AUTOMATIC TUNING OF MANAGEMENT SYSTEM FOR INCIDENT ALERT CONTROL
Methods, systems, and computer programs are presented for generating recommendations to update the severity of a rule for incident-detection. One method includes accessing a resolution status for insights generated based on an evaluation of rules, each rule associated with a weight. The method deter...
Gespeichert in:
Hauptverfasser: | , , , , |
---|---|
Format: | Patent |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | Methods, systems, and computer programs are presented for generating recommendations to update the severity of a rule for incident-detection. One method includes accessing a resolution status for insights generated based on an evaluation of rules, each rule associated with a weight. The method determines, based on the resolution status, if each insight corresponds to a true positive (TP) or a false positive (FP), and optimizing values for the weights of the one or more rules to lower the number of FPs. The optimizing comprises identifying an objective function based on predicted values for the insights and the insights resolution status, identifying one or more constraints, and using a solver to obtain the optimized values for the weights. A recommendation to change the weight associated with at least one rule is presented on a user interface based on the optimized values for the at least one rule. |
---|