Continuous anomaly detection service
First Claim
Patent Images
1. A computer-implemented method for performing anomaly detection, comprising:
- receiving a plurality of data streams;
storing, for each of the data streams, one or more events in a field searchable data store;
determining one or more of the data streams associated with one or more corresponding signals of a plurality of signals;
identifying, from the one or more determined data streams, relevant events of the one or more events that are associated with the one or more corresponding signals;
identifying, for each of the one or more determined data streams, a corresponding set of data points by deriving values for the data points from machine data of the relevant events for the determined data stream;
inserting the identified sets of data points into the one or more corresponding signals; and
continuously performing anomaly detection on the plurality of signals.
1 Assignment
0 Petitions
Accused Products
Abstract
An anomaly detection system includes a plurality of signals. Each of the signals is associated with an anomaly detection procedure that will be used to identify anomalies within the signal. Anomaly detection is performed by applying the anomaly detection procedure to a sequential set of data points of a signal. The signals are updated based on incoming data streams. The data streams are analyzed, and the sequential set of data points for each signal is updated based on data points extracted from the data streams.
-
Citations
20 Claims
-
1. A computer-implemented method for performing anomaly detection, comprising:
-
receiving a plurality of data streams; storing, for each of the data streams, one or more events in a field searchable data store; determining one or more of the data streams associated with one or more corresponding signals of a plurality of signals; identifying, from the one or more determined data streams, relevant events of the one or more events that are associated with the one or more corresponding signals; identifying, for each of the one or more determined data streams, a corresponding set of data points by deriving values for the data points from machine data of the relevant events for the determined data stream; inserting the identified sets of data points into the one or more corresponding signals; and continuously performing anomaly detection on the plurality of signals. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18)
-
-
19. A non-transitory computer-readable storage medium comprising instructions stored thereon, which when executed by one or more processors, cause the one or more processors to perform operations comprising:
-
receiving a plurality of data streams; storing, for each of the data streams, one or more events in a field searchable data store; determining one or more, for each of the data streams associated with one or more corresponding signals of a plurality of signals; identifying, from the one or more determined data streams, relevant events of the one or more events that are associated with the one or more corresponding signals; identifying, for each of the one or more determined data streams, a corresponding set of data points by deriving values for the data points from machine data of the relevant events for the determined data stream; inserting the identified sets of data points into the one or more corresponding signals; and continuously performing anomaly detection on the plurality of signals.
-
-
20. A system for performing anomaly detection, comprising:
-
at least one memory having instructions stored thereon; and at least one processor configured to execute the instructions to; receive a plurality of data streams; store, for each of the data streams, one or more events in a field searchable data store; determine one or more of the data streams associated with one or more corresponding signals of a plurality of signals; identify, from the one or more determined data streams, relevant events of the one or more events that are associated with the one or more corresponding signals; identify, for each of the one or more determined data streams, a corresponding set of data points by deriving values for the data points from machine data of the relevant events for the determined data stream; insert the identified sets of data points into the one or more corresponding signals; and continuously perform anomaly detection on the plurality of signals.
-
Specification