ANOMALY CLASSIFICATION, ANALYTICS AND RESOLUTION BASED ON ANNOTATED EVENT LOGS
First Claim
1. A machine-implemented method for keeping track in an anomalies versus parameters mapping space of previously identified and emerging anomalies of a data processing system, the method comprising:
- running a first section of the data processing system where the first section includes a section alarming subsystem and a section behaviors logging subsystem, the section alarming subsystem being configured to generate alarms for alarm-worthy events within the first section, the section behaviors logging subsystem being configured to generate a log of monitored behaviors within the first section;
logically co-associating recently logged behaviors of the generated log produced by the section behaviors logging subsystem with substantially cotemporaneous alarms generated by the section alarming subsystem and recording the logical associations;
building an annotated log comprised of the logically co-associated logged behaviors and substantially cotemporaneous alarms;
using the annotated log to keep track in a corresponding first anomalies versus parameters mapping space of previously identified as routine and emerging anomalies of the first section of the data processing system; and
automatically repeating said co-associating building and using steps while the first section of the data processing system continues to run.
1 Assignment
0 Petitions
Accused Products
Abstract
Operational event loggings and operational alarm productions within a running multiserver data processing system are automatically and repeatedly sampled and co-associated with one another so as to build annotated logs that can be used by post-process analytics for filling in mappings thereof into an anomalies versus parameters mapping space and for keeping track of unusual changes in the mappings or their rates where the unusual changes can be indicative of emerging new problems of significance within the system.
47 Citations
20 Claims
-
1. A machine-implemented method for keeping track in an anomalies versus parameters mapping space of previously identified and emerging anomalies of a data processing system, the method comprising:
-
running a first section of the data processing system where the first section includes a section alarming subsystem and a section behaviors logging subsystem, the section alarming subsystem being configured to generate alarms for alarm-worthy events within the first section, the section behaviors logging subsystem being configured to generate a log of monitored behaviors within the first section; logically co-associating recently logged behaviors of the generated log produced by the section behaviors logging subsystem with substantially cotemporaneous alarms generated by the section alarming subsystem and recording the logical associations; building an annotated log comprised of the logically co-associated logged behaviors and substantially cotemporaneous alarms; using the annotated log to keep track in a corresponding first anomalies versus parameters mapping space of previously identified as routine and emerging anomalies of the first section of the data processing system; and automatically repeating said co-associating building and using steps while the first section of the data processing system continues to run. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A data processing system configured to keep track in an anomalies versus parameters mapping space of previously identified and emerging anomalies of the data processing system, the data processing system comprising:
-
a plurality of sections including a first section having a section alarming subsystem and a section behaviors logging subsystem, the section alarming subsystem being configured to generate alarms for alarm-worthy events within the first section, the section behaviors logging subsystem being configured to generate a log of monitored behaviors within the first section; an annotated log storing database that is configured to indicate correlations for respective ones of the system sections between the recently logged behaviors and temporally corresponding generatings and non-generatings of alarms by the respective section alarming subsystem; an annotated log builder, coupled to the database and configured to automatically repeatedly for respective ones of the system sections, add to the stored and annotated log additional samples of correlations between recently logged behaviors and temporally corresponding generatings and non-generatings of alarms by the respective section alarming subsystem of the respective section; and a post-process analytics unit that is operatively coupled to respective ones of the annotated logs stored in the database for the respective sections and is configured to automatically repeatedly map into a first anomalies versus parameters mapping space, sample point indicators indicative of respective coordinates in the first anomalies versus parameters mapping space corresponding to plural parameters associated with each generating and non-generating of an alarm by the section alarming subsystem of a first of the sections in response to the recently logged behaviors of the generated log produced by the section behaviors logging subsystem of that first section; wherein the post-process analytics unit is configured to flag out abnormal changes over time in the automatically repeatedly mapped first anomalies versus parameters mapping space. - View Dependent Claims (12, 13, 14, 15, 16, 17)
-
-
18. A machine-implemented method for adaptively responding to previously identified and emerging anomalies of a data processing system, the method comprising:
-
running each of plural and intercoupled sections of the data processing system where each first section includes a respective section alarming subsystem and a respective section behaviors logging subsystem, the respective section alarming subsystem being configured to generate alarms for alarm-worthy events within the respective section, the respective section behaviors logging subsystem being configured to generate a log of monitored behaviors within the respective section; for each running section, co-associating recently logged behaviors of the respectively generated log produced by the respective section behaviors logging subsystem with substantially contemporaneous alarms generated by the section alarming subsystem and recording the co-associations; for each running section, building a respective annotated log that includes the recorded co-associations between the recently logged respective behaviors and the temporally corresponding generatings and non-generatings of alarms by the respective section alarming subsystem; for each running section, using the respective annotated log to keep track within a respective anomalies versus parameters mapping space of previously identified and emerging anomalies of the respective section of the data processing system; automatically repeating said co-associating, building and using steps of each respective section while the respective section of the data processing system continues to run; keeping track in each of the respective anomalies versus parameters mapping spaces of changes over time in the mapping locations and/or the rates of sample point additions to the mappings; and adaptively reallocating resources to sections based on the tracked changes within the respective anomalies versus parameters mapping spaces. - View Dependent Claims (19, 20)
-
Specification