Patent attributes
A method for anomaly alarm consolidation includes detecting a plurality of anomalies in time-series data received from an information technology infrastructure; identifying a plurality of root-cause candidates for each of the anomalies; generating, by a scenario analysis of the anomalies, a plurality of alarms, wherein the scenario analysis predicts a plurality of future expected values of the time-series data over a plurality of historical values of the time-series data using a graphical Granger causal model and generates the alarms based on a difference between the future expected values of the time-series data and actual values of the anomalies in the time-series data; and performing a belief propagation procedure between the root-cause candidates and the alarms to determine a plurality of root-causes that collectively comprise attributed root-causes for the alarms.