×

System for decomposing clustering events from managed infrastructures

  • US 10,013,476 B2
  • Filed: 07/08/2014
  • Issued: 07/03/2018
  • Est. Priority Date: 04/28/2014
  • Status: Active Grant
First Claim
Patent Images

1. An event clustering system with a processor that generates reports, comprising:

  • an extraction engine in communication with an infrastructure, the extraction engine in operation receiving data from the infrastructure and produces events and populates a database with a dictionary of event or graph entropy;

    an alert engine that receives the events and creates alerts mapped into a matrix, M;

    a signalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine, the signalizer engine determining one or more common steps from events and produces clusters relating to the alerts and or events, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware of the infrastructure directed to supporting the flow and processing of information;

    the topology proximity engine using a source address for each event and topology of the infrastructure which represents node to node connectivity of the topology proximity engine and to assign a graph coordinate of a graph to the event with an optional subset of attributes being extracted for each event and turned into a vector of the graph, the topology engine inputs a list of devices and a list a connections between components or nodes in the infrastructure where the graph entropy is calculated for each node in the graph;

    one or more interaction displays that provide a collaborative interface a coupled to the extraction and the signalizer engine for decomposing events from the infrastructure; and

    a reporting engine configured to be coupled to the event clustering system, the reporting engine configured to generate a report from at least one of the clusters and the events that are retrieved from the collaborative interfacea source address for each event to assign a graph coordinate in the graph to the event with an optional subset of attributes being extracted for each event and turning that into a vector of the graph; and

    in response to production of the clusters making one or more physical chances in the infrastructure hardware.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×