×

Event correlation

  • US 9,697,100 B2
  • Filed: 03/10/2014
  • Issued: 07/04/2017
  • Est. Priority Date: 03/10/2014
  • Status: Active Grant
First Claim
Patent Images

1. An event correlation system comprising:

  • at least one processor;

    a feature identification module, executed by the at least one processor, to identify a feature set for each log file of a plurality of log files;

    a feature extraction module, executed by the at least one processor, to extract the feature set for each event of a plurality of events in each log file of the plurality of log files;

    a trace event pairs linkage strength determination module, executed by the at least one processor, to determine a plurality of trace event pairs linkage strength values for at least one event from a first log file of the plurality of log files and a plurality of events from a second log file of the plurality of log files, whereinthe plurality of trace event pairs linkage strength values represent an overlap of the feature set for the at least one event from the first log file and the feature set for each of the plurality of events from the second log file, wherein each linkage strength value increases as the overlap of the feature set increases; and

    a trace event pairs link time strength determination module, executed by the at least one processor, to determine trace event pairs link time strength values between the at least one event from the first log file of the plurality of log files and each of the plurality of events from the second log file of the plurality of log files,whereinthe trace event pairs link time strength values represent a strength of time difference between the at least one event from the first log file of the plurality of log files and each of the plurality of events from the second log file of the plurality of log files,the trace event pairs link time strength values are based on a time difference between the at least one event from the first log file of the plurality of log files and each of the plurality of events from the second log file of the plurality of log files, and a highest absolute difference of all timestamp pairs between the at least one event from the first log file of the plurality of log files and each of the plurality of events from the second log file of the plurality of log files,an event correlation between the at least one event from the first log file of the plurality of log files and at least one event of the plurality of events from the second log file of the plurality of log files is identified based on the plurality of trace event pairs linkage strength values and the trace event pairs link time strength values,the at least one event of the plurality of events from the second log file of the plurality of log files represents an anomaly associated with the second log file of the plurality of log files, andthe anomaly associated with the second log file of the plurality of log files is related to the at least one event from the first log file of the plurality of log files.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×