System for decomposing clustering events from managed infrastructures
First Claim
Patent Images
1. An event clustering system with a processor that generates reports, comprising:
- an extraction engine in communication with an infrastructure, the extraction engine in operation receiving data from the infrastructure and produces events and populates a database with a dictionary of event or graph entropy;
an alert engine that receives the events and creates alerts mapped into a matrix, M;
a signalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine, the signalizer engine determining one or more common steps from events and produces clusters relating to the alerts and or events, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware of the infrastructure directed to supporting the flow and processing of information;
the topology proximity engine using a source address for each event and topology of the infrastructure which represents node to node connectivity of the topology proximity engine and to assign a graph coordinate of a graph to the event with an optional subset of attributes being extracted for each event and turned into a vector of the graph, the topology engine inputs a list of devices and a list a connections between components or nodes in the infrastructure where the graph entropy is calculated for each node in the graph;
one or more interaction displays that provide a collaborative interface a coupled to the extraction and the signalizer engine for decomposing events from the infrastructure; and
a reporting engine configured to be coupled to the event clustering system, the reporting engine configured to generate a report from at least one of the clusters and the events that are retrieved from the collaborative interfacea source address for each event to assign a graph coordinate in the graph to the event with an optional subset of attributes being extracted for each event and turning that into a vector of the graph; and
in response to production of the clusters making one or more physical chances in the infrastructure hardware.
5 Assignments
0 Petitions
Accused Products
Abstract
An event clustering system is configured to generate reports. An extraction engine is in communication with an infrastructure. The extraction engine in operation receives data from the infrastructure and produces events. An alert engine receives the events and creates alerts mapped into a matrix, M. A sigalizer engine includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine. The sigalizer engine determines one or more common steps from events and produces clusters relating to the alerts and or events. A reporting engine is configured to be coupled to the event clustering system.
50 Citations
23 Claims
-
1. An event clustering system with a processor that generates reports, comprising:
-
an extraction engine in communication with an infrastructure, the extraction engine in operation receiving data from the infrastructure and produces events and populates a database with a dictionary of event or graph entropy; an alert engine that receives the events and creates alerts mapped into a matrix, M; a signalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine, the signalizer engine determining one or more common steps from events and produces clusters relating to the alerts and or events, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware of the infrastructure directed to supporting the flow and processing of information; the topology proximity engine using a source address for each event and topology of the infrastructure which represents node to node connectivity of the topology proximity engine and to assign a graph coordinate of a graph to the event with an optional subset of attributes being extracted for each event and turned into a vector of the graph, the topology engine inputs a list of devices and a list a connections between components or nodes in the infrastructure where the graph entropy is calculated for each node in the graph; one or more interaction displays that provide a collaborative interface a coupled to the extraction and the signalizer engine for decomposing events from the infrastructure; and a reporting engine configured to be coupled to the event clustering system, the reporting engine configured to generate a report from at least one of the clusters and the events that are retrieved from the collaborative interface a source address for each event to assign a graph coordinate in the graph to the event with an optional subset of attributes being extracted for each event and turning that into a vector of the graph; and in response to production of the clusters making one or more physical chances in the infrastructure hardware. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23)
-
Specification