×

System for decomposing events from managed infrastructures using a topology proximity engine, graph topologies, and k-means clustering

  • US 9,529,890 B2
  • Filed: 04/28/2014
  • Issued: 12/27/2016
  • Est. Priority Date: 04/29/2013
  • Status: Active Grant
First Claim
Patent Images

1. An event clustering system, comprising:

  • an extraction engine in communication with a managed infrastructure, the extraction engine in operation receiving messages from the managed infrastructure and produces events that relate to the managed infrastructure and converts the events into words and subsets used to group the events into clusters that relate to failures or errors in the managed infrastructure, including managed infrastructure physical hardware, the managed infrastructure supporting the flow and processing of information;

    a sigalizer engine that includes one or more of an Non-negative Matrix Factorization NMF engine, a k-means clustering engine and a topology proximity engine, the sigalizer engine determining one or more common steps from events and produces clusters relating to events, the sigalizer engine determining one or more common characteristics of events and producing clusters of events relating to the failure or errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information;

    the topology proximity engine using a source address for each event and a graph topology of the managed infrastructure which represents node to node connectivity of the topology proximity engine and to assign a graph coordinate to the event with an optional subset of attributes being extracted for each event and turned into a vector, the topology engine inputs a list of devices and a list a connections between components or nodes in the managed infrastructure;

    the k-means clustering engine using the graph coordinates and optionally a subset of attributes assigned to each event to generate cluster to bring together events whose characteristics are similar;

    the NMF engine factoring the matrix M into A and B, where A is inspected and substantially significant clusters are extracted, and B is used to assign a start and end time to each cluster, wherein an output of clusters is produced; and

    wherein in response to production of the clusters one or more physical changes in a managed infrastructure hardware is made.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×