Recommending and prioritizing computer log anomalies
First Claim
1. A method, comprising:
- processing computer log entries to determine a plurality of baseline rank values associated with a ranking dimension, wherein a ranking dimension identifies a specific log data component category, and wherein determining the plurality of baseline rank values comprises determining a count number of log entries for each unique value of the ranking dimension in the computer log entries and sorting the count numbers to rank each unique value of the ranking dimension by its count number;
using a processor to compute an overall baseline rank indicator using the determined baseline rank values;
determining for each log data component value combination included in a group of log data component value combinations, a comparison rank value associated with the ranking dimension;
comparing each of the comparison rank values with the overall baseline rank indicator; and
based at least in part on the comparisons, identifying one or more log data component value combinations included in the group of log data component value combinations as more anomalous than other log data component value combinations included in the group of log data component value combinations.
2 Assignments
0 Petitions
Accused Products
Abstract
Computer log entries are processed to determine a plurality of baseline rank values associated with a ranking dimension. An overall baseline rank indicator is computed using the determined baseline rank values. For each log data component value combination included in a group of log data component value combinations, a comparison rank value associated with the ranking dimension is determined. Each of the comparison rank values is compared with the overall baseline rank indicator. Based at least in part on the comparisons, one or more log data component value combinations included in the group of log data component value combinations are identified as more anomalous than other log data component value combinations included in the group of log data component value combinations.
-
Citations
20 Claims
-
1. A method, comprising:
-
processing computer log entries to determine a plurality of baseline rank values associated with a ranking dimension, wherein a ranking dimension identifies a specific log data component category, and wherein determining the plurality of baseline rank values comprises determining a count number of log entries for each unique value of the ranking dimension in the computer log entries and sorting the count numbers to rank each unique value of the ranking dimension by its count number; using a processor to compute an overall baseline rank indicator using the determined baseline rank values; determining for each log data component value combination included in a group of log data component value combinations, a comparison rank value associated with the ranking dimension; comparing each of the comparison rank values with the overall baseline rank indicator; and based at least in part on the comparisons, identifying one or more log data component value combinations included in the group of log data component value combinations as more anomalous than other log data component value combinations included in the group of log data component value combinations. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18)
-
-
19. A system, comprising:
-
a storage configured to store a repository of computer log entries; and a processor configured to; process the computer log entries to determine a plurality of baseline rank values associated with a ranking dimension, wherein a ranking dimension identifies a specific log data component category, and wherein determining the plurality of baseline rank values comprises determining a count number of log entries for each unique value of the ranking dimension in the computer log entries and sorting the count numbers to rank each unique value of the ranking dimension by its count number; compute an overall baseline rank indicator using the determined baseline rank values; determine for each log data component value combination included in a group of log data component value combinations, a comparison rank value associated with the ranking dimension; compare each of the comparison rank values with the overall baseline rank indicator; and based at least in part on the comparisons, identify one or more log data component value combinations included in the group of log data component value combinations as more anomalous than other log data component value combinations included in the group of log data component value combinations.
-
-
20. A computer program product, the computer program product being embodied in a non-transitory computer-readable storage medium and comprising computer instructions for:
-
processing computer log entries to determine a plurality of baseline rank values associated with a ranking dimension, wherein a ranking dimension identifies a specific log data component category, and wherein determining the plurality of baseline rank values comprises determining a count number of log entries for each unique value of the ranking dimension in the computer log entries and sorting the count numbers to rank each unique value of the ranking dimension by its count number; computing an overall baseline rank indicator using the determined baseline rank values; determining for each log data component value combination included in a group of log data component value combinations, a comparison rank value associated with the ranking dimension; comparing each of the comparison rank values with the overall baseline rank indicator; and based at least in part on the comparisons, identifying one or more log data component value combinations included in the group of log data component value combinations as more anomalous than other log data component value combinations included in the group of log data component value combinations.
-
Specification