System for decomposing events from managed infrastructures
First Claim
1. A system for clustering events, comprising:
- a first engine configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information;
a second engine that determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information;
creating one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure;
wherein in response to production of the clusters making one or more physical changes in the managed infrastructure hardware; and
wherein the second engine is a signalizer engine.
5 Assignments
0 Petitions
Accused Products
Abstract
A system is provided for clustering events. A first engine is configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information. A second engine determines common characteristics of events and produces clusters of events relating to a failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. One or more situations are created that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure. In response to the production of the clusters one or more physical changes in the managed infrastructure hardware.
37 Citations
16 Claims
-
1. A system for clustering events, comprising:
-
a first engine configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information; a second engine that determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information; creating one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure; wherein in response to production of the clusters making one or more physical changes in the managed infrastructure hardware; and wherein the second engine is a signalizer engine. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. A system for clustering events, comprising:
-
a first engine configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information; a second engine that determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information; creating one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure wherein in response to production of the clusters making one or more physical changes in the managed infrastructure hardware; and a compare and merge engine that receives outputs from the second engine, the compare and merge engine communicating with one or more user interfaces in a situation room.
-
-
16. A system for clustering events, comprising:
-
a first engine configured to receive message data from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information; a second engine that determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information; creating one or more situations that is a collection of one or more events or alerts representative of the actionable problem in the managed infrastructure; wherein the first engine is an extraction engine, the first engine in operation receives messages from the managed infrastructure and produces events that relate to the managed infrastructure; and wherein the events are converted into words and subsets used to group the events into clusters that relate to failures or errors in the managed infrastructure.
-
Specification