Event Management
The Event pipeline ingests real-time events and alarms from a multi-vendor estate — Syslog, SNMP traps, webhooks, TL1, email, and more — normalizes and de-duplicates them, and stores them in a real-time event store built to be sharded for scale. Operators work them through event lists designed for the pace of a live NOC.
Above the raw stream sits CAPE — the Custom Action Policy Engine — a policy-based, multi-threaded correlation engine that enriches, correlates, and suppresses events after collection, outside the database, against internal and external data. It is where a flood of alarms becomes a short list of incidents worth a human's attention.
How It Works
Multi-vendor collectors turn Syslog, SNMP traps, webhooks, TL1, and email into normalized events in a real-time, shardable event store.
A policy-based correlation engine enriches, correlates, de-duplicates, and suppresses events in real time — mixing connectors and agents against internal or external datasets.
The RCA microservice reads the topology graph to correlate outages with related events, enriching each event with root-cause and symptom context so operators focus on the cause.
Operators train the system with supervised correlations, teaching it to suppress the noise specific to their network.
Why It Matters
When a single failure lights up hundreds of downstream alarms, RCA reads the graph and resolves the storm to one root cause — the whole organization aimed at the one thing that broke.
Real-time, shardable event store for carrier volumes
Post-collection correlation and suppression with CAPE
Topology-driven root cause versus symptom
Operator-trained supervised correlation
A clean, actionable event list instead of an alarm flood
AccuOSS builds the collection, CAPE policies, and topology-driven RCA that turn an alarm storm into a single, answerable incident.