To address the challenges of digital transformation and enhance overall IT O&M capabilities, the data center management framework in the financial industry has been continuously evolving and maturing. We see this evolution broadly divided into two major phases: from narrow-scope data center monitoring management to broad-scope data center monitoring management. The broad-scope approach increasingly emphasizes comprehensive construction from a business value perspective across all domains. By establishing robust Monitoring and Alerting management standards—combined with the right tooling—organizations can improve system stability and
reliability, reduce the occurrence and impact of failures, and elevate business value.
A major insurance company leveraged the CanWay BlueWhale Alert Management Platform to establish a comprehensive alert management framework, build a full alert lifecycle management system, and achieve significant improvements in business availability.
01 Business Scenario
Over the course of years of monitoring buildout, the company had progressively implemented network device monitoring, infrastructure monitoring, middleware and database monitoring, cloud platform monitoring, application monitoring, and facility monitoring (power and environmental). All Monitoring and Alerting management standards and tools were administered by data center managers, while domain-specific management staff and outsourced personnel were responsible for receiving and handling alerts generated during the monitoring process. Due to the dispersion of monitoring systems and the large number of roles involved, it was difficult for data center administrators to enforce standardized management.
Without professional tooling support, the generation, routing, and handling of alerts consumed excessive time, resulting in low response and processing efficiency and impacting business continuity. Meanwhile, because domain-specific management roles were widely distributed, it was extremely difficult to assess and quantify alert handling efficiency and associated labor costs.
02 Pain Point Analysis
The company had well-defined management processes but lacked the tooling to support them, resulting in the following pain points in real-world business scenarios:
Tooling Unable to Match Management Standards
Based on the company's alert management standards, alerts at Level 5 and above should automatically generate incident tickets assigned to the appropriate personnel. Furthermore, standards are refined throughout the alert governance process, requiring flexible, configurable adaptation.
Non-Standardized Alert Information
Due to the diversity of monitoring systems and their early deployment timelines, alert information lacked standardization, with many alerts even missing critical details.
Excessive Tickets Due to Lack of Alert Convergence
In the existing systems, over 60% of generated alerts were duplicates. These invalid and repetitive alerts led to an excessive volume of incident tickets and alert notifications, requiring significant manual effort during processing to identify and correlate duplicate tickets. The excessive number of incident tickets also violated management standards.
Inability to Adapt to Trading Hours
Business systems in the financial industry are closely tied to trading schedules. Changes and trading window closures also generate invalid alerts, requiring alert validity to be determined based on trading hours.
Alert Storms Triggered by Changes
During or after change implementations, a large volume of alerts is generated. Alerts caused by changes need to be automatically suppressed.
03 Solution
1. Aligning Alert Management Standards with Best Practices
Based on the company's organizational structure and management standards, combined with business scenarios, a closed-loop alert lifecycle management process was achieved through configuration and integration with third-party systems.
2. Alert Enrichment and Dynamic Dispatch via CMDB
By correlating with CMDB data, alert information was enriched and refined. Leveraging the responsible-person information in CMDB instances, dynamic alert routing was implemented, ensuring the timeliness and accuracy of alert notifications.
3. Alert Convergence Based on Trading Calendar and Changes
Based on the trading calendar and ITSM change tickets, alert convergence policy timeframes were modified or new convergence policies were created. Through automation, invalid alerts were reduced as much as possible.
04 Results Showcase
1. Dynamic Alert Dispatch via CMDB


2. Alert Suppression Based on ITSM Change Tickets


3. Trading Calendar-Controlled Suppression Policy Activation


05 Implementation Outcomes
Achieved unified lifecycle management of alerts across multiple monitoring systems, with 100% of alerts under management.
Implemented dynamic alert dispatch with precise delivery—less than 1 minute from alert generation to notification.
Achieved alert convergence tailored to the characteristics of the financial industry, reducing resource waste from invalid alerts and reaching a 70% alert convergence rate.
Combined multiple automation scenarios to reduce the cost of routine manual maintenance and management.
Provided data support for alert governance, enabling optimization at every stage through data-driven retrospective analysis.
06 Scenario Applicability
The CanWay BlueWhale Alert Management Platform is designed for alert lifecycle management scenarios. Combined with enterprise alert management standards, it delivers best-practice implementation guidance. It is applicable to the financial industry and other broader industries seeking efficient alert handling and standardized approaches to ensure continuous business system availability. It is suitable for enterprises with the following business scenario requirements:
Enterprises with numerous monitoring systems but no centralized alert management system.
Enterprises with a high volume of alerts—many of which are invalid—resulting in low alert processing efficiency.
Enterprises where alert generation is tied to market trading open/close times, requiring alerts to be handled differently based on trading schedules.
Enterprises whose existing Monitoring and Alerting lacks comprehensive standards and whose management is disorganized, seeking standardization.
Enterprises that find Root Cause Analysis (RCA) difficult during alert handling and desire supplementary information for troubleshooting.
Enterprises that want to implement automated remediation for established scenarios or drive scenario innovation through self-healing capabilities.

















