Introduction to It Event Management
In Itil, It’s a Piece of the It Infrastructure Management Strategy. It Includes Monitoring, Investigating, Escalating and Responding to Events That Occur on...
In ITIL, it’s a piece of the IT infrastructure management strategy. It includes monitoring, investigating, escalating and responding to events that occur on the IT platform. Event management includes incident management, which is important to enterprise operation and information security puzzle.
At its most basic unit, an event is a piece of data that offers important insight about state changes that occur on the IT infrastructure to a manager.
This data has a few critical objectives:
- Allows IT managers to detect, interpret and respond to events with required actions
- Provides centralization of event management duties via event hub
- Provides a notification system that supports automating critical tasks
In this article, we’ll introduce IT event management to give you a better idea of why your organization needs it.
Incidents or Events?
When it comes to incident management, a critical duty of event managers, it’s important to understand the differences between an event and an incident.
An event is any state change that occurs in the IT infrastructure. A new user log-in? That’s a state change. A transaction? That’s a change of state, too. Any number of things can trigger an event to be logged.
However, when an event is logged because of a potential problem in the system, that’s an incident. If there’s a network outage? That’s an incident. A decline in service quality? That’s an incident, too. Because of the serious nature of incidents, they often require immediate action, whereas some events may not require a response at all.
In a previous post, we outlined that ITIL events are generally characterized by a few common traits:
- Informative: Informative events are often basic system updates telling of mundane state changes. They don’t often require any real follow up.
- Warnings: Warnings provide information that lets the system manager know that something is amiss. This could be something like server capacity is almost full, or network bandwidth is lagging. These are important to respond to as they can impact service quality and information security.
- Exceptions: Exceptions tell the system manager that an event has occurred that’s caused a problem. This is what you get when an entire server goes down, or another piece of the infrastructure isn’t functioning as it should. These require immediate action.
IT system managers will need to designate what state changes trigger “informative events,” as well as which ones trigger “warnings” and “exceptions.”
Must Read
IT Event Management Lifecycle
After defining what types of events exist within your enterprise IT infrastructure, it’s good to understand what a typical lifecycle looks like for event management. In many cases, the lifecycle includes these key activities:
- An event has occurred: Something in the infrastructure has shifted its state.
- A notification is generated: Monitoring tools and configuration items play a large part in generating the event notification.
- An event is detected: Usually an automated process, the event is detected by monitoring system, automated agent or systems management solution.
- An event has been logged: In this step, the event is annotated in a system log.
- An event is filtered or correlated: An automated event filtration system helps to determine if the event should be ignored or escalated. If it’s escalated, it’s through a process of correlating it with some kind of response required.
- An event is responded to: Event response is logged, and it’s determined if further action is required.
- An event is closed: Once the lifecycle process is completed and all actions are logged, the event is closed.
You should expect to invest in tools and resources that help automate this process along the way.