Market Guide for AIOps Platforms
Overview
Key Findings
- AIOps is getting entrenched in enterprises predominantly for IT operations, while some of the more mature organizations are using the technology to provide insights to business leaders.
- AIOps skills and IT operations maturity are the usual inhibitors in ensuring quick time to value when using these tools, followed by data quality as an emerging challenge for some of the more mature deployments.
- Enterprises adopting AIOps platforms use it to enhance and, occasionally, augment classical application performance monitoring (APM) and network performance monitoring and diagnostics (NPMD) tools.
- Vendors are developing strategies to use machine learning — the primary technology within AIOps — to analyze data challenges for IT operations across the three dimensions of volume, variety and velocity. At the same time, they are building specialization across both data storage and AI practices.
Recommendations
- Deploy AIOps by adopting an incremental approach that starts with historical data, and progress to the use of streaming data, aligned with a continuously improving IT operations maturity.
- Select platforms that enable comprehensive insight into past and present states of IT systems by identifying AIOps platforms that are capable of ingesting and providing access to text and metric data.
- Deepen their IT operations team’s analytical skills by selecting tools that support the ability to incrementally deploy the four phases of IT-operations-oriented machine learning: descriptive, diagnostic, proactive capabilities and root cause analysis to help avoid high-severity outages.
Market Definition
Market Description
- Ingesting data from multiple sources agnostic to source or vendor
- Enabling data analytics at two points:
- Real-time analysis at the point of ingestion
- Historical analysis of stored data
- Providing access to the data
- Storing the acquired data
- Using machine learning
- Initiating an action or next step based on the result of analysis
Source: Gartner (November 2018)

Market Direction
- Rapid growth in data volumes generated by the IT infrastructure and applications (two- to three-fold increase per annum)
- The increasing variety of data types generated by machines and humans (for example, metrics, logs, wire data and documents [knowledge management])
- The increasing velocity at which data is generated as well as the increasing rate of change within IT architectures due to the adoption of cloud-native or other ephemeral architectures
- Reduce noise (for example, in the form of false alarms or redundant events)
- Provide better causality, which helps identify probable cause of incidents
- Capture anomalies that go beyond static thresholds to proactively detect abnormal conditions
- Extrapolate future events to prevent potential breakdowns
- Initiate action to resolve a problem (either directly or via integration)
- Alerting
- Problem triage
- CMDB population
- Run book automation
- Application release orchestration
Source: Gartner (November 2018)

Market Analysis
- Historical and streaming data management — Software or appliances that allow for the ingestion, indexing and persisted storage of log data, wire data, metrics and document data (see Note 2). The resulting databases are mostly unstructured or polystructured, while the stored datasets accumulate in high volumes, change with high velocity and are implicitly structured according to highly varied formats. This historical data management functionality can be called “big data management.” To provide value under the IT operations use case, the tool must also present data in time scales perceived by a human user as real time, delivering data directly at the point of ingestion without requiring access to a persisted database. It must provide a coherent analysis across multiple streams of real-time and historical data.
- Basic and advanced statistical analysis— A combination of univariate and multivariate analysis, including the use of correlation, clustering, classifying and extrapolation on metrics captured across IT entities as well as for curating data at source.
- Automated pattern discovery and prediction — Use of historical or streaming data of one or more of the types mentioned above, to elicit mathematical or structural patterns that describe novel correlations that may be inferred from, but are not immediately present in, the datasets themselves. These patterns may then be used to go forward in time and predict incidents with varying degrees of probability.
- Anomaly detection — Using the patterns discovered by the previous components to first determine what constitutes normal system behavior, and then to discern departures from that normal system behavior.
- Root cause determination — Pruning down the network of correlations established by the automated pattern discovery and prediction component to isolate those links of dependency that represent genuine causal relationships in the sense of providing recipes for effective intervention.
- Prescriptive advice — Performing triage on problems, classifying them into known categories. It may then mine stores of prior solutions, analyzing these for applicability and offering them in a prioritized form for usage of remediation. Eventually, these will use a closed-loop approach and enable voting on their effectiveness after they are utilized.
- Topology— For the patterns AIOps detects to be relevant and actionable, a context must be placed around the data ingested. That context is topology. Without the context and de facto constraint of topology, the patterns detected, while valid, may be unhelpful and distracting. Deriving patterns from data within a topology will reduce the number of patterns, establish relevancy and illustrate hidden dependencies. Using topology as part of causality determination can greatly increase its accuracy and effectiveness. Capturing where events occurred and their up and downstream dependencies using graph and bottleneck analysis can provide great insight on where to focus remediation efforts.
- Vendors going to market with a data-source-agnostic AIOps platform. These products tend to be generic and cater to the broadest use cases.
- Vendors that have the key components, but tend to have a restricted set of data sources. These vendors are typically focused on one domain (for example, network, endpoint systems and APM), or are selective about data types like alert streams from other tools. Such tools tend to have a restricted set of use cases, targeted at a certain segment of IT operations.
- Some vendors with existing monitoring solutions limit data sources to their own monitoring products or extend to a limited partner ecosystem. This is again a case where the target audience is limited to those with the right mix of data sources.
- Some open-source projects enable users to assemble their own AIOps platforms by offering tools for data ingest, a big data platform, ML and a visualization layer. End users can mix and match the components from multiple providers.
Representative Vendors
Market Introduction
Table 1: Representative Vendors
|
Vendors
|
Year Founded
|
Headquarters
|
Website
|
|---|---|---|---|
|
Anodot
|
2014
|
Israel
|
|
|
BigPanda
|
2014
|
United States
|
|
|
BMC
|
1980
|
United States
|
|
|
Brains Technology
|
2008
|
Japan
|
|
|
CA Technologies
|
1974
|
United States
|
|
|
Devo (Logtrust)
|
2011
|
United States
|
|
|
Elastic
|
2012
|
United States
|
|
|
Evolven
|
2007
|
United States
|
|
|
FixStream
|
2013
|
United States
|
|
|
IBM
|
1911
|
United States
|
|
|
InfluxData
|
2013
|
United States
|
|
|
ITRS
|
1993
|
United Kingdom
|
|
|
jKool
|
2014
|
United States
|
|
|
Loom Systems
|
2015
|
United States
|
|
|
Moogsoft
|
2011
|
United States
|
|
|
Scalyr
|
2012
|
United States
|
|
|
ScienceLogic
|
2003
|
United States
|
|
|
SignalFx
|
2013
|
United States
|
|
|
Splunk
|
2004
|
United States
|
|
|
Stackstate
|
2015
|
Netherlands
|
|
|
Sumo Logic
|
2010
|
United States
|
|
|
VNT Software
|
2010
|
Israel
|
|
|
VuNet
|
2014
|
India
|
Market Recommendations
Ensure Success in the Deployment of AIOps Functionality by Adopting an Incremental Approach
Select AIOps Platforms Capable of Supporting a Broad Range of Historical and Streaming Data Types
Source: Gartner (November 2018)

- Digital experience data from APM
- Order data pulled from payloads in business transactions
- Sentiment data from social media
- Service desk requests and statuses
- Account activity from the CRM system
Choose Tools Offering the Ability to Systematically Progress Across the Four Phases of IT-Operations-Oriented Analytics and Machine Learning
Source: Gartner (November 2018)

- Initially experiment with allowing the software to reveal patterns that organize large volumes of data.
- Next, test the degree to which those patterns allow them to anticipate future events and incidents.
- Finally, work with root cause analysis functionality.
Evidence
- Platform selection
- Deployment strategy
- Multiple AIOps use case within and outside IT to aid visualization, decisions and diagnostics
Note 1Representative Vendor Selection
- Ability to ingest data from multiple sources, including historic and real-time streaming.
- Different offerings that include proprietary, open source, free and commercialized versions, including deployment that cuts across on-premises and SaaS-based options.
Note 2Data Types
- Log data ingestion — Software that allows for the capture of alphanumeric text strings from log files generated by any software or hardware device, and the preparation of that data for access and analysis, indexed for storage.
- Wire data ingestion — Software that allows for the capture of packet data direct from taps on the network. All protocol and flow information should be prepared for access and analysis, and indexed for storage.
- Metric data ingestion — Software that allows for the direct capture of numerical data (for example, the capture of data to which time series and more general mathematical operations can be immediately applied).
- Document text ingestion — Software that allows for the ingestion, parsing, and syntactical and semantic indexing of human readable documents. This may include the use of technologies commonly described as natural language processing (NLP).
Market Guide for AIOps Platforms的更多相关文章
- DataOps Reading Notes
质量.效率.成本.安全,是运维工作核心四要素. AIOps 技术会涉及到数据收集方面的基础监控,服务监控和业务监控,甚至会涉及到与持续交付流水线的数据和状态整合(比如在软件发布的阶段会自动关闭某些监控 ...
- Magic Quadrant for Security Information and Event Management
https://www.gartner.com/doc/reprints?id=1-4LC8PAW&ct=171130&st=sb Summary Security and risk ...
- Gartner容器市场指南中国语境:容器成为新常态,灵雀云等本地厂商在选择中占据优势
在2019年2月“ China Summary Translation: 'Market Guide for Container Management Software'”的报告中,Gartner认为 ...
- 如何选型商业智能和分析平台,Gartner给了这些建议!
文 | 水手 在2017年1月20日Gartner发布的<China Summary Translation: 'Survey Analysis: Customers Rate Their BI ...
- 国外DDoS产品的一些调研—— Akamai Arbor Networks Cloudflare DOSarrest F5 Fastly Imperva Link11 Neustar Nexusguard Oracle (Dyn) Radware Verisign
Global DDoS Threat LandscapeQ4 2017 https://www.incapsula.com/ddos-report/ddos-report-q4-2017.html,D ...
- 使用mongify将sqlserver数据导入到mongodb
最近需要将sqlserver数据导入到mongodb中,在github上搜了一圈,发现两个项目有点适合 mongify sql2mongodb 先试了下sql2mongodb(有个好名字果然有好处啊) ...
- Ultimate Facebook Messenger for Business Guide (Feb 2019)
Ultimate Facebook Messenger for Business Guide (Updated: Feb 2019) By Iaroslav Kudritskiy November 2 ...
- The 10 Best Choices On The Market Review 2018
Looking to buy a scan tool or considering one of Autel Scanner impressive product line?. The company ...
- Ultimate Guide to Line For Business (May 2019)
Ultimate Guide to Line For Business (May 2019) By Iaroslav Kudritskiy February 4, 2019 No Comments I ...
随机推荐
- 代理服务 SQUID 测试
第一部分:SQUID基础 Squid代理服务的基本配置: http_port 3128 #设置监听的IP与端口号 cache_mem 64 MB ...
- Redis持久化之RDB与AOF
1. Redis的持久化方式 Redis作为高效的缓存件,它的数据存放在内存中,如果没有配置持久化,那么数据会在重启后丢失,因此如果不是仅用Redis做缓存的话,需要开启Redis的持久化功能,将数据 ...
- ios中LeveyPopListView 弹出view的用法
下载地址https://github.com/levey/LeveyPopListView 是arc, 如果是非arc项目要设置一下 方法 选中工程->TARGETS->相应的targe ...
- [转]深入理解Java之线程池
原文链接 原文出处: 海 子 在前面的文章中,我们使用线程的时候就去创建一个线程,这样实现起来非常简便,但是就会有一个问题: 如果并发的线程数量很多,并且每个线程都是执行一个时间很短的任务就结束了,这 ...
- iOS页面性能优化
前言 在软件开发领域里经常能听到这样一句话,“过早的优化是万恶之源”,不要过早优化或者过度优化.我认为在编码过程中时刻注意性能影响是有必要的,但凡事都有个度,不能为了性能耽误了开发进度.在时间紧急的情 ...
- IP概念盛行的背后:资本在狂欢,电影想哭泣 IP,英文“Intellectual Property”的缩写,直译为“知识产权”。它的存在方式很多元,可以是一个故事,也可以是某一个形象,运营成功的IP可以在漫画、小说、电影、玩具、手游等不同的媒介形式中转换。
IP概念盛行的背后:资本在狂欢,电影想哭泣 IP容易拉投资.谈合作,甚至还能简化宣发途径,越来越多的人涌入了电影这个产业,争抢IP成为他们进入行业的最快捷的方法.IP盛行暴露出的另一个问题是国产电影原 ...
- Ubuntu下架设FTP服务器(转)
Ubuntu下架设FTP服务器 Linux下提供了很多的ftp服务器,这里我选用了安全,快速,简单的vsftpd作为FTP服务器.本文是我在自己的Ubuntu 10.10 -32 位系统下搭建的.搭建 ...
- Oracle2MySQL注意事项
在Oracle切换成MySQL时,会碰到如下注意事项: Oracle中的sysdate在MySQL中是不支持的: Oracle中的分布方案在MySQL中的实现: Oracle中的SQL语句是大小写不敏 ...
- php数组添加元素的方法
PHP数组添加一个元素的方式: push(), arr[], Php代码 $arr = array(); array_push($arr, el1, el2 ... eln); 但其实有一种更直 ...
- Oracle 12C -- 在相同的列的集合上创建多个索引
在12C中,可以在相同的列的集合上创建多个索引,但是多个索引的类型要不同.同一时刻,只有一个是可见的. SQL> create table emp_tab as select * from em ...