Log Analysis Based on User Activity Volume
First Claim
Patent Images
1. A log analysis system comprising:
- an activity engine to monitor user activity of a computer system;
a baseline engine to generate an expected baseline of a log based on historical log activity; and
an abnormality engine to;
compare the log to the expected baseline to identify an abnormality;
compare the abnormality to a user activity volume based on a correlation between the user activity volume and the log activity; and
classify the log based on the abnormality, the correlation, and the user activity volume.
8 Assignments
0 Petitions
Accused Products
Abstract
In one example implementation, a log analysis system can comprise an activity engine to monitor user activity of a computer system, a baseline engine to generate an expected baseline of a log, and an abnormality engine to compare the log to the expected baseline to identify an abnormality, compare the abnormality to a user activity volume based on a correlation between the user activity volume and the log activity, and classify the log.
42 Citations
15 Claims
-
1. A log analysis system comprising:
-
an activity engine to monitor user activity of a computer system; a baseline engine to generate an expected baseline of a log based on historical log activity; and an abnormality engine to; compare the log to the expected baseline to identify an abnormality; compare the abnormality to a user activity volume based on a correlation between the user activity volume and the log activity; and classify the log based on the abnormality, the correlation, and the user activity volume. - View Dependent Claims (2, 3, 4, 5)
-
-
6. A computer readable storage medium comprising a set of instructions executable by a processor resource to:
-
generate a first graph, the first graph to represent an expected baseline of log activity of a computer system based on a log template of the log activity and a seasonal effect of the log activity; generate a second graph, the second graph to represent a user activity volume of the computer system; compare the first graph to the second graph to identify a correlation between the expected baseline and the user activity volume; and score the log activity based on the expected baseline, the correlation, and the user activity volume. - View Dependent Claims (7, 8, 9, 10)
-
-
11. A method for analyzing a log comprising:
-
identifying a log template based on a set of entries of the log; generating a baseline graph associated with expected log activity based on the log template; generating a user activity graph associated with a volume of user activity; comparing the user activity graph to the baseline graph to identify a correlation between the log template and the volume of user activity; comparing a potential abnormality of the log to the volume of user activity associated with the log, the potential abnormality being a difference between the log and the baseline; and visually indicating a log status based on the correlation between the potential abnormality and the volume of user activity. - View Dependent Claims (12, 13, 14, 15)
-
Specification