Method and system for clustering event messages and managing event-message clusters

US10616038B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10616038-B2
Application numberUS-201615251481-A
CountryUS
Kind codeB2
Filing dateAug 30, 2016
Priority dateJun 24, 2014
Publication dateApr 7, 2020
Grant dateApr 7, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The current document is directed to methods and systems that process, classify, efficiently store, and display large volumes of event messages generated in modern computing systems. In a disclosed implementation, received event messages are assigned to event-message clusters based on non-parameter tokens identified within the event messages. A parsing function is generated for each cluster that is used to extract data from incoming event messages and to prepare event records from event messages that more efficiently and accessible store event information. The parsing functions also provide an alternative basis for assignment of event messages to clusters. Event types associated with the clusters are used for gathering information from various information sources with which to automatically annotate event messages displayed to system administrators, maintenance personnel, and other users of event messages.

First claim

Opening claim text (preview).

The invention claimed is: 1. A system that displays accumulated events, the system comprising: one or more processors; one or more memories; one or more data-storage devices; a display device; and computer instructions, stored in one or more of the one or more memories that, when executed by one or more of the one or more processors, control the accumulated-event display system to accumulate events in one or more of the one or more memories and one or more data-storage devices; determine a set of event types, each accumulated event belonging to one of the event types; display, on the display screen, active representations of event types to which the accumulated events belong; and in response to an input directed to a particular displayed active representation of an event type, accessing stored descriptions of information entities associated with event types to select one or more of the stored descriptions of information entities associated with the event type represented by the particular displayed representation, and displaying, on the display screen, an active representation of each of the one or more selected descriptions of information entities, an input to each of which invokes display of a corresponding information entity. 2. The system of claim 1 wherein, in a first display mode, the system displays representations of events on the display screen; and wherein, in a second display more, the system displays, on the display screen, active representations of event types to which the accumulated events belong. 3. The system of claim 2 wherein types of information sources include: a remote server that is accessed through a uniform resource locator; a person or system accessed through an email address; a person or system accessed through a phone number; a person accessed through a mail address; a person or system accessed through a social network; a person or system accessed through a web browser; component or system information that is accessed through a stock keeping unit input to a search engine or on-line information interface; and an on-line information service accessed through a dial-up phone number. 4. The system of claim 1 wherein descriptions of information entities associated with event types are stored in an associated-information database that, for each information entity associated with an event type, stores: an indication of an information source for the information entity; an indication of the type of information source; and an indication of the type of information entity. 5. The system of claim 1 wherein types of information entities include: a blog page; a web page; an article encoded in a text file; an article encoded in a web page; a link to an article encoded in a web page; an article encoded in a formatted file; a human developer; a human expert; a frequently-asked-question message or message response; a frequently-asked-question message or message response encoded in a web page; a link to a frequently-asked-question message or message response encoded in a web page; text stored in a database; a user manual or product specification encoded in a web page; and a link to a user manual or product specification encoded in a web page; and a user manual or product specification encoded in a text file; and a user manual or product specification encoded in a formatted file. 6. The system of claim 1 wherein the accumulated events are one of: entries in event-log files; and error messages generated within one or more computer systems. 7. The system of claim 1 wherein display of active representations of each of the one or more selected descriptions of information entities further comprises: displaying an additional-information text-display window above, below, to the side of, or overlapping the displayed event types, the additional-information text-display window including, for each displayed active representation of each of the one or more selected descriptions of information entities, a textural description of the information entity embedded within, or displayed adjacent to, an active input feature that receives an input through an input device or subsystem. 8. The system of claim 7 wherein the active input feature is one of: a button or other feature to which an input is directed; a hyperlink to which an input is directed; and an active area of the display screen underlying the displayed active representation to which an input is directed. 9. The system of claim 1 wherein event types are generated by: receiving event messages; and processing each of the received event messages by normalizing the event message to identify parameter tokens within the event message, computing, using non-parameter tokens within the event message, a metric to represent the event message, using the metric to select an event-message cluster to which to assign the event message, generating an event record using an identifier for the selected cluster and the parameter tokens, and storing the event record within, or associated with, the selected cluster in a physical data-storage device. 10. A method that displays accumulated events in a system having one or more processors, one or more memories, one or more data-storage devices, and a display device, the method comprising: accumulating events in one or more of the one or more memories and one or more data-storage devices; determining a set of event types, each accumulated event belonging to one of the event types; displaying, on the display screen, active representations of event types to which the accumulated events belong; and in response to an input directed to a particular displayed active representation of an event type, accessing stored descriptions of information entities associated with event types to select one or more of the stored descriptions of information entities associated with the event type represented by the particular displayed representation, and displaying, on the display screen, an active representation of each of the one or more selected descriptions of information entities, an input to each of which invokes display of a corresponding information entity. 11. The method of claim 10 wherein, in a first display mode, displaying representations of events on the display screen; and wherein, in a second display more, the system displays, on the display screen, active representations of event types to which the accumulated events belong. 12. The method of claim 10 wherein descriptions of information entities associated with event types are stored in an associated-information database that, for each information entity associated with an event type, stores: an indication of an information source for the information entity; an indication of the type of information source; and an indication of the type of information entity. 13. The method of claim 12 wherein types of information sources include: a remote server that is accessed through a uniform resource locator; a person or system accessed through an email address; a person or system accessed through a phone number; a person accessed through a mail address; a person or system accessed through a social network; a person or system accessed through a web browser; component or system information that is accessed through a stock keeping unit input to a search engine or on-line information interface; and an on-line information service accessed through a dial-up phone number. 14. The system of claim 1 wherein types of information entities include: a blog page; a web page; an article encoded in a

Assignees

Inventors

Classifications

  • in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title

  • comprising specially adapted graphical user interfaces [GUI] · CPC title

  • using logs of notifications; Post-processing of notifications · CPC title

  • based on the type or category of the network elements · CPC title

  • Electricity · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10616038B2 cover?
The current document is directed to methods and systems that process, classify, efficiently store, and display large volumes of event messages generated in modern computing systems. In a disclosed implementation, received event messages are assigned to event-message clusters based on non-parameter tokens identified within the event messages. A parsing function is generated for each cluster that…
Who is the assignee on this patent?
Vmware Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/0613. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 07 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).