事件与事故差别(备忘)
学习资料:IT运维管理社区专家讲堂直播300期视频回放
词汇表解释:
Event
(ServiceOperation)AchangeofstatewhichhassignificanceforthemanagementofaConfigurationItemorITService.
ThetermEventisalsousedtomeananAlertornotificationcreatedbyanyITService,ConfigurationItemorMonitoringtool.EventstypicallyrequireITOperationspersonneltotakeactions,andoftenleadtoIncidentsbeinglogged.
EventManagement
(ServiceOperation)TheProcessresponsibleformanagingEventsthroughouttheirLifecycle.EventManagementisoneofthemainActivitiesofITOperations.
Incident
(ServiceOperation)AnunplannedinterruptiontoanITServiceorareductionintheQualityofanITService.FailureofaConfigurationItemthathasnotyetimpactedServiceisalsoanIncident.ForexampleFailureofonediskfromamirrorset.
IncidentManagement
(ServiceOperation)TheProcessresponsibleformanagingtheLifecycleofallIncidents.TheprimaryObjectiveofIncidentManagementistoreturntheITServicetoUsersasquicklyaspossible.
网上详解文章(带举例):
WhatisthedifferencebetweenEventandIncidentManagement?Mostofthetime,wheneverIattendITILseminarsorITILexamcourses(speciallytheonesthattouchbasedwithEventandIncidentManagement),thisisoneofthequestionsthatweremostcommonlyasked.Moreover,thediscussiongetsprolonged.Sotoday,IdecidedthatIwillblogaboutthedifferencebetweenEventManagementandIncidentManagement.
Keepinmindthatwithintherealmofthisdiscussionarethefactorsthatcanhelpyoudifferentiatethetwo.Themostthatyoucantakeawayfromthisarticleisbetterunderstan**ofEventandIncidentManagementthatwillcertainlybeofhelpinyourITILcertificationexam.Attheveryleast,itcanbehandywhenexplainingthedifferencesbetweenanEventandanIncidenttoyourcolleaguesorITILimplementationsponsor(s).TheexamwillcertainlyincludequestionsmeanttotrickyoubetweenEventandIncidentManagement.ThatisonlyifyoudonothavecleardistinctionbetweenEventandIncidentManagement.
Butbeforewegoforward,letusfirstclearlydefinewhatisanEventandwhatisanIncident.LetusrefertotheOGC’sITILV3ServiceOperationbookforthedefinitionofanEventandanIncident.Accor**toOGC’sbook,aneventisachangeofthestatethathassignificanceforthemanagementofaConfigurationItemorITService.Whereas,anIncidentisanunplannedinterruptiontoanITServiceorreductionintheQualityofanITServiceisalsoanIncident.
Thereyougo,keyterminologieshasbeenproperlydefinedandnowletusdealwiththedifferencesofthesetwo.
EventManagement
Accor**totheOGC’sITILV3ServiceOperationbook,EventManagementmonitorsalleventsthatoccurthroughouttheITinfrastructure,andmonitorsnormaloperationanddetectandescalateexceptionconditions.
Baseonthatdefinition,wecanusearacecaranalogy.Inaprofessionalracecar,youhaveasetofgaugestopayattentionto.YouhavetheTachometergauge,Oilpressuregauge,OilTemperature,Watertemperaturegaugeandothergaugesthatprobablymonitorthestatusofothercomponentsoftheracecar.
Thedataonthesemaingaugesaresenttotheteamonthesidelines.TheteamwhomonitorsthesedataiscomparabletotheEventManagementteam.Forthepurposeofthisanalogy,let’scallthem“RacingteamEventManagement”.Anyred,orangeorwhatcolorhaveyouflaggedintheon-boardgaugesistrackbythisteam.Iftheracecar’sengineoverheats,itwillbedetectedbyoneofthegaugesonboardtheracecarandthedatawillbesenttotheRacingteamEventManagement–theengineoverheatingisanevent;andishandledbyRacingteamEventManagementteam.InareallifescenarioinanITenvironment,theracecarcouldbeaserverhostingmultiplebusinesscriticalapplications.Theracecar’sengineoverheatingcouldbeahighCPUutilizationandyourEventManagementteamcouldbethetheTivoli/Sitescopeguys,level1techsupportteamoradedicatedEventManagementteam.RememberthatinITIL,anindividualorateamcanwearmultiplehats.
Whenaneventisdetected,thereispredeterminedandagreeduponprocessthatwillbetriggeredbyeveryevent,eitherautomaticallyormanually.ThesecouldrangefromassimpleaspayextraattentionforthenextalertandseeiftheCPUusageincreasesbyanother10%.OrimmediatelyraiseanIncidentrecordandkickoffMajorIncidentHandlingprocess.
WhatEventManagementis;
•Monitornormaloperation(BAU)activities
•Flagsoccurrencethatmightbeofinterestdepen**ontheorganization’sdefinitionofwhatisof“interest”tothebusiness.“Interest”inITILtermsiscalledexceptionalconditions.
•Escalationofanyexceptioncondition/interest.Noticetheuseofthewordescalation;itdoesnotsayresolutionof.
Rememberthekeywordhere,escalationisforEventManagement(triggersapredeterminedprocess)andresolutionisforIncidentManagement(goalisimmediaterestorationofthedegradedservice).
•EventManagementservesastheentrypointorthetriggerformostoftheServiceOperations’definetask(i.e.ServiceOperationprocess:ifaneventalertwastriggeredfora98%usageofinkprinter,thennotifyDesktopSupportteamtochangetheprinter’sinkcartridge)
•EventManagementprovidesawaytocomparetheactualperformanceandthebehaviorofasystemagainsttheagreeduponanddesignedstandards(i.e.SLA).
•ItgivesinputsforServiceAssuranceandContinualServiceImprovementtopossiblyadjusttheservice’sstandardsorprocessasneededtomeetthebusinessrequirements.
WhatEventManagementisnot;
•EventManagementisNOTintendedtoresolveorimplementpermanentfixestoeventsthatwereidentified.
•EventManagementisNOTtoidentifyimprovementsbasedonthereportsthattheywillgenerate.ThatisthejobforCSI.EventManagementonlyprovidestatisticaldataandinformationtoCSI.
IncidentManagement
IncidentManagementontheotherhandconcentratesonrestoringunexpectedlydegradedordisruptedservicestousersasquicklyaspossible,inordertominimizebusinessimpact.
EventManagementidentifiesoccurrenceofitemsthatareofinteresttothebusiness.Inthatpredeterminedlistofevents,therearesomeofthoseeventsthatfallunderthedefinedexceptionalcondition.Agoodexampleofwhichisthatiftheresponsetimeofabusinesscriticalapplicationsincreasesby88%,thentriggeranalertandraiseanIncidentrecordfortheIncidentManagementteam.Fromthisexample,youcanseetheprocesssignatureofanevent;conditionmeet,sendanalertandthentriggertheoperationaltasks.Operationaltaskcanberoutine(forvalidevents)andquitecomplexresolutionforvalidexceptionalconditions(whicharemostlyescalatedasanIncident).
WhatIncidentManagementis;
•IncidentManagementhasasolepurposethatistorestoreservicetotheusersbacktonormalstandardsandacceptablelevel.
•IncidentManagementdealswithallincidents;thisincludesfailures,reportedbyeventmonitoringtools,and/orquestions/inquiriesreportedbyusers(eitherviaphonethroughtheServiceDeskorviaanIncidentrecord).
•IncidentManagementprovidesinputstoProblemManagementteamasneededtoassistintheidentificationoftheunderlyingrootcauseoftheincident.
•IncidentManagementprovidestatisticaldata(asrequired)toCSI.Thedatacouldincludenumberofrepeatincidents,incidentstriggeredbyachange,andaverageincidentdurationbeforeresolutionamongotherinformation.SomeorganizationscallthisasKPI(KeyPerformanceIndex).
WhatIncidentManagementisNot;
•IncidentManagementisNOTresponsibleforimplementingapermanentfixorpermanentsolutiontoanissue.IncidentManagement’spurposeistorestoretheservicethesoonestpossibletime.Itdoesnotmatterifthesolutionusedisa“blegum”solution(i.epatchingablegumtotheholeonaboatshullsothatitcanmanagetoreachtheotherendoftheriveranddeliverthegoodsthatareon-board).
•IncidentManagementdoesNOTandisNOTresponsibleforidentifyingtherootcauseofanissue.
注:此文章转载自:h...ncident-management/ {:soso_e179:} 马上对event和incident的区别了解了更多
页:
[1]