Systems and methods for monitoring and acting on logged system messages
First Claim
1. A method with regard to a computer operations center having a plurality of computing systems, the plurality of computing systems issuing system messages that are stored in a message logging database, the method comprising:
- monitoring the system messages stored in the message logging database for a predetermined pattern in the system messages;
detecting a particular pattern in the system messages;
querying the message logging database for relevant messages;
computing a statistic based on the relevant messages;
obtaining, from the detected pattern, a first threshold and a first action to be taken if the first threshold is surpassed by the statistic, wherein the detected pattern further includes a second threshold, and a third threshold; and
acting in response to the detected pattern by taking a predetermined action corresponding to the detected pattern that anticipates an occurrence of an unwanted system event, the predetermined action intended to prevent or at least minimize the unwanted system event, wherein the predetermined action corresponding to the detected pattern includes the first action to be taken if the first threshold is satisfied, a second corresponding action to be taken if the second threshold is satisfied, and a third corresponding action to be taken if the third threshold is satisfied, and wherein the first corresponding action, the second corresponding action, and the third corresponding action are each different from each other.
0 Assignments
0 Petitions
Accused Products
Abstract
A computer operations center that has a number of computing systems, where each computing system issues system messages regarding such computing system. Each issued system message from each computing system is stored in a message logging database. The system messages stored in the message logging database are monitored for predetermined patterns, and upon detecting a particular pattern in the system messages, a predetermined action corresponding to the detected pattern is taken. The detected pattern anticipates an occurrence of an unwanted system event, and the corresponding action is intended to prevent or at least minimize the unwanted system event.
12 Citations
17 Claims
-
1. A method with regard to a computer operations center having a plurality of computing systems, the plurality of computing systems issuing system messages that are stored in a message logging database, the method comprising:
-
monitoring the system messages stored in the message logging database for a predetermined pattern in the system messages; detecting a particular pattern in the system messages; querying the message logging database for relevant messages; computing a statistic based on the relevant messages; obtaining, from the detected pattern, a first threshold and a first action to be taken if the first threshold is surpassed by the statistic, wherein the detected pattern further includes a second threshold, and a third threshold; and acting in response to the detected pattern by taking a predetermined action corresponding to the detected pattern that anticipates an occurrence of an unwanted system event, the predetermined action intended to prevent or at least minimize the unwanted system event, wherein the predetermined action corresponding to the detected pattern includes the first action to be taken if the first threshold is satisfied, a second corresponding action to be taken if the second threshold is satisfied, and a third corresponding action to be taken if the third threshold is satisfied, and wherein the first corresponding action, the second corresponding action, and the third corresponding action are each different from each other. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A non-transitory computer-readable medium having stored thereon computer-executable instructions implementing a method with regard to a computer operations center having a plurality of computing systems, the plurality of computing systems issuing system messages that are stored in a message logging database, the instructions causing a computer processor to:
-
monitor the system messages stored in the message logging database for a predetermined pattern in the system messages; detect a particular pattern in the system messages; query the message logging database for relevant messages; compute a statistic based on the relevant messages; obtain, from the detected pattern, a first threshold and a first action to be taken if the first threshold is surpassed by the statistic, wherein the detected pattern further includes a second threshold, and a third threshold; and act in response to the detected pattern by taking a predetermined action corresponding to the detected pattern that anticipates an occurrence of an unwanted system event, the predetermined action intended to prevent or at least minimize the unwanted system event, wherein the predetermined action corresponding to the detected pattern includes the first action to be taken if the first threshold is satisfied, a second corresponding action to be taken if the second threshold is satisfied, and a third corresponding action to be taken if the third threshold is satisfied, and wherein the first corresponding action, the second corresponding action, and the third corresponding action are each different from each other. - View Dependent Claims (8, 9, 10, 11, 12)
-
-
13. A system with regard to a computer operations center having a plurality of computing systems, the plurality of computing systems issuing system messages that are stored in a message logging database, the system comprising:
-
a sub-system that monitors the system messages stored in the message logging database for a predetermined pattern in the system messages; a sub-system that detects a particular pattern in the system messages; a sub-system that queries the message logging database for relevant messages; a sub-system that computes a statistic based on the relevant messages; a sub-system that obtains, from the detected pattern, a first threshold and a first action to be taken if the first threshold is surpassed by the statistic, wherein the detected pattern further includes a second threshold, and a third threshold; and a sub-system that acts in response to the detected pattern by taking a predetermined action corresponding to the detected pattern that anticipates an occurrence of an unwanted system event, the predetermined action intended to prevent or at least minimize the unwanted system event, wherein the predetermined action corresponding to the detected pattern includes the first action to be taken if the first threshold is satisfied, a second corresponding action to be taken if the second threshold is satisfied, and a third corresponding action to be taken if the third threshold is satisfied, and wherein the first corresponding action, the second corresponding action, and the third corresponding action are each different from each other. - View Dependent Claims (14, 15, 16, 17)
-
Specification