海心 发表于 2012-3-15 17:47:37

事件与事故差别(备忘)


学习资料:IT运维管理社区专家讲堂直播300期视频回放




词汇表解释:

Event
(ServiceOperation)AchangeofstatewhichhassignificanceforthemanagementofaConfigurationItemorITService.
ThetermEventisalsousedtomeananAlertornotificationcreatedbyanyITService,ConfigurationItemorMonitoringtool.EventstypicallyrequireITOperationspersonneltotakeactions,andoftenleadtoIncidentsbeinglogged.

EventManagement
(ServiceOperation)TheProcessresponsibleformanagingEventsthroughouttheirLifecycle.EventManagementisoneofthemainActivitiesofITOperations.

Incident
(ServiceOperation)AnunplannedinterruptiontoanITServiceorareductionintheQualityofanITService.FailureofaConfigurationItemthathasnotyetimpactedServiceisalsoanIncident.ForexampleFailureofonediskfromamirrorset.

IncidentManagement
(ServiceOperation)TheProcessresponsibleformanagingtheLifecycleofallIncidents.TheprimaryObjectiveofIncidentManagementistoreturntheITServicetoUsersasquicklyaspossible.

网上详解文章(带举例):

WhatisthedifferencebetweenEventandIncidentManagement?Mostofthetime,wheneverIattendITILseminarsorITILexamcourses(speciallytheonesthattouchbasedwithEventandIncidentManagement),thisisoneofthequestionsthatweremostcommonlyasked.Moreover,thediscussiongetsprolonged.Sotoday,IdecidedthatIwillblogaboutthedifferencebetweenEventManagementandIncidentManagement.
Keepinmindthatwithintherealmofthisdiscussionarethefactorsthatcanhelpyoudifferentiatethetwo.Themostthatyoucantakeawayfromthisarticleisbetterunderstan**ofEventandIncidentManagementthatwillcertainlybeofhelpinyourITILcertificationexam.Attheveryleast,itcanbehandywhenexplainingthedifferencesbetweenanEventandanIncidenttoyourcolleaguesorITILimplementationsponsor(s).TheexamwillcertainlyincludequestionsmeanttotrickyoubetweenEventandIncidentManagement.ThatisonlyifyoudonothavecleardistinctionbetweenEventandIncidentManagement.
Butbeforewegoforward,letusfirstclearlydefinewhatisanEventandwhatisanIncident.LetusrefertotheOGC’sITILV3ServiceOperationbookforthedefinitionofanEventandanIncident.Accor**toOGC’sbook,aneventisachangeofthestatethathassignificanceforthemanagementofaConfigurationItemorITService.Whereas,anIncidentisanunplannedinterruptiontoanITServiceorreductionintheQualityofanITServiceisalsoanIncident.
Thereyougo,keyterminologieshasbeenproperlydefinedandnowletusdealwiththedifferencesofthesetwo.
EventManagement
Accor**totheOGC’sITILV3ServiceOperationbook,EventManagementmonitorsalleventsthatoccurthroughouttheITinfrastructure,andmonitorsnormaloperationanddetectandescalateexceptionconditions.
Baseonthatdefinition,wecanusearacecaranalogy.Inaprofessionalracecar,youhaveasetofgaugestopayattentionto.YouhavetheTachometergauge,Oilpressuregauge,OilTemperature,Watertemperaturegaugeandothergaugesthatprobablymonitorthestatusofothercomponentsoftheracecar.
Thedataonthesemaingaugesaresenttotheteamonthesidelines.TheteamwhomonitorsthesedataiscomparabletotheEventManagementteam.Forthepurposeofthisanalogy,let’scallthem“RacingteamEventManagement”.Anyred,orangeorwhatcolorhaveyouflaggedintheon-boardgaugesistrackbythisteam.Iftheracecar’sengineoverheats,itwillbedetectedbyoneofthegaugesonboardtheracecarandthedatawillbesenttotheRacingteamEventManagement–theengineoverheatingisanevent;andishandledbyRacingteamEventManagementteam.InareallifescenarioinanITenvironment,theracecarcouldbeaserverhostingmultiplebusinesscriticalapplications.Theracecar’sengineoverheatingcouldbeahighCPUutilizationandyourEventManagementteamcouldbethetheTivoli/Sitescopeguys,level1techsupportteamoradedicatedEventManagementteam.RememberthatinITIL,anindividualorateamcanwearmultiplehats.
Whenaneventisdetected,thereispredeterminedandagreeduponprocessthatwillbetriggeredbyeveryevent,eitherautomaticallyormanually.ThesecouldrangefromassimpleaspayextraattentionforthenextalertandseeiftheCPUusageincreasesbyanother10%.OrimmediatelyraiseanIncidentrecordandkickoffMajorIncidentHandlingprocess.
WhatEventManagementis;
•Monitornormaloperation(BAU)activities
•Flagsoccurrencethatmightbeofinterestdepen**ontheorganization’sdefinitionofwhatisof“interest”tothebusiness.“Interest”inITILtermsiscalledexceptionalconditions.
•Escalationofanyexceptioncondition/interest.Noticetheuseofthewordescalation;itdoesnotsayresolutionof.
Rememberthekeywordhere,escalationisforEventManagement(triggersapredeterminedprocess)andresolutionisforIncidentManagement(goalisimmediaterestorationofthedegradedservice).
•EventManagementservesastheentrypointorthetriggerformostoftheServiceOperations’definetask(i.e.ServiceOperationprocess:ifaneventalertwastriggeredfora98%usageofinkprinter,thennotifyDesktopSupportteamtochangetheprinter’sinkcartridge)
•EventManagementprovidesawaytocomparetheactualperformanceandthebehaviorofasystemagainsttheagreeduponanddesignedstandards(i.e.SLA).
•ItgivesinputsforServiceAssuranceandContinualServiceImprovementtopossiblyadjusttheservice’sstandardsorprocessasneededtomeetthebusinessrequirements.
WhatEventManagementisnot;
•EventManagementisNOTintendedtoresolveorimplementpermanentfixestoeventsthatwereidentified.
•EventManagementisNOTtoidentifyimprovementsbasedonthereportsthattheywillgenerate.ThatisthejobforCSI.EventManagementonlyprovidestatisticaldataandinformationtoCSI.
IncidentManagement
IncidentManagementontheotherhandconcentratesonrestoringunexpectedlydegradedordisruptedservicestousersasquicklyaspossible,inordertominimizebusinessimpact.
EventManagementidentifiesoccurrenceofitemsthatareofinteresttothebusiness.Inthatpredeterminedlistofevents,therearesomeofthoseeventsthatfallunderthedefinedexceptionalcondition.Agoodexampleofwhichisthatiftheresponsetimeofabusinesscriticalapplicationsincreasesby88%,thentriggeranalertandraiseanIncidentrecordfortheIncidentManagementteam.Fromthisexample,youcanseetheprocesssignatureofanevent;conditionmeet,sendanalertandthentriggertheoperationaltasks.Operationaltaskcanberoutine(forvalidevents)andquitecomplexresolutionforvalidexceptionalconditions(whicharemostlyescalatedasanIncident).
WhatIncidentManagementis;
•IncidentManagementhasasolepurposethatistorestoreservicetotheusersbacktonormalstandardsandacceptablelevel.
•IncidentManagementdealswithallincidents;thisincludesfailures,reportedbyeventmonitoringtools,and/orquestions/inquiriesreportedbyusers(eitherviaphonethroughtheServiceDeskorviaanIncidentrecord).
•IncidentManagementprovidesinputstoProblemManagementteamasneededtoassistintheidentificationoftheunderlyingrootcauseoftheincident.
•IncidentManagementprovidestatisticaldata(asrequired)toCSI.Thedatacouldincludenumberofrepeatincidents,incidentstriggeredbyachange,andaverageincidentdurationbeforeresolutionamongotherinformation.SomeorganizationscallthisasKPI(KeyPerformanceIndex).
WhatIncidentManagementisNot;
•IncidentManagementisNOTresponsibleforimplementingapermanentfixorpermanentsolutiontoanissue.IncidentManagement’spurposeistorestoretheservicethesoonestpossibletime.Itdoesnotmatterifthesolutionusedisa“blegum”solution(i.epatchingablegumtotheholeonaboatshullsothatitcanmanagetoreachtheotherendoftheriveranddeliverthegoodsthatareon-board).
•IncidentManagementdoesNOTandisNOTresponsibleforidentifyingtherootcauseofanissue.

注:此文章转载自:h...ncident-management/

jadeloyalbird 发表于 2012-3-15 18:35:43

{:soso_e179:}

xyz8231 发表于 2012-3-24 00:22:37

马上对event和incident的区别了解了更多
页: [1]
查看完整版本: 事件与事故差别(备忘)