×

Identifying correlations between log data and network packet data

  • US 10,268,652 B2
  • Filed: 10/31/2016
  • Issued: 04/23/2019
  • Est. Priority Date: 07/31/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method, comprising:

  • obtaining log data generated by at least one component in an information technology (IT) environment, and network packet data generated by at least one component in the IT environment;

    generating, based on the log data and the network packet data, event data including log data events and network packet data events;

    receiving, by a query processor, a query that includes search criteria including;

    an attribute of at least one log data event and at least one network packet data event; and

    a plurality of qualitative search terms to be applied to the attribute using an aggregate compatibility index for the event data,wherein the plurality of qualitative search terms each comprises an adjective describing the attribute, andwherein the aggregate compatibility index is based on an ordering of associated qualitative search terms in the query; and

    executing the query to identify query results that satisfy the search criteria by;

    for each event in at least a subset of the log data events and the network packet events;

    for each qualitative search term of the plurality of qualitative search terms;

    determining a compatibility index value for an attribute value in the event with the qualitative search term, andmultiplying the compatibility index value by a corresponding weight to obtain an intermediate value for the qualitative search term, the corresponding weight matching the order of the qualitative search term in the query, the order being with respect to the query;

    generating the aggregate compatibility index for the event by averaging the intermediate value across the plurality of qualitative search terms, andincluding the event in the query results when the aggregate compatibility index satisfies a threshold,wherein the query results include at least one log data event of the event data and at least one network packet data event of the event data that have a relationship, andwherein the query results reflect performance activity associated with the IT environment.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×