Automatic correlation of dynamic system events within computing devices
First Claim
Patent Images
1. A method, comprising:
- providing, using a computing device, an event log electronic database, the database logically structured as a collection of tree-like graphs, with each node of the graph characterizing a computer network event;
receiving, using the computing device, information regarding a new computer network event to be logged;
automatically creating, using the computing device, a new event node within the event log database for the new computer network event;
automatically identifying, using the computing device, any existing event nodes within the event log database that each represent a respective past computer network event that may have caused the new computer network event, at least in part by matching a characteristic of the new event node to a characteristic of the existing event nodes;
automatically creating, using the computing device, a causal link within the event log database between the new event node and each of the identified existing event nodes; and
automatically storing, using the computing device, the new event node as an unattached root node in response to not identifying an existing event node representing a past computer network event that may have caused the new computer network event.
1 Assignment
0 Petitions
Accused Products
Abstract
Systems and methods are described herein for logging system events within an electronic machine using an event log structured as a collection of tree-like cause and effect graphs. An event to be logged may be received. A new event node may be created within the event log for the received event. One or more existing event nodes within the event log may be identified as having possibly caused the received event. One or more causal links may be created within the event log between the new event node and the one or more identified existing event nodes. The new event node may be stored as an unattached root node in response to not identifying an existing event node that may have caused the received event.
37 Citations
17 Claims
-
1. A method, comprising:
-
providing, using a computing device, an event log electronic database, the database logically structured as a collection of tree-like graphs, with each node of the graph characterizing a computer network event; receiving, using the computing device, information regarding a new computer network event to be logged; automatically creating, using the computing device, a new event node within the event log database for the new computer network event; automatically identifying, using the computing device, any existing event nodes within the event log database that each represent a respective past computer network event that may have caused the new computer network event, at least in part by matching a characteristic of the new event node to a characteristic of the existing event nodes; automatically creating, using the computing device, a causal link within the event log database between the new event node and each of the identified existing event nodes; and automatically storing, using the computing device, the new event node as an unattached root node in response to not identifying an existing event node representing a past computer network event that may have caused the new computer network event. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A system, comprising:
a computing device comprising an event logging module and an event log electronic database configured to; receive information regarding a new computer network event to be logged; automatically create an event node representing the new event within the event log database; automatically storing the event node within the event log database in a structure comprising a collection of tree-like graphs where wherein links within the graphs represent causal relationships between computer network events represented by linked nodes, and wherein one or more of the links is established where one or more existing event nodes within the event log database is identified as possibly having caused the new computer network event by matching a characteristic of the event node to a characteristic of the one or more existing event nodes; automatically storing the event node as an unattached root node in response to not identifying an existing event node representing a past computer network event that may have caused the new computer network event; and providing an output of one or more result tree-like graphs in response to a user search for an event represented by an event node linked within the one or more result tree-like graphs. - View Dependent Claims (8, 9, 10, 11, 12)
-
13. A computer program product, comprising:
a non-transitory computer-readable medium having computer-readable program code embodied therein that, when executed by one or more computing machines, perform a method comprising; providing an event log electronic database structured as a collection of tree-like graphs, with each node of the graph characterizing a computer network event; receiving information regarding a new event to be logged; automatically creating a new event node within the event log database for the new computer network event; automatically identifying any existing event nodes within the event log database that each represent a respective past computer network event that may have caused the new computer network event by matching a characteristic of the new event node to a characteristic of the existing event nodes; automatically creating a causal link within the event log database between the new event node and each of the identified existing event nodes; and automatically storing the new event node as an unattached root node in response to not identifying an existing event node representing a past computer network event that may have caused the new computer network event. - View Dependent Claims (14, 15, 16, 17)
Specification