Intelligent anomaly identification and alerting system based on smart ranking of anomalies
Abstract
A method for ranking detected anomalies is disclosed. The method includes generating a graph based on a plurality of rules, wherein the graph comprises nodes representing metrics identified in the rules, edges connecting nodes where metrics associated with connected nodes are identified in a given rule, and edge weights of the edges each representing a severity level assigned to the given rule. The method further includes ranking nodes of the graph based on the edge weights. The method further includes ranking detected anomalies based on the ranking of the nodes corresponding to the metrics associated with the detected anomalies.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for ranking detected anomalies, the method comprising:
defining a plurality of rules; generating a graph of the plurality of rules, comprising:
creating a plurality of nodes, each of the nodes corresponding to a metric of the plurality of rules, the rules including a first rule in which a single metric is a potential source of an anomaly and a second rule in which a pair of metrics is a potential source of anomaly;
connecting, for each node corresponding to a single metric of the rules, the corresponding each node to itself with an edge;
connecting, for each pair of metrics of the second rules, the corresponding pair of nodes with edges;
assigning each of the edges with an edge weight corresponding to a severity level of the corresponding rule that defined the edge;
detecting anomalies by comparing system metrics relative to the rules; and ranking detected anomalies based on the ranking of the nodes corresponding to the metrics of the graph; wherein the defining occurs before the detecting.
2 . The method of claim 1 , further comprising:
alerting an end user of the detected anomalies based on the ranking of the detected anomalies.
3 . The method of claim 1 , wherein the plurality of rules each comprises:
at least one metric describing a state of one or more resources; and at least one condition, wherein each condition is defined for a corresponding metric.
4 . The method of claim 1 , wherein the detected anomalies are detected by observing for anomalous metrics and/or anomalous log through statistical analysis.
5 . The method of claim 1 , wherein edges are defined in the graph when two or more metrics and their corresponding conditions are connected in a given rule via a logical operation.
6 . The method of claim 1 , wherein value for a given edge weight of a given edge connecting two nodes varies depending on a type of logical operation which connects metrics corresponding to the two nodes.
7 . The method of claim 1 , wherein ranking nodes comprises:
computing an importance value for a given node based on all edge weights of edges connected to the given node; and upon computing importance values for all nodes, ranking the nodes based on the importance values.
8 . A non-transitory computer-readable medium comprising one or more instructions that when executed on a processor cause the processor to perform operations comprising:
define a plurality of rules; generate a graph of the plurality of rules, comprising:
create a plurality of nodes, each of the nodes corresponding to a metric of the plurality of rules, the rules including a first rule in which a single metric is a potential source of an anomaly and a second rule in which a pair of metrics is a potential source of anomaly;
connect, for each node corresponding to a single metric of the rules, the corresponding each node to itself with an edge;
connect, for each pair of metrics of the second rules, the corresponding pair of nodes with edges;
assign each of the edges with an edge weight corresponding to a severity level of the corresponding rule that defined the edge;
detect anomalies by comparing system metrics relative to the rules; and rank detected anomalies based on the ranking of the nodes corresponding to the metrics of the graph; wherein the define occurs before the detect.
9 . The non-transitory computer-readable medium of claim 8 , the operations further comprising:
alerting an end user of the detected anomalies based on the ranking of the detected anomalies.
10 . The non-transitory computer-readable medium of claim 8 , wherein the plurality of rules each comprises:
at least one metric describing a state of one or more resources; and at least one condition, wherein each condition is defined for a corresponding metric.
11 . The non-transitory computer-readable medium of claim 8 , wherein the detected anomalies are detected by observing for anomalous metrics and/or anomalous log through statistical analysis.
12 . The non-transitory computer-readable medium of claim 8 , wherein edges are defined in the graph when two or more metrics and their corresponding conditions are connected in a given rule via a logical operation.
13 . The non-transitory computer-readable medium of claim 8 , wherein value for a given edge weight of a given edge connecting two nodes varies depending on a type of logical operation which connects metrics corresponding to the two nodes.
14 . The non-transitory computer-readable medium of claim 8 , wherein the operation of rank nodes comprises:
compute an importance value for a given node based on all edge weights of edges connected to the given node; and upon compute importance values for all nodes, rank the nodes based on the importance values.
15 . A system, comprising:
a non-transitory computer readable media storing instructions; a processor programmed to cooperate with the instructions to perform operations comprising:
define a plurality of rules;
generate a graph of the plurality of rules, comprising:
create a plurality of nodes, each of the nodes corresponding to a metric of the plurality of rules, the rules including a first rule in which a single metric is a potential source of an anomaly and a second rule in which a pair of metrics is a potential source of anomaly;
connect, for each node corresponding to a single metric of the rules, the corresponding each node to itself with an edge;
connect, for each pair of metrics of the second rules, the corresponding pair of nodes with edges;
assign each of the edges with an edge weight corresponding to a severity level of the corresponding rule that defined the edge;
detect anomalies by comparing system metrics relative to the rules; and
rank detected anomalies based on the ranking of the nodes corresponding to the metrics of the graph;
wherein the define occurs before the detect.
16 . The system of claim 15 , the operations further comprising:
alerting an end user of the detected anomalies based on the ranking of the detected anomalies.
17 . The system of claim 15 , wherein the plurality of rules each comprises:
at least one metric describing a state of one or more resources; and at least one condition, wherein each condition is defined for a corresponding metric.
18 . The system of claim 15 , wherein the detected anomalies are detected by observing for anomalous metrics and/or anomalous log through statistical analysis.
19 . The system of claim 15 , wherein edges are defined in the graph when two or more metrics and their corresponding conditions are connected in a given rule via a logical operation.
20 . The system of claim 15 , wherein value for a given edge weight of a given edge connecting two nodes varies depending on a type of logical operation which connects metrics corresponding to the two nodes.Join the waitlist — get patent alerts
Track US2021397982A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.