<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itskeptic.org"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The IT Skeptic - Comments for &quot;Vendor marketeers stretch to reach out for ITIL&quot;</title>
 <link>http://www.itskeptic.org/node/698</link>
 <description>Comments for &quot;Vendor marketeers stretch to reach out for ITIL&quot;</description>
 <language>en</language>
<item>
 <title>Silo-ed monitoring as root-cause</title>
 <link>http://www.itskeptic.org/node/698#comment-3193</link>
 <description>&lt;p&gt;Can&#039;t resist a few more comments here. I absolutely agree that [ &quot;&lt;em&gt;Many vendors hard sell monitoring tools which only address time to detect.&lt;/em&gt;&quot;];it can often take 8 hours to diagnose an Incident/Problem and 8 minutes to fix. So, your RCA/monitor tool should focus on diagnosis, not simply detection.&lt;/p&gt;
&lt;p&gt;As far as multiple causation I have not seen tools that will do the kind of RCA that will tell you the root of your problem is lack of effective pre-production testing. Having a tool --- even a good one --- does not relieve you of your responsibility to dig deeper into the fundamental root causes; that&#039;s where lasting improvements will come from. So YES you need BOTH automation and good practice.&lt;/p&gt;
&lt;p&gt;However, as the complexity of service infrastructures increases, the need for rapid isolation and diagnosis is becoming paramount; particularly in light of what is becoming an n-tier, virtualized mess. &lt;/p&gt;
&lt;p&gt;For example, how long will it take you to diagnose that excessive disk reads by the media server are slowing down Oracle data base accesses? Or (adding VMs to the mix), that excessive disk reads by the user running MS Access is slowing down accesses for the user running Outlook &amp;amp; Word processing!&lt;/p&gt;
&lt;p&gt;Service monitoring intelligence will not do your homework for you. You still need to apply good practices in the form of frameworks like ITIL, CobiT, et al. &lt;/p&gt;
&lt;p&gt;But when you&#039;re up to your a__ in alligators, you&#039;d better get some help. Silo based monitoring isn&#039;t working, and can actually be an inhibitor to the paradigm shift we seek.&lt;/p&gt;
&lt;p&gt;So, why don&#039;t we dive deeper into multiple causation? Lack of pre-production testing may be significant; but if you can&#039;t quickly find out which layer of which component is the source of anomalies you never seem to get there.&lt;/p&gt;
&lt;p&gt;Silo-ed monitoring is the root-cause. That should stir the pot a bit!&lt;/p&gt;
&lt;p&gt;John M. Worthington&lt;br /&gt;
MyServiceMonitor, LLC&lt;/p&gt;
</description>
 <pubDate>Sat, 26 Jul 2008 13:56:30 +0000</pubDate>
 <dc:creator>John Worthington aka MySvcMon</dc:creator>
 <guid isPermaLink="false">comment 3193 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Multiple Causation</title>
 <link>http://www.itskeptic.org/node/698#comment-3190</link>
 <description>&lt;p&gt;The point about multiple causation is a good one. I&#039;ve also always tried to push RCA back beyond the technical fault towards the kind of generic issues that impact a lot of apparantly unrelated incidents, for instance lack of effective pre-production testing.&lt;/p&gt;
</description>
 <pubDate>Fri, 25 Jul 2008 08:33:09 +0000</pubDate>
 <dc:creator>JamesFinister</dc:creator>
 <guid isPermaLink="false">comment 3190 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>The expanded incident lifecycle</title>
 <link>http://www.itskeptic.org/node/698#comment-3189</link>
 <description>&lt;p&gt;All the usual suspects handle incidents by providing a time and then typing in some gobbledygook associated with the time.  None enforces the expanded incident lifecycle.  This lifecycle is the crucial link between incidents and problems as the trending of these times can highlight problems associated with insufficient workarounds plus time to detect, diagnose, repair, restore and recover. Many vendors hard sell monitoring tools which only address time to detect.  In most case studies I have conducted that is hardly ever where the problem lies.&lt;br /&gt;
And while on the topic about the lack of RCA, additionally, most tools assume incorrectly that multiple causation is not required in managing problems.&lt;/p&gt;
</description>
 <pubDate>Thu, 24 Jul 2008 16:51:12 +0000</pubDate>
 <dc:creator>Red Pineapple</dc:creator>
 <guid isPermaLink="false">comment 3189 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>The need for thought</title>
 <link>http://www.itskeptic.org/node/698#comment-3186</link>
 <description>&lt;p&gt;Handling major incidents as a a different process stream should be within the ability of most tools - and to some extent so should the extended lifecycle. In the early days of ITIL the classic question to a vendor was to ask &quot;How does it handle problems?&quot; and if the answer was &quot;You change the I to a P&quot; you would walk away.&lt;/p&gt;
&lt;p&gt;Whilst the usual suspects can also manage the problem work flow (which of course is seperate again from the amjor incident workflow) I&#039;m not aware of any that effectively actually support the analysis activity, that is the bit where you have to engage the crerative juices and actually DO the RCA.&lt;/p&gt;
</description>
 <pubDate>Thu, 24 Jul 2008 08:57:29 +0000</pubDate>
 <dc:creator>JamesFinister</dc:creator>
 <guid isPermaLink="false">comment 3186 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Reminds me...</title>
 <link>http://www.itskeptic.org/node/698#comment-3185</link>
 <description>&lt;p&gt;I once encountered a vendor who will remain nameless, who every time I asked for something that I had referenced or researched in the ITIL books, would answer with a &quot;yes we can do that but it will cost you.&quot;  I asked once, what would the cost be, and was rudely shocked at the price.  My most efficient and effective tool remains a ball point pen and A4 counter book.&lt;/p&gt;
</description>
 <pubDate>Thu, 24 Jul 2008 05:15:05 +0000</pubDate>
 <dc:creator>Red Pineapple</dc:creator>
 <guid isPermaLink="false">comment 3185 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Getting to the root of the Problem....</title>
 <link>http://www.itskeptic.org/node/698#comment-3184</link>
 <description>&lt;p&gt;Of course I immediately started to plug my favorite tool and had to revise my post....everyone has their personal favorites and I am no exception. &lt;/p&gt;
&lt;p&gt;So I will simply say that if you can establish a cross-silo monitor that can look at every layer of every component --- across a distributed array of network, system and application components --- and automatically isolate which layer of which component is the source of an anomaly you&#039;d be off to a good start. &lt;/p&gt;
&lt;p&gt;As far as root-cause correlation, there are many approaches and I am not the geek here... I know of one that leverages a data flow and dependency based correlation which is embedded into the product architecture. :)&lt;/p&gt;
&lt;p&gt;Of course, if the root-cause is a result of process, poor training, or otherwise unrelated to the service technology infrastructure you&#039;re on your own. So, what are you looking for?&lt;/p&gt;
&lt;p&gt;You&#039;ll have to call or e-mail me if you want more info than that.&lt;/p&gt;
&lt;p&gt;There&#039;s another problem though. I&#039;m not sure that looking for tools that fit neatly into ITIL process boxes (Problem Mgt, Config Mgt, etc.) is such a great idea. In fact, ITIL&#039;s suggestion of obtaining an &#039;integrated ITSM suite&#039; is kinda like saying all roads lead to nirvana....good luck. Don&#039;t get me wrong, I think it would be great but when at and what cost? Tomorrow&#039;s always a day away...&lt;/p&gt;
&lt;p&gt;From what I&#039;ve seen and heard from customers, the big gorillas product development is being driven by the marketing departments, who listen to the customer and in a panic-stricken fever rush to devour technology (and market share), which leads to an &#039;evolutionary&#039; approach to product design and &#039;integration&#039; that is more about account control and cost saving than solving problems.&lt;/p&gt;
&lt;p&gt;You want ITIL? We do ITIL! You want root cause? We do root cause! Until you really try to do it, then it&#039;s&lt;/p&gt;
&lt;p&gt;Burrrrp! &lt;/p&gt;
&lt;p&gt;Look at what the tool does, and form your own opinion.&lt;/p&gt;
&lt;p&gt;John M. Worthington&lt;br /&gt;
MyServiceMonitor, LLC&lt;/p&gt;
</description>
 <pubDate>Wed, 23 Jul 2008 22:38:44 +0000</pubDate>
 <dc:creator>John Worthington aka MySvcMon</dc:creator>
 <guid isPermaLink="false">comment 3184 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Thank you.
However, now you</title>
 <link>http://www.itskeptic.org/node/698#comment-3183</link>
 <description>&lt;p&gt;Thank you.&lt;/p&gt;
&lt;p&gt;However, now you ought to remove my post as well, or people might think that I refer to mr. Pineapples&#039; post :-&amp;gt;&lt;/p&gt;
</description>
 <pubDate>Wed, 23 Jul 2008 22:04:32 +0000</pubDate>
 <dc:creator>Michiel</dc:creator>
 <guid isPermaLink="false">comment 3183 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Yes I removed it</title>
 <link>http://www.itskeptic.org/node/698#comment-3182</link>
 <description>&lt;p&gt;Yes I removed it.   An interesting concept for a product but the post was a crude plug.  See more &lt;a href=&quot;http://www.itskeptic.org/node/263&quot;&gt;here &lt;/a&gt;&lt;/p&gt;
</description>
 <pubDate>Wed, 23 Jul 2008 21:51:00 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 3182 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Problem Management</title>
 <link>http://www.itskeptic.org/node/698#comment-3181</link>
 <description>&lt;p&gt;Hi Red,&lt;/p&gt;
&lt;p&gt;I am not familiair with tooling that fills in your questions. IMO, this ought to be covered through an integral approach, touching tooling, people and process. I know of the existence of ATS (Analytical Trouble Shooting). Just google it.&lt;/p&gt;
&lt;p&gt;Also, there has been a recent post where this subject was briefly discussed on the forum of itSMF international. Just look it up under Best Practices.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Michiel&lt;/p&gt;
</description>
 <pubDate>Wed, 23 Jul 2008 21:38:36 +0000</pubDate>
 <dc:creator>Michiel</dc:creator>
 <guid isPermaLink="false">comment 3181 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Survive-now.com</title>
 <link>http://www.itskeptic.org/node/698#comment-3180</link>
 <description>&lt;p&gt;Skep,&lt;/p&gt;
&lt;p&gt;Why do you allow the above post [update: post removed] to remain on your blog? This is nothing more than rubish IMO. ITIL aligned? We can all name a few dozen of those. Extremely flexible? So is my uncles spine (and he is quite old already).&lt;/p&gt;
</description>
 <pubDate>Wed, 23 Jul 2008 21:34:00 +0000</pubDate>
 <dc:creator>Michiel</dc:creator>
 <guid isPermaLink="false">comment 3180 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>A few questions / challenges</title>
 <link>http://www.itskeptic.org/node/698#comment-3179</link>
 <description>&lt;p&gt;Thanks for agreeing, skep!!! I want to touch on a single discipline in which I am interested in and that is problem management.  I have a few questions and challengers:&lt;br /&gt;
1. Is there any IT tool that has problem management as a product attribute that does root cause analysis.  I mean really management and facilitate root cause analysis and not just arbitarily populate fields in a form?&lt;br /&gt;
2. Is there a tool that actually uses and allows the expanded incident lifecycle to be populated and leveraged?&lt;br /&gt;
3. Is there a tool that has a different process stream for handling major incidents versus the rest?&lt;br /&gt;
The above is basic in problem management and if it is not there is the tool stretching the point about being able to assist in problem management?&lt;/p&gt;
</description>
 <pubDate>Wed, 23 Jul 2008 18:48:35 +0000</pubDate>
 <dc:creator>Red Pineapple</dc:creator>
 <guid isPermaLink="false">comment 3179 at http://www.itskeptic.org</guid>
</item>
</channel>
</rss>
