System for decomposing events from managed infrastructures with semantic clustering

US10693707B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10693707-B2
Application numberUS-201816043168-A
CountryUS
Kind codeB2
Filing dateJul 24, 2018
Priority dateJan 27, 2015
Publication dateJun 23, 2020
Grant dateJun 23, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system is provided for decomposing events from managed infrastructures. A first engine is configured to receive message data from a managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, the at least one engine is configured to determine common characteristics of events and produce clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in a physical hardware of the managed infrastructure directed to supporting the flow and processing of information. The first engine is configured to create one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. A second engine is configured to determine one or more common steps from events and produces clusters relating to events. The second engine determines one or more common characteristics of events and produces clusters of events relating to the failure or errors in the managed infrastructure. The system is configured to use data-driven fault localization, more particularly using semantic clustering.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for decomposing events from a managed infrastructure, comprising: one or more processors: a memory including instructions that when executed by the one or more processors executes the following: a first engine receiving data from a managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information; a second engine coupled to the first engine determining common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information, and producing events that relate to the managed infrastructure while converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware; and a semantic clustering engine coupled to the first and second engines taking text from an event source, manipulates the text to produce a feature vector for each of an event, and the feature vector is feed into a clustering engine, with semantic clustering looking at text description of events, analyses the words in the text description, and groups them with other events when there is significant overlap; and wherein a change to a managed infrastructure physical hardware component is made on the semantic clustering. 2. The system of claim 1 , further comprising: using a vector quantization for cluster analysis. 3. The system of claim 2 , wherein the vector quantization is a K-means algorithm. 4. The system of claim 1 , wherein the clustering engine executes on a sliding window of data on a period basis. 5. The system of claim 4 , wherein a variety of the period basis is utilized. 6. The system of claim 1 , wherein the system periodically takes a snapshot of the prior X minutes of data to group data alerts. 7. The system of claim 4 , wherein attributes are used for grouping data. 8. The system of claim 7 , wherein a choice of attributes is taken at a deployment level that is determined by a client. 9. The system of claim 8 , wherein the attributes are turned into a feature vector that is executed using the sliding data worth of data. 10. The system of claim 8 , wherein a similarity of the attributes is grouped together. 11. The system of claim 1 , wherein the clustering engine operates in a streaming manner for data. 12. The system of claim 1 , wherein the clustering engine operates in a streaming manner of the data that streams continuously for a selected period of time. 13. The system of claim 12 , wherein every time an event arrives it is at least one of: allocated to a cluster; and a new cluster is created. 14. The system of claim 13 , wherein attributes are turned into a feature vector that is executed using the streaming manner of data. 15. The system of claim 1 , wherein the first engine is an extraction engine. 16. The system of claim 1 , wherein the second engine is a signaliser engine. 17. The system of claim 1 , further comprising: a compare and merge engine coupled to the first and second engines and receiving outputs from the second engine, the compare and merge engine communicating with one or more user interfaces in a situation room. 18. The system of claim 1 , wherein the first engine in operation receives messages from the managed infrastructure. 19. The system of claim 1 , wherein the first engine in operation produces events that relate to the managed infrastructure. 20. The system of claim 19 , wherein the events are converted into words and subsets used to group the events into clusters that relate to failures or errors in the managed infrastructure. 21. The system of claim 1 , wherein the second engine includes one or more of an Non-negative Matrix Factorization NMF engine, a k-means clustering engine and a topology proximity engine.

Assignees

Inventors

Classifications

  • Policy-based network configuration management · CPC title

  • H04L41/046Primary

    comprising network management agents or mobile agents therefor · CPC title

  • H04L41/064Primary

    involving time analysis · CPC title

  • Protocols · CPC title

  • involving logical or physical relationship, e.g. grouping and hierarchies · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10693707B2 cover?
A system is provided for decomposing events from managed infrastructures. A first engine is configured to receive message data from a managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information, the at least one engine is configured to determine common characteristics of events and produce clusters of events relating to the …
Who is the assignee on this patent?
Moogsoft Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/046. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 23 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).