REMEDIATING EVENTS USING BEHAVIORS
0 Assignments
0 Petitions
Accused Products
Abstract
Remediating events of components using behaviors via an administrator system and an administrator client. The administrator system receives an event from a component of an information technology (IT) environment. A behavior is determined at least partly from the event. The behavior is determined to be an anomalous behavior at least partly from a group of previously received events. A coefficient is calculated, via a calculation, for the anomalous behavior at least partly from a weight. The administrator system sends a description of the anomalous behavior and a group of options to the administrator client. The description is at least partly based on the calculation. The administrator system receives a severity indication from the administrator client. The weight, the calculation, and the description are updated based on the severity indication.
13 Citations
50 Claims
-
1-25. -25. (canceled)
-
26. A computer program product stored on a computer readable storage device having computer readable program code embodied thereon that is executable by a data processing system for remediating events using behaviors via an administrator system, the computer program product comprising:
-
computer readable program code for receiving an event from a component of an information technology (IT) environment; computer readable program code for determining a behavior at least partly from the event; computer readable program code for determining that the behavior is an anomalous behavior at least partly from a group of previously received events; computer readable program code for calculating a coefficient via a calculation for the anomalous behavior at least partly from a weight; computer readable program code for sending a description of the anomalous behavior and a group of options to an administrator client, the description is at least partly based on the calculation; computer readable program code for receiving a severity indication from the administrator client; and computer readable program code for updating the weight, the calculation, and the description based on the severity indication. - View Dependent Claims (27, 28, 29, 30, 31, 32, 33, 34, 35)
-
-
36. A computer program product stored on a computer readable storage device having computer readable program code embodied thereon that is executable by a data processing system for remediating events using behaviors via an administrator client, the computer program product comprising:
-
computer readable program code for receiving a first description of an anomalous behavior and a group of options from an administrator system, the description is at least partly based on a calculation, wherein; an event is received from a component of an information technology (IT) environment; a behavior is determined at least partly from the event; the behavior is determined to be an anomalous behavior at least partly from a group of previously received events; a coefficient is calculated via the calculation for the anomalous behavior at least partly from a weight; and computer readable program code for sending a severity indication to the administrator system, wherein; the weight, the calculation, and the description are updated based on the severity indication. - View Dependent Claims (37, 38, 39, 40, 41, 42, 43)
-
-
44. A computer program product stored on a computer readable storage device having computer readable program code embodied thereon that is executable by a data processing system for remediating events using behaviors via component of an information technology environment, the computer program product comprising:
-
computer readable program code for sending an event to an administrator system of the information technology (IT) environment, wherein; a behavior is determined at least partly from the event; the behavior is determined to be an anomalous behavior at least partly from a group of previously received events; a coefficient is calculated via a calculation for the anomalous behavior at least partly from a weight; a description of the anomalous behavior and a group of options is sent to an administrator client, the description is at least partly based on the calculation; a severity indication is received from the administrator client; the weight, the calculation, and the description are updated based on the severity indication; and computer readable program code for receiving a command associated with a script to remediate the event. - View Dependent Claims (45, 46, 47, 48, 49, 50)
-
Specification