METHOD AND SYSTEM FOR CLUSTERING AND PRIORITIZING EVENT MESSAGES
First Claim
Patent Images
1. An event-message clustering system comprising:
- one or more processors;
one or more memories; and
computer instructions, stored in one or more of the one or more memories that, when executed by one or more of the one or more processors, control the event-message clustering system toreceive event messages, andprocess each of the received event messages bydetermining a cluster to which to assign the event message,extracting data values from the event message,computing a significance value for the event message,generating an event record corresponding to the event message that includes the extracted data values, andstoring the event record within, or associated with, the selected cluster in a physical data-storage device.
1 Assignment
0 Petitions
Accused Products
Abstract
The current document is directed to methods and systems for processing, classifying, and efficiently storing large volumes of event messages generated in modern computing systems. In a disclosed implementation, received event messages are assigned to clusters based on metrics computed for the event messages. In addition, a significance value is determined for each received event message. When the significance value exceeds a threshold value, one or more actions are taken, including marking an event record corresponding to the event message, storing an event record corresponding to the event message in a significant-event log, and generating a notice or alarm.
31 Citations
23 Claims
-
1. An event-message clustering system comprising:
-
one or more processors; one or more memories; and computer instructions, stored in one or more of the one or more memories that, when executed by one or more of the one or more processors, control the event-message clustering system to receive event messages, and process each of the received event messages by determining a cluster to which to assign the event message, extracting data values from the event message, computing a significance value for the event message, generating an event record corresponding to the event message that includes the extracted data values, and storing the event record within, or associated with, the selected cluster in a physical data-storage device. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A method that processes event messages, carried out within an event-message clustering system, the event-message clustering system having one or more processors, one or more memories, and computer instructions, stored in one or more of the one or more memories that, when executed by one or more of the one or more processors, control the event-message clustering system to receive event messages and process each of the received event messages, the method comprising:
-
receiving event messages, and processing each of the received event messages by determining a cluster to which to assign the event message, extracting data values from the event message, computing a significance value for the event message, generating an event record corresponding to the event message that includes the extracted data values, and storing the event record within, or associated with, the selected cluster in a physical data-storage device. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20, 21, 22)
-
-
23. Computer instructions stored in a physical device that, when executed on one or more processors of an event-message clustering system that additionally includes one or more memories, control the event-message clustering system to:
-
receive event messages; and process each of the received event messages by determining a cluster to which to assign the event message, extracting data values from the event message, computing a significance value for the event message, generating an event record corresponding to the event message that includes the extracted data values, and storing the event record within, or associated with, the selected cluster in a physical data-storage device.
-
Specification