Systems and methods for classifying and predicting the cause of information technology incidents using machine learning
Abstract
The present disclosure provides systems and methods for classifying incidents based on determining an odds ratio that represents a likelihood of an incident being related to the problem, classifying incidents based on determining a decision tree that forms branches based on whether a feature is present in the incident, and predicting whether a new incident is related to a problem. Features may be extracted from a set of incidents (e.g., that are reported over a certain time period) that include incidents related to a problem and incidents not related to the problem. The incidents related to the problem and a portion of the incidents not related to the problem may be used to train a logistic regression model or generate a decision tree. The trained logistic regression model may be used to determine the odds ratios or predict whether a new incident is related to a problem.
Claims
exact text as granted — not AI-modified1 . A cloud computing system, comprising:
one or more data centers; a client instance hosted by the one or more data centers, wherein the client instance is accessible by one or more remote client networks, wherein the cloud computing system is configured to:
receive an indication of a problem and a set of incidents, wherein the set of incidents comprises a set of related incidents that are related to the problem and a set of unrelated incidents that are unrelated to the problem;
receive a set of trained logistic regression models based on one or more features of the set of incidents; and
predict whether a new incident is related to the problem by applying the set of trained logistic regression models to the new incident.
2 . The cloud computing system of claim 1 , wherein the problem comprises an elevated level incident that has been reported multiple times.
3 . The cloud computing system of claim 1 , wherein the set of incidents are reported during a specified time range.
4 . The cloud computing system of claim 1 , wherein each trained logistic regression model of the set of trained logistic regression models is configured to describe a relationship between the one or more features of the set of incidents and the problem.
5 . The cloud computing system of claim 1 , wherein each feature of the one or more features comprises a numerical features, a categorical feature, a text feature, or a time-related feature.
6 . The cloud computing system of claim 1 , wherein the cloud computing system is configured to train a plurality of sets of logistic regression models corresponding to a plurality of problems to generate a plurality of sets of trained logistic regression models, wherein the plurality of sets of trained logistic regression models comprises the set of trained logistic regression models, wherein the plurality of problems comprises the problem.
7 . The cloud computing system of claim 6 , wherein the cloud computing system is configured to predict which problem of the plurality of problems the new incident is related to by applying each set of trained logistic regression models of the plurality of sets of trained logistic regression models to the new incident.
8 . The cloud computing system of claim 6 , wherein each set of trained logistic regression models of the plurality of sets of trained logistic regression models is used to make a respective prediction as to whether the new incident is related to a respective problem of the plurality of problems.
9 . A tangible, non-transitory, machine-readable-medium, comprising machine-readable instructions for predicting whether a new incident is related to a problem reported to an information technology system, wherein the instructions, when executed by a processor, cause the processor to:
receive an indication of the problem and a set of incidents, wherein the set of incidents comprises a set of related incidents that are related to the problem and a set of unrelated incidents that are unrelated to the problem; receive a set of trained logistic regression models based on one or more features of the set of incidents; and predict whether the new incident is related to the problem by applying the set of trained logistic regression models to the new incident.
10 . The tangible, non-transitory, machine-readable-medium of claim 9 , wherein the instructions, when executed by the processor, cause the processor to train a set of logistic regression models based on the one or more features of the set of incidents to generate the set of trained logistic regression models.
11 . The tangible, non-transitory, machine-readable-medium of claim 9 , wherein the instructions, when executed by the processor, cause the processor to receive the new incident.
12 . The tangible, non-transitory, machine-readable-medium of claim 9 , wherein the instructions, when executed by the processor, cause the processor to report whether the new incident is related to the problem.
13 . The tangible, non-transitory, machine-readable-medium of claim 9 , wherein the new incident is predicted to be related to the problem when a majority of trained logistic regression models of the set of trained logistic regression models predict that the new incident is related to the problem.
14 . A method for predicting whether a new incident is related to a problem reported to an information technology system, comprising:
receiving an indication of the problem and a set of incidents, wherein the set of incidents comprises a set of related incidents that are related to the problem and a set of unrelated incidents that are unrelated to the problem; receiving a set of trained logistic regression models based on one or more features of the set of incidents; and predicting whether the new incident is related to the problem by applying the set of trained logistic regression models to the new incident.
15 . The method of claim 14 , comprising:
sampling the set of unrelated incidents to generate a subset of unrelated incidents that are unrelated to the problem; and training a set of trained logistic regression models with the set of related incidents and the subset of unrelated incidents to generate the set of trained logistic regression models.
16 . The method of claim 15 , wherein training the set of logistic regression models comprises training each logistic regression model with a different subset of unrelated incidents.
17 . The method of claim 14 , wherein the new incident is predicted to be related to the problem when a majority of trained logistic regression models of the set of trained logistic regression models predict that the new incident is related to the problem.
18 . The method of claim 14 , comprising training a plurality of sets of logistic regression models corresponding to a plurality of problems to generate a plurality of sets of trained logistic regression models, wherein the plurality of sets of trained logistic regression models comprises the set of trained logistic regression models, wherein the plurality of problems comprises the problem.
19 . The method of claim 18 , comprising predicting which problem of the plurality of problems the new incident is related to by applying each set of trained logistic regression models of the plurality of sets of trained logistic regression models to the new incident.
20 . The method of claim 18 , wherein each set of trained logistic regression models of the plurality of sets of trained logistic regression models is used to make a respective prediction as to whether the new incident is related to a respective problem of the plurality of problems.Join the waitlist — get patent alerts
Track US2021382775A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.