Automatic log sensor tuning
First Claim
Patent Images
1. A method comprising:
- responsive to an occurrence of an alert condition, generating a piped HTTP request for performing analytics on a first set of machine data in a search cluster, the first set of machine data collected by a collector according to a first configuration of the collector, the first configuration establishing default data collection levels;
receiving a single-threaded, piped HTTP response to the piped HTTP request as analytics output;
determining a second configuration for the collector to collect a second set of machine data responsive to the analytics output, the second configuration establishing debug data collection levels, wherein the debug data collection level causes a list of events to be monitored for data collection in addition to actions of the default data collection levels;
executing a sync instruction to the collector to replace the first configuration with the second configuration; and
causing the collector to collect a second set of machine data by processing new machine data according to the second configuration, the new machine data generated after the occurrence of the alert condition;
wherein;
the second set of machine data includes event-specific data determined to be relevant by the performing analytics on the first set of machine data.
1 Assignment
0 Petitions
Accused Products
Abstract
A process for automatic tuning a set of collectors and/or sensors includes: collecting first machine data by a first sensor in a collection framework, processing the first machine data by a first collector in the collection framework to yield first collected machine data, performing analytics on the first collected machine data to generate analytics output, and tuning, based, at least in part, on the analytics output, at least one of the following: the first sensor and the first collector.
-
Citations
20 Claims
-
1. A method comprising:
-
responsive to an occurrence of an alert condition, generating a piped HTTP request for performing analytics on a first set of machine data in a search cluster, the first set of machine data collected by a collector according to a first configuration of the collector, the first configuration establishing default data collection levels; receiving a single-threaded, piped HTTP response to the piped HTTP request as analytics output; determining a second configuration for the collector to collect a second set of machine data responsive to the analytics output, the second configuration establishing debug data collection levels, wherein the debug data collection level causes a list of events to be monitored for data collection in addition to actions of the default data collection levels; executing a sync instruction to the collector to replace the first configuration with the second configuration; and causing the collector to collect a second set of machine data by processing new machine data according to the second configuration, the new machine data generated after the occurrence of the alert condition; wherein; the second set of machine data includes event-specific data determined to be relevant by the performing analytics on the first set of machine data. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A computer program product comprising a computer-readable storage medium having a set of instructions stored therein which, when executed by a processor, causes the processor to perform a tuning action by:
-
responsive to an occurrence of an alert condition, generating a piped HTTP request for performing analytics on a first set of machine data in a search cluster, the first set of machine data collected by a collector according to a first configuration of the collector, the first configuration establishing default data collection levels; receiving a single-threaded, piped HTTP response to the piped HTTP request as analytics output; determining a second configuration for the collector to collect a second set of machine data responsive to the analytics output, the second configuration establishing debug data collection levels, wherein the debug data collection level causes a list of events to be monitored for data collection in addition to actions of the default data collection levels; executing a sync instruction to the collector to replace the first configuration with the second configuration; and causing the collector to collect a second set of machine data by processing new machine data according to the second configuration, the new machine data generated after the occurrence of the alert condition; wherein; the second set of machine data includes event-specific data determined to be relevant by the performing analytics on the first set of machine data. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
-
15. A computer system comprising:
-
a processor set; and a computer readable storage medium; wherein; the processor set is structured, located, connected, and/or programmed to run program instructions stored on the computer readable storage medium; and the program instructions which, when executed by the processor set, cause the processor set to perform a tuning action by; responsive to an occurrence of an alert condition, generating a piped HTTP request for performing analytics on a first set of machine data in a search cluster, the first set of machine data collected by a collector according to a first configuration of the collector, the first configuration establishing default data collection levels; receiving a single-threaded, piped HTTP response to the piped HTTP request as analytics output; determining a second configuration for the collector to collect a second set of machine data responsive to the analytics output, the second configuration establishing debug data collection levels, wherein the debug data collection level causes a list of events to be monitored for data collection in addition to actions of the default data collection levels; executing a sync instruction to the collector to replace the first configuration with the second configuration; and causing the collector to collect a second set of machine data by processing new machine data according to the second configuration, the new machine data generated after the occurrence of the alert condition; wherein; the second set of machine data includes event-specific data determined to be relevant by the performing analytics on the first set of machine data. - View Dependent Claims (16, 17, 18, 19, 20)
-
Specification