Automatic analysis of log entries through use of clustering
First Claim
Patent Images
1. A method in a computerized environment, said method comprising:
- obtaining log entries;
determining a matching function between a log entry and an at least one cluster based on a first portion of the log entries;
associating a second portion of the log entries with the at least one cluster, based on the matching function;
associating at least one timeframe with the at least one cluster;
labeling a portion of the at least one timeframe; and
providing an indication referring to the at least one cluster associated with the first portion of the log entries and the second portion of the log entries;
whereby the first portion of the log entries and the second portion of the log entries are transformed to an at least one indication of the at least one cluster.
1 Assignment
0 Petitions
Accused Products
Abstract
A set of log entries is automatically inspected to determine a bug. A training set is utilized to determine clustering of log identifications. Log entries are examined in real-time or retroactively and matched to clusters. Timeframe may also be matched to a cluster based on log entries associated with the timeframe. Error indications may be outputted to a user of the system in respect to a log entry or a timeframe.
-
Citations
12 Claims
-
1. A method in a computerized environment, said method comprising:
-
obtaining log entries; determining a matching function between a log entry and an at least one cluster based on a first portion of the log entries; associating a second portion of the log entries with the at least one cluster, based on the matching function; associating at least one timeframe with the at least one cluster; labeling a portion of the at least one timeframe; and providing an indication referring to the at least one cluster associated with the first portion of the log entries and the second portion of the log entries; whereby the first portion of the log entries and the second portion of the log entries are transformed to an at least one indication of the at least one cluster. - View Dependent Claims (2, 3, 4)
-
-
5. A computerized apparatus, the apparatus comprising a hardware processor which is arranged to:
-
obtain log entries; determine a matching function between a log entry and an at least one cluster based on a first portion of the log entries; associate a second portion of the log entries with the at least one cluster, based on the matching function; associate at least one timeframe with the at least one cluster; label a portion of the at least one timeframe; and provide an indication referring to the at least one cluster associated with the first portion of the log entries and the second portion of the log entries; whereby the first portion of the log entries and the second portion of the log entries are transformed to an at least one indication of the at least one cluster. - View Dependent Claims (6, 7, 8)
-
-
9. A computer program product, said computer program product comprising a non-transitory computer readable medium, in which computer instructions are stored, which instructions, when read by a computer, cause the computer to:
-
obtain log entries; determine a matching function between a log entry and an at least one cluster based on a first portion of the log entries; associate a second portion of the log entries with the at least one cluster, based on the matching function; associate at least one timeframe with the at least one cluster; label a portion of the at least one timeframe; and provide an indication referring to the at least one cluster associated with the first portion of the log entries and the second portion of the log entries; whereby the first portion of the log entries and the second portion of the log entries are transformed to an at least one indication of the at least one cluster. - View Dependent Claims (10, 11, 12)
-
Specification