operating system 407, web server 408 etc. In some embodiments, rules generating system 400 may store user/application data 406, such as the data, variables, records, etc. as described in this invention. Such databases may be implemented as fault-tolerant, relational, scalable, secure databases such as Oracle or Sybase.

The operating system 407 may facilitate resource management and operation of the rules generating system 400. Examples of operating systems include, without limitation, Apple Macintosh OS X, UNIX, Unix-like system distributions (e.g., Berkeley Software Distribution (BSD), FreeBSD, NetBSD, OpenBSD, etc.), Linux distributions (e.g., Red Hat, Ubuntu, Kubuntu, etc.), International Business Machines (IBM) OS/2, Microsoft Windows (XP, Vista/7/8, etc.), Apple iOS, Google Android, Blackberry Operating System (OS), or the like. User interface 406 may facilitate display, execution, interaction, manipulation, or operation of program components through textual or graphical facilities. For example, user interfaces may provide computer interaction interface elements on a display system operatively connected to the rules generating system 400, such as cursors, icons, check boxes, menus, scrollers, windows, widgets, etc. Graphical User Interfaces (GUIs) may be employed, including, without limitation, Apple Macintosh operating systems’ Aqua, IBM OS/2, Microsoft Windows (e.g., Aero, Metro, etc.), Unix X-Windows, web interface libraries (e.g., ActiveX, Java, Javascript, AJAX, HTML, Adobe Flash, etc.), or the like.

In some embodiments, the rules generating system 400 may implement a web browser 408 stored program component. The web browser may be a hypertext viewing application, such as Microsoft Internet Explorer, Google Chrome, Mozilla Firefox, Apple Safari, etc. Secure web browsing may be provided using Secure Hypertext Transport Protocol (HTTPS) secure sockets layer (SSL), Transport Layer Security (TLS), etc. Web browsers may utilize facilities such as AJAX, DHTML, Adobe Flash, JavaScript, Java, Application Programming Interfaces (APIs), etc. In some embodiments, the rules generating system 400 may implement a mail server stored program component. The mail server may be an Internet mail server such as Microsoft Exchange, or the like. The mail server may utilize facilities such as Active Server Pages (ASP), ActiveX, American National Standards Institute (ANSI) C++/C#, Microsoft .NET, CGI scripts, Java, JavaScript, PERL, PHP, Python, WebObjects, etc. The mail server may utilize communication protocols such as Internet Message Access Protocol (IMAP), Messaging Application Programming Interface (MAPI), Microsoft Exchange, Post Office Protocol (POP), Simple Mail Transfer Protocol (SMTP), or the like. In some embodiments, the rules generating system 400 may implement a mail client stored program component. The mail client may be a mail viewing application, such as Apple Mail, Microsoft Entourage, Microsoft Outlook, Mozilla Thunderbird, etc.

Furthermore, one or more computer-readable storage media may be utilized in implementing embodiments consistent with the present invention. A computer-readable storage medium refers to any type of physical memory on which information or data readable by a processor may be stored. Thus, a computer-readable storage medium may store instructions for execution by one or more processors, including instructions for causing the processor(s) to perform steps or stages consistent with the embodiments described herein. The term “computer-readable medium” should be understood to include tangible items and exclude carrier waves and transient signals, i.e., non-transitory. Examples include Random Access Memory (RAM), Read-Only Memory (ROM), volatile memory, non-volatile memory, hard drives, Compact Disc (CD) ROMs, Digital Video Disc (DVDs), flash drives, disks, and any other known physical storage media.

Advantages of the embodiment of the present disclosure are illustrated herein.

In an embodiment, the present disclosure provides a method and a system for generating one or more rules for a root cause analysis system.

The present disclosure provides a feature wherein the rules generating system is adaptive and is capable of generating one or more rules automatically for any rules based system.

The present disclosure enables use of minimum resources to generate the one or more rules for the root cause analysis system.

The present disclosure reduces cost for deploying the root cause analysis system.

The present disclosure provides enhances reliability of the root cause analysis system by performing automatic verification of the one or more rules and removing errors from the one or more rules based on the automatic verification.

A description of an embodiment with several components in communication with each other does not imply that all such components are required. On the contrary a variety of optional components are described to illustrate the wide variety of possible embodiments of the invention.

When a single device or article is described herein, it will be readily apparent that more than one device/article (whether or not they cooperate) may be used in place of a single device/article. Similarly, where more than one device or article is described herein (whether or not they cooperate), it will be readily apparent that a single device/article may be used in place of the more than one device or article or a different number of devices/articles may be used instead of the shown number of devices or programs. The functionality and/or the features of a device may be alternatively embodied by one or more other devices which are not explicitly described as having such functionality/features. Thus, other embodiments of the invention need not include the device itself.

The specification has described a method and a system for generating one or more rules for a root cause analysis system. The illustrated steps are set out to explain the exemplary embodiments shown, and it should be anticipated that on-going technological development will change the manner in which particular functions are performed. These examples are presented herein for purposes of illustration, and not limitation. Further, the boundaries of the functional building blocks have been arbitrarily defined herein for the convenience of the description. Alternative boundaries can be defined so long as the specified functions and relationships thereof are appropriately performed. Alternatives (including equivalents, extensions, variations, deviations, etc., of those described herein) will be apparent to persons skilled in the relevant art(s) based on the teachings contained herein. Such alternatives fall within the scope and spirit of the disclosed embodiments. Also, the words "comprising," "having," "containing," and "including," and other similar forms are intended to be equivalent in meaning and be open ended in that an item or items following any one of these words is not meant to be an exhaustive listing of such item or items, or meant to be limited to only the listed item or items. It must also be noted that as used herein and in the appended claims, the singular forms “a,” “an,” and “the” include plural references unless the context clearly dictates otherwise.

Finally, the language used in the specification has been principally selected for readability and instructional purposes, and it may not have been selected to delineate or circumscribe the inventive subject matter. It is therefore intended that the scope of the invention be limited not by this detailed description, but rather by any claims that issue on an application based here on. Accordingly, the embodiments of the present invention are intended to be illustrative, but not limiting, of the scope of the invention, which is set forth in the following claims.

Referral numerals

Reference Number Description
100 Architecture
103 One or more first data sources
104 One or more second data sources
105 One or more first events
106 Process flow data
109 One or more second events
111 Communication network
113 Rules generation system
115 Processor
117 I/O interface
119 Memory
121 Rules verification system
123 Root cause analysis system
203 Data
205 Modules
209 Cluster data
211 Data related to predefined data structure
213 Relationship data
215 Rules data
219 Other data
223 Retrieving module
225 First analysis module
227 Event clustering module
229 Second analysis module
231 Event relationship determining module
233 Event linking module
237 Rules generation module
238 Fault correction module
239 Other modules
241 X-axis (denoting Resource type)
241a Central Processing Unit
241b Network
241c Storage
243 Y-axis (denoting Event type)
243a Less than threshold value
243b Normal value
243c Greater than threshold value

Documents

Application Documents

# Name Date
1 Form 5 [28-07-2016(online)].pdf 2016-07-28
2 Form 3 [28-07-2016(online)].pdf 2016-07-28
3 Drawing [28-07-2016(online)].pdf 2016-07-28
4 Description(Complete) [28-07-2016(online)].pdf 2016-07-28
5 Form 18 [29-07-2016(online)].pdf_80.pdf 2016-07-29
6 Form 18 [29-07-2016(online)].pdf 2016-07-29
7 Other Patent Document [21-09-2016(online)].pdf 2016-09-21
8 Form 26 [22-09-2016(online)].pdf 2016-09-22
9 201641025844-FER.pdf 2020-05-06
10 201641025844-FER_SER_REPLY [04-09-2020(online)].pdf 2020-09-04
11 201641025844-US(14)-HearingNotice-(HearingDate-10-04-2024).pdf 2024-03-19
12 201641025844-Correspondence to notify the Controller [05-04-2024(online)].pdf 2024-04-05

Search Strategy

1 201641025844E_30-04-2020.pdf