System for decomposing events from managed infrastructures using a topology proximity engine, graph topologies, and k-means clustering
First Claim
Patent Images
1. An event clustering system, comprising:
- an extraction engine in communication with a managed infrastructure, the extraction engine in operation receiving messages from the managed infrastructure and produces events that relate to the managed infrastructure and converts the events into words and subsets used to group the events into clusters that relate to failures or errors in the managed infrastructure, including managed infrastructure physical hardware, the managed infrastructure supporting the flow and processing of information;
a sigalizer engine that includes one or more of an Non-negative Matrix Factorization NMF engine, a k-means clustering engine and a topology proximity engine, the sigalizer engine determining one or more common steps from events and produces clusters relating to events, the sigalizer engine determining one or more common characteristics of events and producing clusters of events relating to the failure or errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information;
the topology proximity engine using a source address for each event and a graph topology of the managed infrastructure which represents node to node connectivity of the topology proximity engine and to assign a graph coordinate to the event with an optional subset of attributes being extracted for each event and turned into a vector, the topology engine inputs a list of devices and a list a connections between components or nodes in the managed infrastructure;
the k-means clustering engine using the graph coordinates and optionally a subset of attributes assigned to each event to generate cluster to bring together events whose characteristics are similar;
the NMF engine factoring the matrix M into A and B, where A is inspected and substantially significant clusters are extracted, and B is used to assign a start and end time to each cluster, wherein an output of clusters is produced; and
wherein in response to production of the clusters one or more physical changes in a managed infrastructure hardware is made.
5 Assignments
0 Petitions
Accused Products
Abstract
An event clustering system includes an extraction engine in communication with an infrastructure. The extraction engine receives data from the infrastructure and produces events. An alert engine receives the events and creates alerts mapped into a matrix, M. A sigalizer engine includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine. The sigalizer engine determines one or more common steps from events and produces clusters relating to the alerts and or events.
36 Citations
48 Claims
-
1. An event clustering system, comprising:
-
an extraction engine in communication with a managed infrastructure, the extraction engine in operation receiving messages from the managed infrastructure and produces events that relate to the managed infrastructure and converts the events into words and subsets used to group the events into clusters that relate to failures or errors in the managed infrastructure, including managed infrastructure physical hardware, the managed infrastructure supporting the flow and processing of information; a sigalizer engine that includes one or more of an Non-negative Matrix Factorization NMF engine, a k-means clustering engine and a topology proximity engine, the sigalizer engine determining one or more common steps from events and produces clusters relating to events, the sigalizer engine determining one or more common characteristics of events and producing clusters of events relating to the failure or errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information; the topology proximity engine using a source address for each event and a graph topology of the managed infrastructure which represents node to node connectivity of the topology proximity engine and to assign a graph coordinate to the event with an optional subset of attributes being extracted for each event and turned into a vector, the topology engine inputs a list of devices and a list a connections between components or nodes in the managed infrastructure; the k-means clustering engine using the graph coordinates and optionally a subset of attributes assigned to each event to generate cluster to bring together events whose characteristics are similar; the NMF engine factoring the matrix M into A and B, where A is inspected and substantially significant clusters are extracted, and B is used to assign a start and end time to each cluster, wherein an output of clusters is produced; and wherein in response to production of the clusters one or more physical changes in a managed infrastructure hardware is made. - View Dependent Claims (2, 3, 4, 5, 6, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48)
-
-
7. The system 1, wherein the extraction engine creates from events subsets of events that relate to failures or errors in the infrastructure.
Specification