Posts from — February 2007
links for 2007-02-28
February 28, 2007 No Comments
links for 2007-02-24
February 24, 2007 No Comments
links for 2007-02-23
February 23, 2007 No Comments
DICE - Distributed Intelligent Correlation Engine
Douglas “Dougie” Stevenson has initiated a Sourceforge project focused on developing a high performance, ultra scalable polling, correlation and event management engine. If you don’t know Dougie, he’s got a tremendous history and knowledge in this space. He’s built some powerful tools like this before and I’m sure he’ll do wonders with this new project. He’s the ultimate geek, coder, hacker, bits and bytes twiddler that is driven by taking the concepts and ideas he’s laid out below to places nobody has imagined they could go before.
I encourage you to check out the project page and get in touch with Dougie if you’d like to participate. It’d be great to see a modular approach taken here where the efforts of the many other great OSS projects can all come together to form that ecosphere I’ve mentioned before in the blog. (something for inventory/discovery like ZipTie, visualizations/dashboards/wiki/mashups/knowledgebase/enrichment like ??, rules/workflow/bpel/bpms like Intalio, integration/esb/glue with Mule, etc.)
-snip-
In getting this project off the ground, I’m putting together the requirements, features, and use cases for the different functions of DICE.
I’m also soliciting input, thoughts, and ideas of what could be put into a World class Correlation Engine. So, if you want to contribute, I’m all Ears!
Within the basic requirements, the needs include:
- Scaling to handle greater than 1 million events a minute.
- Be able to dynamically add and subtract handler components on the fly.
- Be able to accomodate a single Control port to the entire distributed application such that any component can be controlled, queried, and monitored via this control port.
- Be able to take raw data feeds from Syslog, various log files in differing file formats, SNMP Trap data, SOAP Services, and assign handlers and process these as a function of workflow.
- Be able to log and track event records throughout the process.
- Be able to enable administrative users to build and modify filtering, parsing, and processing rules as part of a web based build process.
- Be able to add, remove, or schedule changes related to built and tested filters, parsers, and processing functions without causing application downtime.
- Be able to display Objects and states via a Tabular type display.
- Be able to provide state information to an iconic, canvas based map sort of display. This map display ought to be exportable to Visio.
- Be able to enact state based polling via SNMP, TCP connections, and SSH.
- Be able to provide for an intelligent MIB Compiler and analysis function. MIBs should be loadable in any order and be able to be verified and tested against devices in the infrastructure. In effect, the MIB compiler function needs to be able to document differences between a published MIB Structure and real attributes from a given devices’s agent.
- Workflow and states mechanisms should be documented within the product in BPEL format as well as Excel Spreadsheet formats.
February 22, 2007 1 Comment
links for 2007-02-22
-
This is the homepage for the joint collaboration between IBM, BMC, HP, CA, Fujitsu and Microsoft on CMDB Federation.
-
Given the new focus on automation for enterprise network infrastructures, network inventory and configuration management is one such area ripe for hosting a vibrant open source community.
-
(tags: bpm)
February 22, 2007 No Comments
CMDB Federation Consortium’s White Paper Released
Just found the CMDB Federation white paper today. This is the much anticipated first deliverable from the joint working group made up of IBM, BMC, HP, Microsoft, Fujitsu and CA. You can download it here or here.
Update - Looks like they have the beginnings of a website now here.
Update - IT Skeptic’s Post here.
Hank Marquis has some good commentary here.
February 21, 2007 1 Comment
Splunk-2-Netcool - Creating an Ecosphere for Better/Easier Event Management
Looks like an innovative client and the folks over at Splunk got togther and put together a nice way to leverage Splunk with Netcool/OMNIbus. Details can be found here.
Giving operations and support folks a capability to work with events in an easier way that’s relevent to their jobs and real time daily responsibilities is crucial. The traditional sort, filter, this but not that approach to working with events is past its time. Leading edge event management techniques incorporating direct linkages with all other IT resource, application and service information (Splunk), instant collaboration (RSS Event Feeds, Event Wikis, Event/Incident IM Channels), trending/reporting/analytics, situational management mashups (shift based event/incident management tear-aways, in-flight rules/analytics, workflow, etc.) and other contextual management applications which are developed and managed by the individual users instead of the tools group is the future.
Thinking outside the box with a focus on how to do things better, faster (agile, less-code) and cheaper such as this is an area ripe for the OSS community to create an ecosphere of new tools, applications and add-ons that can greatly complement and enhance the traditional network, systems, application and servivce management and monitoring vendor solutions. The front line operations and support groups and the tools group would be two key IT organizations that would greatly benefit from initiatives such as this.
-snip-
Integrated IT Data Search with IBM Netcool and Splunk
Splunk-2-Netcool is an integrated module that provides seamless workflow and data integration between Splunk Professional and IBM Tivoli Netcool. It allows Netcool customers to launch Splunk directly from the Netcool/Webtop and Netcool/OMNIbus Event List. It also configures Splunk to seamlessly index events from any Netcool ObjectServer, to provide the ability to search Netcool events alongside other kinds of IT data, such as logs and configuration files from servers and applications. Finally, it allows Live Splunk alerts to be forwarded to a Netcool ObjectServer for notification and correlation.
February 21, 2007 1 Comment
links for 2007-02-21
-
Carrier and Service Provider SLA’s
-
The Soapstone Networksâ„¢ product can be easily shaped through its SOA-based modular architecture to different applications, sharing the attributes of soapstone itself, a material that can be easily carved and taken to finish quality easily and flexibly b
-
Aternity empowers IT organizations to identify and resolve business application performance issues where information is hardest to come by – the “last mile,†the real end-users.
-
Oblicore’s U.S. Patent No. 6,925,493 and International Patent WO/2002/044832 describe how service providers can leverage Oblicore’s solutions to set up customized service level agreements with customers, and monitor, modify and control all aspects of SLAs
February 21, 2007 No Comments
