US2019171644A1PendingUtilityA1
Efficient event searching
Est. expiryDec 4, 2037(~11.3 yrs left)· nominal 20-yr term from priority
G06F 16/2455G06F 16/24542G06F 18/285G06F 16/2465G06F 2216/03G06F 16/1734G06F 16/9038G06F 16/152G06F 11/08
56
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Methods and systems for event detection and correction include determining a log pattern for a received event. The log pattern is translated to an event search query. The event search query is weighted according to discriminative dimensions using term-frequency inverse-document-frequency. The event search query is matched to one or more known events. A corrective action is automatically performed based on a solution associated with the one or more known events.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for event detection and correction, comprising:
determining a log pattern for a received event; translating the log pattern to an event search query; weighting the event search query according to discriminative dimensions using term-frequency inverse-document-frequency (TF-IDF); matching the event search query to one or more known events; and automatically performing a corrective action based on a solution associated with the one or more known events.
2 . The method of claim 1 , wherein translating forms a vector representation of the log pattern as part of the event search query.
3 . The method of claim 2 , wherein matching the event search query to one or more known events comprises determining whether the vector representation of the log pattern is within a threshold value of a vector representation of a stored known event according to a similarity metric.
4 . The method of claim 3 , wherein the similarity metric is a cosine similarity that measures a similarity between the vector representation of the log pattern and the vector representation of the stored known event.
5 . The method of claim 1 , wherein translating the log pattern into an event query comprises extracting information from the log pattern and rendering the extracted information in the format of an event search query.
6 . The method of claim 5 , wherein the extracted information comprises log pattern type, a pattern identifier, and pattern-type-specific information.
7 . The method of claim 5 , wherein translating the log pattern into an event query decouples the determination of the log pattern from matching the event search query to one or more known events.
8 . The method of claim 1 , further comprising determining the solution associated with the one or more known events by searching a solutions database using the matched one or more known events.
9 . The method of claim 1 , wherein matching the event search query to the one or more known events generates an output that includes an identifier of the one or more known events, a similarity score that identifies a similarity between the event search query and the one or more known events, and an identifier for the received event.
10 . The method of claim 1 , wherein the corrective action includes one or more actions selected from the group consisting of changing a security setting for an application or hardware component, halting and/or restarting an application, halting and/or rebooting a hardware component, changing an environmental condition, and changing a network interface's status or settings.
11 . A system for event detection and correction, comprising:
a pattern mining module configured to determine a log pattern for a received event; an event query module configured to translate the log pattern to an event search query and to weight the event search query according to discriminative dimensions using term-frequency inverse-document-frequency (TF-IDF); a search module comprising a processor configured to match the event search query to one or more known events; and a correction module configured to automatically perform a corrective action based on a solution associated with the one or more known events.
12 . The system of claim 11 , wherein the event query module is further configured to form a vector representation of the log pattern as part of the event search query.
13 . The system of claim 12 , wherein the search module is further configured to determine whether the vector representation of the log pattern is within a threshold value of a vector representation of a stored known event according to a similarity metric.
14 . The system of claim 13 , wherein the similarity metric is a cosine similarity that measures a similarity between the vector representation of the log pattern and the vector representation of the stored known event.
15 . The system of claim 11 , wherein the event query module is further configured to extract information from the log pattern and rendering the extracted information in the format of an event search query.
16 . The system of claim 15 , wherein the extracted information comprises log pattern type, a pattern identifier, and pattern-type-specific information.
17 . The system of claim 15 , wherein the event query module is further configured to decouple operation of the pattern mining module from operation of the search module.
18 . The system of claim 11 , further comprising a solution module configured to determine the solution associated with the one or more known events by searching a solutions database using the matched one or more known events.
19 . The system of claim 11 , wherein the search module is further configured to generate an output that includes an identifier of the one or more known events, a similarity score that identifies a similarity between the event search query and the one or more known events, and an identifier for the received event.
20 . The system of claim 11 , wherein the correction module is configured to automatically perform a corrective action selected from the group consisting of changing a security setting for an application or hardware component, halting and/or restarting an application, halting and/or rebooting a hardware component, changing an environmental condition, and changing a network interface's status or settings.Join the waitlist — get patent alerts
Track US2019171644A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.