×

Anomaly detection

  • US 10,592,093 B2
  • Filed: 09/18/2015
  • Issued: 03/17/2020
  • Est. Priority Date: 10/09/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • executing a search query over a period of time to produce values for a key performance indicator (KPI), the KPI associated with the search query that derives a value indicative of the performance of a service at a point in time or during a period of time, the value derived from machine data pertaining to one or more entities that provide the service;

    causing for display a graphical user interface (GUI) comprising a first user-selectable interface element that enables a user to indicate a sensitivity setting and a second user-selectable interface element that enables the user to indicate a training window comprising an interval of time;

    receiving, via the first and second user-selectable interface elements of the GUI, user input indicating the sensitivity setting and the training window;

    identifying one or more of the values as anomalies based on the sensitivity setting and the training window indicated by the user input, the sensitivity setting establishing a threshold by which the one or more values are considered as the anomalies with respect to a deviation from historical values for the KPI, the historical values corresponding to the training window, wherein identifying one or more of the values as anomalies comprises comparing one of the values against a predicted value, the comparing including determining an error value and determining the position of the error value in a range of error values; and

    causing for display, via an update to a graph in the GUI, information related to the values identified as anomalies to visually represent anomaly points in the graph, wherein the graph in the GUI is updated in real-time to visually represent new anomaly points corresponding to updated values identified based on received adjustments of the first and second user-selectable interface elements;

    wherein the method is performed by a computer system comprising one or more processors.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×