System for decomposing events from managed infrastructures with prediction of a networks topology
First Claim
Patent Images
1. An event clustering system, comprising:
- a managed infrastructure with hardware components;
an extraction engine in communication with the managed infrastructure, the extraction engine extracting text components from event messages and convert them into words and subtexts;
a signalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine, the signalizer engine converting at least a portion of the event messages into a sequence of attributes that have text or numerical values indicative of a state of a hardware component and determining if collections of event messages share a common attribute, possessing either identically equal textual values, or values that are similar up to a pre-defined threshold with production of an output of clusters, and in response to production of the clusters one or more physical changes in a managed infrastructure hardware is made.
5 Assignments
0 Petitions
Accused Products
Abstract
An event clustering system is provided that in response to a time series infers a network topology. Matrices W and H are estimated as a local minimum. For each pair of nodes: (i) a computation of the convolution is made; a number of peaks within the convolution is a function of a delay; and a comparison is made to an average behavior of a pair of nodes that emits the same number of alerts. Alerts are only spread to adjacent nodes, alerts are caused by dysfunctional nodes that do not emit alerts, and a true topology coincides with the end of the recording.
84 Citations
1 Claim
-
1. An event clustering system, comprising:
-
a managed infrastructure with hardware components; an extraction engine in communication with the managed infrastructure, the extraction engine extracting text components from event messages and convert them into words and subtexts; a signalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine, the signalizer engine converting at least a portion of the event messages into a sequence of attributes that have text or numerical values indicative of a state of a hardware component and determining if collections of event messages share a common attribute, possessing either identically equal textual values, or values that are similar up to a pre-defined threshold with production of an output of clusters, and in response to production of the clusters one or more physical changes in a managed infrastructure hardware is made.
-
Specification