Generating notification visualizations based on event pattern matching
First Claim
1. A method, comprising:
- creating a plurality of time stamped events from data received from one or more information technology systems;
analyzing the plurality of time stamped events to identify whether an event pattern that occurs in the plurality of time stamped events is the same or similar to one or more registered event patterns, the one or more registered event patterns indicative of performance aspects of the one or more information technology systems;
generating, based upon identification of one or more registered event patterns of the one or more registered event patterns that are the same or similar to the event pattern, a visualization representing one or more information technology systems of the one or more information technology systems that generated events associated with the event pattern;
generating within the visualization a control tool, wherein interaction with the control tool triggers;
retrieving events by searching the plurality of time stamped events for events surrounding the event pattern; and
replaying the retrieved events; and
generating within the visualization a representation of the replaying of the retrieved events surrounding the event pattern;
wherein the method is performed by one or more computing devices.
1 Assignment
0 Petitions
Accused Products
Abstract
Embodiments are directed towards the visualization of machine data received from computing clusters. Embodiments may enable improved analysis of computing cluster performance, error detection, troubleshooting, error prediction, or the like. Individual cluster nodes may generate machine data that includes information and data regarding the operation and status of the cluster node. The machine data is received from each cluster node for indexing by one or more indexing applications. The indexed machine data including the complete data set may be stored in one or more index stores. A visualization application enables a user to select one or more analysis lenses that may be used to generate visualizations of the machine data. The visualization application employs the analysis lens to produce visualizations of the computing cluster machine data.
48 Citations
20 Claims
-
1. A method, comprising:
-
creating a plurality of time stamped events from data received from one or more information technology systems; analyzing the plurality of time stamped events to identify whether an event pattern that occurs in the plurality of time stamped events is the same or similar to one or more registered event patterns, the one or more registered event patterns indicative of performance aspects of the one or more information technology systems; generating, based upon identification of one or more registered event patterns of the one or more registered event patterns that are the same or similar to the event pattern, a visualization representing one or more information technology systems of the one or more information technology systems that generated events associated with the event pattern; generating within the visualization a control tool, wherein interaction with the control tool triggers; retrieving events by searching the plurality of time stamped events for events surrounding the event pattern; and replaying the retrieved events; and generating within the visualization a representation of the replaying of the retrieved events surrounding the event pattern; wherein the method is performed by one or more computing devices. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. One or more non-transitory storage media storing instructions which, when executed by one or more computing devices, cause:
-
creating a plurality of time stamped events from data received from one or more information technology systems; analyzing the plurality of time stamped events to identify whether an event pattern that occurs in the plurality of time stamped events is the same or similar to one or more registered event patterns, the one or more registered event patterns indicative of performance aspects of the one or more information technology systems; generating, based upon identification of one or more registered event patterns of the one or more registered event patterns that are the same or similar to the event pattern, a visualization representing one or more information technology systems of the one or more information technology systems that generated events associated with the event pattern; generating within the visualization a control tool, wherein interaction with the control tool triggers; retrieving events by searching the plurality of time stamped events for events surrounding the event pattern; and replaying the retrieved events; and generating within the visualization a representation of the replaying of events surrounding the event pattern. - View Dependent Claims (15, 16, 20)
-
-
17. An apparatus, comprising:
-
an event creation device, implemented at least partially in hardware, that creates a plurality of time stamped events from data received from one or more information technology systems; an event analysis device, implemented at least partially in hardware, that analyzes the plurality of time stamped events to identify whether an event pattern that occurs in the plurality of time stamped events is the same or similar to one or more registered event patterns, the one or more registered event patterns indicative of performance aspects of the one or more information technology systems; a display formatter, implemented at least partially in hardware, that generates, based upon identification of one or more registered event patterns of the one or more registered event patterns that are the same or similar to the event pattern, a visualization representing one or more information technology systems of the one or more information technology systems that generated events associated with the event pattern; wherein the display formatter generates within the visualization a control tool, wherein interaction with the control tool triggers the display formatter to retrieve events by searching the plurality of time stamped events for events surrounding the event pattern, and replay the retrieved events; and wherein the display formatter generates within the visualization a representation of the replaying of events surrounding the event pattern. - View Dependent Claims (18, 19)
-
Specification