METHOD, PROGRAM, AND SYSTEM FOR CLASSIFICATION OF SYSTEM LOG
First Claim
1. A computer-implemented method for inputting system logs and classifying formats, the method comprising the steps of:
- reading a message in one line of a system log;
preparing a root node of a tree structure in which each node holds a format;
calculating a similarity between a log of the root node and the message;
if the calculated similarity is equal to or greater than a threshold value, theni) generating a first format; and
ii) storing the first format in the root node;
adding the message to a child node of the root node, in accordance with a given condition;
searching for, after the first format is created, a second format that is similar to the first format in a format storage table;
if a similar format is found, then combining the first format and the similar format to produce a combined parent format, wherein the combined parent format holds a plurality of formats; and
storing the combined parent format in the format storage table to produce a classified format.
1 Assignment
0 Petitions
Accused Products
Abstract
Method and system for classifying system logs. A data processing system reads a message in one line of a system log; prepares a root node of a tree structure in which each node holds a format; calculates a similarity between a log of the root node and the message; generates and stores a first format in the root node if the calculated similarity is equal to or greater than a threshold value; adds the message to a child node of the root node, in accordance with a given condition; searches for, after the first format is created, a second format similar to the first format in a format storage table; combines the first format and the similar format to produce a combined parent format, where the combined parent format holds a plurality of formats; and stores the combined parent format in the format storage table to produce a classified format.
38 Citations
17 Claims
-
1. A computer-implemented method for inputting system logs and classifying formats, the method comprising the steps of:
-
reading a message in one line of a system log; preparing a root node of a tree structure in which each node holds a format; calculating a similarity between a log of the root node and the message; if the calculated similarity is equal to or greater than a threshold value, then i) generating a first format; and ii) storing the first format in the root node; adding the message to a child node of the root node, in accordance with a given condition; searching for, after the first format is created, a second format that is similar to the first format in a format storage table; if a similar format is found, then combining the first format and the similar format to produce a combined parent format, wherein the combined parent format holds a plurality of formats; and storing the combined parent format in the format storage table to produce a classified format. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A computer readable non-transitory article of manufacture tangibly embodying computer readable instructions, which, when executed, cause a computer to perform the steps of a method for inputting system logs and classifying formats, the method comprising the steps of:
-
reading a message in one line of a system log; preparing a root node of a tree structure, wherein each node of the tree structure holds a format; calculating a similarity between a log of the root node and the message; if the calculated similarity is equal to or greater than a given threshold, then i) generating a first format; and ii) storing the first format in the root node; adding the message to a child node of the root node, in accordance with a given condition; searching for, after the first format is created, a second format that is similar to the first format in a format storage table; if a similar format is found, then combining the first format and the similar format to produce a combined parent format, wherein the combined parent formula holds a combination of a plurality of formats; and storing the combined parent format in the format storage table to produce a classified format. - View Dependent Claims (8, 9, 10, 11, 12)
-
-
13. A data processing system for inputting system logs and classifying formats, the data processing system comprising a memory and a processing device communicatively coupled to the memory, wherein the processing device is configured to perform the steps of a method comprising:
-
reading a message in one line of a system log; preparing a root node of a tree structure, wherein each node of the tree structure holds a format; calculating a similarity between a log of the root node and the message, if the calculated similarity is equal to or greater than a given value, then i) creating a first format; and ii) storing the first format in the root node; replacing the root node with a most similar child node if the similarity is less than a given threshold and a number of child nodes held by the root node is equal to or greater than a given number; adding the message to the child node of the root node, if the similarity is lower than the given threshold and the number of child nodes held by the root node is less than the given number; searching for, after the new format is created, a second format that is similar to the first format in a format storage table; if a similar format is found, then combining the new format and the similar format to produce a combined parent format, wherein the combined parent formula holds a combination of a plurality of formats; and storing the combined parent format in the format storage table to produce a classified format. - View Dependent Claims (14, 15, 16, 17)
-
Specification