×

Anomaly classification, analytics and resolution based on annotated event logs

  • US 10,133,614 B2
  • Filed: 03/24/2015
  • Issued: 11/20/2018
  • Est. Priority Date: 03/24/2015
  • Status: Active Grant
First Claim
Patent Images

1. A machine-implemented method of separately dealing with emerging and possibly not routine anomalies of a data processing system that could be of significance to continuing operations of the data processing system, the data processing system being subdivided into a plurality of sections with each section comprising intercoupled local resources including one or more local data processing units and one or more local data storage units, wherein two or more of the plural sections each respectively includes a respective section behaviors logging subsystem configured to automatically log monitored behaviors within the respective section and a respective section alarming subsystem configured to automatically generate alarms for alarm worthy events within the respective section, wherein said routine anomalies and said emerging and possibly not routine anomalies are not catastrophic failures, the method comprising:

  • running a first section among said plural sections of the data processing system where the first section includes as its respective section alarming subsystem, a first section alarming subsystem and includes as its respective section behaviors logging subsystem, a first section behaviors logging subsystem, the first section alarming subsystem being configured to generate alarms for non-catastrophic alarm-worthy events detected within the first section, the section behaviors logging subsystem being configured to generate a log of monitored behaviors within the first section;

    logically co-associating recently logged behaviors of the generated log produced by the first section behaviors logging subsystem with substantially cotemporaneous alarms generated by the first section alarming subsystem;

    building an annotated log comprised of the logically co-associated logged behaviors and the substantially cotemporaneous alarms;

    using the annotated log to update a corresponding anomalies versus parameters first mapping space populated by sample points representing previously identified as routine anomalies of the first section of the data processing system by adding recent, alarm-including sample point entries from the annotated log into the first mapping space as recently logged ones of alarmed sample points (ASP'"'"'s);

    determining if the recently logged ASP'"'"'s map into a first region of the first mapping space occupied by older ASP'"'"'s associated with the identified as routine anomalies or if the recently logged ASP'"'"'s map into a different region of the first mapping space, where the ASP'"'"'s which map into the different region can represent newly emerging and possibly non-routine anomalies;

    automatically repeating said logically co-associating step, said building step, said using step and said determining step while the first section of the data processing system continues to run; and

    automatically responding to said determining that the recently logged ASP'"'"'s map into the different region and can thus represent newly emerging and possibly non-routine anomalies that could be of significance to operations of the data processing system, the automatic responding being separate from responses to known-to-be-routine anomalies and separate from responses to detected catastrophic failures.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×