Alert dashboard system and method from event clustering

US9607074B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9607074-B2
Application numberUS-201414262861-A
CountryUS
Kind codeB2
Filing dateApr 28, 2014
Priority dateApr 29, 2013
Publication dateMar 28, 2017
Grant dateMar 28, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer-implemented method is provided that is stored on computer readable non-transitory media. One or more data fields are accessed within a file. Accessed data field, are mapped mapping on a display computer system. The accessed one or more data fields are from one or more data sources that relate to alerts from clustering messages received from managed infrastructure. The mapping being performed based on a input of the alert summaries using a graphical user interface. Displayed on the display computer system are one or more dashboards of alerts relative to summaries from clustering messages received from managed infrastructure. The one or more dashboards include at least one of actions that a user can take relative to clustered messages.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method stored on computer readable non-transitory media, comprising: receiving messages at an extraction engine from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information; producing events that relate to the managed infrastructure; providing a sigalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine; using the sigalizer engine to determine one or more common characteristics of one or more events; using the signalizer engine with the NMF engine, the k-means clustering engine and the topology proximity engine to produce clusters of events relating to a failure or errors in the managed infrastructure, the topology proximity engine using a source address for each event and a graph topology of the managed infrastructure which represents node to node connectivity of the topology proximity engine and assigns a graph coordinate to the event with an optional subset of attributes being extracted for each event and turned into a vector, the topology engine inputting a list of devices and a list a connections between components or nodes in the managed infrastructure; using membership in a cluster to determine a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information; in response to the production of the clusters making one or more proposed physical hardware changes in a managed infrastructure hardware; accessing one or more data fields within a file directed to the one or more proposed physical hardware changes in a managed infrastructure hardware; mapping on a display computer system accessed one or more proposed physical hardware changes in a managed infrastructure hardware; and displaying on the display computer system a dashboard of the display computer system configured to generate a dashboard display from a configuration in the file that includes one or more proposed physical hardware changes in a managed infrastructure hardware. 2. The method of claim 1 , further comprising: converting data from the clusters of events that are compatible with a format of the file using the external connection adapter. 3. The method of claim 1 , wherein the file is a web format file that exposes one or more data fields of the alerts from the clusters of events. 4. The method of claim 1 , wherein a graphical user interface is used for receiving textual programming code from a user. 5. A user interface system comprising: an extraction engine to communicate with a managed infrastructure that includes physical hardware, and receiving messages from the managed infrastructure; a sigalizer engine that determines one or more common steps from events and produces clusters of events relating to a failure or errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware of the managed infrastructure directed to supporting the flow and processing of information, in response to the production of the clusters making one or more proposed physical hardware changes in a managed infrastructure hardware; an external connection adapter configured to provide access to one or more data fields within a file; a display computer system configured to display using a graphical user interface the one or more data fields relating to the failure or the actionable problem in the physical hardware of the managed infrastructure; and the display computer system configured to generate a dashboard display that includes the failure or the actionable problem in the physical hardware of the managed infrastructure. 6. The system of claim 5 , wherein the graphical user interface is free of receiving textual programming code from the user. 7. The system of claim 5 , wherein one or more alerts are produced in response to the production of the clusters. 8. The system of claim 7 , wherein the common steps are in response to data that include attributes selected from at least one of, time, source a description of the event, textural or numerical values from which those text or numerical values indicate a state of any hardware or software component of an infrastructure. 9. The system of claim 7 , wherein the alerts are in response to event or subsets of events that relate to failures or errors in an infrastructure. 10. The system of claim 5 , wherein the alerts are in response to subsets of messages or the events that are grouped into the clusters. 11. The system of claim 5 , wherein one or more alerts are produced in response to extracted text components from the events that are convert into word and subtext. 12. The system of claim 11 , wherein the alerts are in response to utilization of a generated dictionary with the word and subtexts using Shannon Entropy. 13. The system of claim 12 , wherein normalized words and subtexts are mapped from a common 0.0 to a non-common 1.0. 14. The system of claim 13 , wherein the alerts are in response to utilization of an entropy database that in operation normalizes entropy for events. 15. The system of claim 1 , wherein the entropy for events creates normalized entropy for events mapped to a common, 0.0 and a non-common, 1.0. 16. The system of claim 5 , wherein the alerts are generated in response to outputs from a sigalizer engine.

Assignees

Inventors

Classifications

  • Assignment of logical groups to network elements · CPC title

  • using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis · CPC title

  • involving logical or physical relationship, e.g. grouping and hierarchies · CPC title

  • Discovery or management of network topologies · CPC title

  • Browsing; Visualisation therefor · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9607074B2 cover?
A computer-implemented method is provided that is stored on computer readable non-transitory media. One or more data fields are accessed within a file. Accessed data field, are mapped mapping on a display computer system. The accessed one or more data fields are from one or more data sources that relate to alerts from clustering messages received from managed infrastructure. The mapping being p…
Who is the assignee on this patent?
Moogsoft Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/22. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 28 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).