SYSTEM EVENT LOGS
First Claim
Patent Images
1. An automated method, comprising:
- receiving event messages associated with one or more computer system event logs, each event message including event text;
determining a set of message clusters, each cluster in the set identifying a template text that represents one or more event messages across the one or more event logs; and
assigning each received event message to a message cluster of the set, according to a measure of similarity between the respective event text of the event message and the template text of the message cluster.
8 Assignments
0 Petitions
Accused Products
Abstract
An automated method of processing computer system event logs comprises receiving event messages associated with one or more system event logs, each event message including event text, determining a set of message clusters, each comprising a template text, representative of the event messages across the one or more event logs, and assigning each event message to a message cluster of the set, according to a measure of similarity between the respective event text of the event message and the template text of the message cluster.
128 Citations
18 Claims
-
1. An automated method, comprising:
-
receiving event messages associated with one or more computer system event logs, each event message including event text; determining a set of message clusters, each cluster in the set identifying a template text that represents one or more event messages across the one or more event logs; and assigning each received event message to a message cluster of the set, according to a measure of similarity between the respective event text of the event message and the template text of the message cluster. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16)
-
-
17. A computer implemented method of diagnosing a computer system problem, comprising:
-
receiving computer system behaviour information over one or more periods of time, the system behaviour information indicating a system problem; receiving event messages associated with one or more system event logs over the same period(s) of time, each event message including event text; determining a set of message clusters, each comprising a template text, representative of the event messages across the one or more event logs; assigning each event message to a message cluster of the set, according to a measure of similarity between the respective event text of the event message and the template text of the message cluster; determining which event clusters coincide with the system problem; and using the determination of which message clusters coincide with the system problem to diagnose a source of the system problem.
-
-
18. A program product containing instructions that, when executed on a computer, perform a method of diagnosing a computer system problem, comprising:
-
receiving computer system behaviour information over one or more periods of time, the system behaviour information indicating a system problem; receiving event messages associated with one or more system event logs over the same period(s) of time, each event message including event text; determining a set of message clusters, each comprising a template text, representative of the event messages across the one or more event logs; assigning each event message to a message cluster of the set, according to a measure of similarity between the respective event text of the event message and the template text of the message cluster; determining which event clusters coincide with the system problem; and using the determination of which message clusters coincide with the system problem to diagnose a source of the system problem.
-
Specification