Event log analysis
First Claim
Patent Images
1. A method for analyzing an event log, comprising:
- accessing an event log element from an electronic event log file;
calculating a similarity index between the event log element and a text element;
calculating a threshold of similarity as a linear function of a length of the event log element;
calculating an adjusted threshold by dividing the threshold of similarity by a square root of a product of a length of the text element times the length of the event log element;
comparing the similarity index to the adjusted threshold; and
if the similarity index is greater than the adjusted threshold, adding the event log element to an electronic file of cluster assignments, the cluster assignments representing a grouping of the event log element into a cluster with the text element.
8 Assignments
0 Petitions
Accused Products
Abstract
Method and systems for analyzing event log elements are provided. In one example, a method includes receiving an event log element in a computer. A similarity index is calculated between the event log element and a text element. A threshold of similarity is calculated. The similarity index is compared to the threshold. If the similarity index is greater than the threshold, the event log element is grouped into a cluster with the text element to create a file of cluster assignments.
-
Citations
20 Claims
-
1. A method for analyzing an event log, comprising:
-
accessing an event log element from an electronic event log file; calculating a similarity index between the event log element and a text element; calculating a threshold of similarity as a linear function of a length of the event log element; calculating an adjusted threshold by dividing the threshold of similarity by a square root of a product of a length of the text element times the length of the event log element; comparing the similarity index to the adjusted threshold; and if the similarity index is greater than the adjusted threshold, adding the event log element to an electronic file of cluster assignments, the cluster assignments representing a grouping of the event log element into a cluster with the text element. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A system for analyzing event log elements, comprising:
-
a processor; and a storage, wherein the storage comprises code configured to direct the processor to; access electronic event logs from a network of systems; store the electronic event logs in the storage; calculate a similarity index between an event log element and a text element; calculate a threshold of similarity as a linear function of a length of the event log element; calculate an adjusted threshold by dividing the threshold of similarity by a square root of a product of a length of the text element times the length of the event log element; compare the similarity index to the adjusted threshold and if the similarity index is greater than the adjusted threshold, writing an entry to a cluster assignment file to indicate that the event log element is part of a cluster with the text element; and diagnose problems in a network by automatically identifying patterns in the cluster assignment file. - View Dependent Claims (10, 11, 12)
-
-
13. A non-transitory, computer-readable medium, comprising instructions configured to direct a processor to:
-
access an event log element from an electronic event log file; calculate a similarity index between the event log element and a text element; calculate a threshold of similarity as a linear function of a length of the event log element; calculate an adjusted threshold of similarity by dividing the threshold of similarity by a square root of a product of a length of the text element times the length of the event log element; and write an entry into an electronic cluster assignment file indicating that the event log element is part of a cluster represented by the text element if the similarity index is greater than the adjusted threshold of similarity. - View Dependent Claims (14, 15, 16, 17, 18, 19, 20)
-
Specification