×

EVENT MINI-GRAPHS IN DATA INTAKE STAGE OF MACHINE DATA PROCESSING PLATFORM

  • US 20170063912A1
  • Filed: 10/30/2015
  • Published: 03/02/2017
  • Est. Priority Date: 08/31/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method for processing data at data intake for detection of an anomaly in a distributed computer environment, the method comprising:

  • receiving event data representing an event on a computer network, the event data being indicative of a plurality of entities and an action involved in the event;

    identifying the entities and a relationship between the entities, based on the action in the event data;

    creating, for the event, a record of the relationship between the entities by using a data structure representing a relationship graph, the relationship graph including at least two nodes and an edge between the two nodes, each node representing one of the entities, the edge representing the relationship between the entities; and

    before sending the event data to a processing fabric for performing anomaly detection, updating the event data representing the event to include the record of the relationship,wherein the record of the relationship is specific to the event, andwherein the anomaly detection is performed based on applying a machine learning model to perform analytics on at least a portion of a composite relationship graph that is combined from relationship graphs for a plurality of events.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×