Method and system for clustering event messages and managing event-message clusters
US-2016373293-A1 · Dec 22, 2016 · US
US10616038B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10616038-B2 |
| Application number | US-201615251481-A |
| Country | US |
| Kind code | B2 |
| Filing date | Aug 30, 2016 |
| Priority date | Jun 24, 2014 |
| Publication date | Apr 7, 2020 |
| Grant date | Apr 7, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The current document is directed to methods and systems that process, classify, efficiently store, and display large volumes of event messages generated in modern computing systems. In a disclosed implementation, received event messages are assigned to event-message clusters based on non-parameter tokens identified within the event messages. A parsing function is generated for each cluster that is used to extract data from incoming event messages and to prepare event records from event messages that more efficiently and accessible store event information. The parsing functions also provide an alternative basis for assignment of event messages to clusters. Event types associated with the clusters are used for gathering information from various information sources with which to automatically annotate event messages displayed to system administrators, maintenance personnel, and other users of event messages.
Opening claim text (preview).
The invention claimed is: 1. A system that displays accumulated events, the system comprising: one or more processors; one or more memories; one or more data-storage devices; a display device; and computer instructions, stored in one or more of the one or more memories that, when executed by one or more of the one or more processors, control the accumulated-event display system to accumulate events in one or more of the one or more memories and one or more data-storage devices; determine a set of event types, each accumulated event belonging to one of the event types; display, on the display screen, active representations of event types to which the accumulated events belong; and in response to an input directed to a particular displayed active representation of an event type, accessing stored descriptions of information entities associated with event types to select one or more of the stored descriptions of information entities associated with the event type represented by the particular displayed representation, and displaying, on the display screen, an active representation of each of the one or more selected descriptions of information entities, an input to each of which invokes display of a corresponding information entity. 2. The system of claim 1 wherein, in a first display mode, the system displays representations of events on the display screen; and wherein, in a second display more, the system displays, on the display screen, active representations of event types to which the accumulated events belong. 3. The system of claim 2 wherein types of information sources include: a remote server that is accessed through a uniform resource locator; a person or system accessed through an email address; a person or system accessed through a phone number; a person accessed through a mail address; a person or system accessed through a social network; a person or system accessed through a web browser; component or system information that is accessed through a stock keeping unit input to a search engine or on-line information interface; and an on-line information service accessed through a dial-up phone number. 4. The system of claim 1 wherein descriptions of information entities associated with event types are stored in an associated-information database that, for each information entity associated with an event type, stores: an indication of an information source for the information entity; an indication of the type of information source; and an indication of the type of information entity. 5. The system of claim 1 wherein types of information entities include: a blog page; a web page; an article encoded in a text file; an article encoded in a web page; a link to an article encoded in a web page; an article encoded in a formatted file; a human developer; a human expert; a frequently-asked-question message or message response; a frequently-asked-question message or message response encoded in a web page; a link to a frequently-asked-question message or message response encoded in a web page; text stored in a database; a user manual or product specification encoded in a web page; and a link to a user manual or product specification encoded in a web page; and a user manual or product specification encoded in a text file; and a user manual or product specification encoded in a formatted file. 6. The system of claim 1 wherein the accumulated events are one of: entries in event-log files; and error messages generated within one or more computer systems. 7. The system of claim 1 wherein display of active representations of each of the one or more selected descriptions of information entities further comprises: displaying an additional-information text-display window above, below, to the side of, or overlapping the displayed event types, the additional-information text-display window including, for each displayed active representation of each of the one or more selected descriptions of information entities, a textural description of the information entity embedded within, or displayed adjacent to, an active input feature that receives an input through an input device or subsystem. 8. The system of claim 7 wherein the active input feature is one of: a button or other feature to which an input is directed; a hyperlink to which an input is directed; and an active area of the display screen underlying the displayed active representation to which an input is directed. 9. The system of claim 1 wherein event types are generated by: receiving event messages; and processing each of the received event messages by normalizing the event message to identify parameter tokens within the event message, computing, using non-parameter tokens within the event message, a metric to represent the event message, using the metric to select an event-message cluster to which to assign the event message, generating an event record using an identifier for the selected cluster and the parameter tokens, and storing the event record within, or associated with, the selected cluster in a physical data-storage device. 10. A method that displays accumulated events in a system having one or more processors, one or more memories, one or more data-storage devices, and a display device, the method comprising: accumulating events in one or more of the one or more memories and one or more data-storage devices; determining a set of event types, each accumulated event belonging to one of the event types; displaying, on the display screen, active representations of event types to which the accumulated events belong; and in response to an input directed to a particular displayed active representation of an event type, accessing stored descriptions of information entities associated with event types to select one or more of the stored descriptions of information entities associated with the event type represented by the particular displayed representation, and displaying, on the display screen, an active representation of each of the one or more selected descriptions of information entities, an input to each of which invokes display of a corresponding information entity. 11. The method of claim 10 wherein, in a first display mode, displaying representations of events on the display screen; and wherein, in a second display more, the system displays, on the display screen, active representations of event types to which the accumulated events belong. 12. The method of claim 10 wherein descriptions of information entities associated with event types are stored in an associated-information database that, for each information entity associated with an event type, stores: an indication of an information source for the information entity; an indication of the type of information source; and an indication of the type of information entity. 13. The method of claim 12 wherein types of information sources include: a remote server that is accessed through a uniform resource locator; a person or system accessed through an email address; a person or system accessed through a phone number; a person accessed through a mail address; a person or system accessed through a social network; a person or system accessed through a web browser; component or system information that is accessed through a stock keeping unit input to a search engine or on-line information interface; and an on-line information service accessed through a dial-up phone number. 14. The system of claim 1 wherein types of information entities include: a blog page; a web page; an article encoded in a
in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title
comprising specially adapted graphical user interfaces [GUI] · CPC title
using logs of notifications; Post-processing of notifications · CPC title
based on the type or category of the network elements · CPC title
Electricity · mapped topic
Related publications grouped by family.
Answers are generated from the same data shown on this page.