×

System for decomposing clustering events from managed infrastructures coupled to a data extraction device

  • US 10,007,716 B2
  • Filed: 07/08/2014
  • Issued: 06/26/2018
  • Est. Priority Date: 04/28/2014
  • Status: Active Grant
First Claim
Patent Images

1. An event clustering system configured to provide extracted information, comprising:

  • an extraction engine with a processor in communication with an infrastructure, the extraction engine in operation receiving data from the infrastructure and produces clustering events and populates a database with a dictionary of event or graph entropy;

    an alert engine that receives the events and creates alerts mapped into a matrix, M;

    a signalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine, the signalizer engine determining one or more common steps from events and produces clusters relating to the alerts and or events, the signalizer engine determining one or more common steps from events and produces clusters relating to events, the signalizer engine determining one or more common characteristics of events and producing clusters of events relating to the failure or errors in the infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in physical hardware of the infrastructure directed to supporting the flow and processing of information, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware of the infrastructure directed to supporting the flow and processing of information;

    one or more interactive displays that provide a collaborative interface coupled to the extraction and the signalizer engine with a collaborative interface (UI) for decomposing events from the infrastructure;

    a data extraction device that is configured to collect information from one or more clusters;

    a topology engine using a source address for each event and a graph topology of the infrastructure which represents node to node connectivity of the topology engine and to assign a graph coordinate to the event with an optional subset of attributes being extracted for each event and turned into a vector;

    the signalizer engine with at one or more of the NMF engine and the k-means clustering engine using graph coordinates and optionally a subset of attributes assigned to each event to generate cluster to bring together events whose characteristics are similar;

    the signalizer engine with at one or more of the NMF engine and the k-means clustering engine factoring the matrix M into A and B, where A is inspected and substantially significant clusters are extracted, and B is used to assign a start and end time to each cluster, wherein an output of clusters is produced; and

    wherein in response to production of the clusters one or more physical changes in a managed infrastructure hardware is made.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×