×

Scalable log analytics

  • US 9,244,755 B2
  • Filed: 05/20/2013
  • Issued: 01/26/2016
  • Est. Priority Date: 05/20/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method for providing real-time analysis of log messages for a computer infrastructure, the method comprising:

  • receiving a plurality of log messages including a first log message;

    generating a sketch associated with the first log message, wherein the the sketch includes a tuple of fingerprint values generated by processing a subset of words of the first log message through a fingerprint function;

    determining a message type for the first log message based on a comparison of the generated sketch to a plurality of sketches stored in an index, wherein log messages of a same message type have similar sketches;

    determining a first log event associated with one or more of the plurality of log messages occurring with a time interval, wherein the first log event comprises a first composition of message types corresponding to the one or more of the plurality of log messages associated with the first log event;

    determining an event type for the first log event based on a comparison of the first composition of message types to a plurality of compositions of message types stored in the index; and

    determining an anomalous log event within the plurality of log messages based on the event type for the first log event.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×