×

Apparatus for and method of implementing system log message ranking via system behavior analysis

  • US 8,452,761 B2
  • Filed: 10/24/2007
  • Issued: 05/28/2013
  • Est. Priority Date: 10/24/2007
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of analyzing system logs, said method comprising the steps of:

  • creating, on a computer in a preprocessing training phase, at least one system profile representing a type of system based on an expected frequency each message type appears in a training set of system logs derived from a plurality of computers;

    matching, in an operation phase, a new input system log from a computer to be analyzed to the most similar system profile created previously based on determination of a vector representing an observed frequency each message type in said new input system log appears therein;

    calculating, in said operation phase, a score for each system log message in said new input system log that is related to the probability that a corresponding message type would appear in said system profile, wherein said score represents a measure of deviation of said observed frequency from said expected frequency; and

    ranking, in said operation phase, said plurality of scored system log message types in order to identify atypical deviations of observed frequency from expected frequency for system log messages, whereby higher ranked message types have higher observed frequencies in said system log as compared to expected frequencies in said system profile generated during said preprocessing training phase.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×