IP Library Granted Patent US 12681790
Granted Patent B2
US 12681790 · App. 18/212,447 · Granted Jul 14, 2026

Method and system for triggering alerts on identification of an anomaly in data logs

Inventor: Durga Shanker Balla (Rangareddy, IN)
Assignee: JPMORGAN CHASE BANK, N.A.
G06F11/0769G06F11/0721G06F11/079
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12681790
App. No.
18/212,447
Granted
Jul 14, 2026
Kind
B2
Abstract

A method and system for automatically triggering alerts for at least one anomaly are disclosed. The method includes receiving a plurality of data logs associated with a plurality of applications. Next, the method includes trimming the plurality of data logs into a set of data logs and comparing the set of data logs with each of a plurality of previously stored set of data logs. Next, the method includes identifying a set of new events associated with the at least one anomaly. Next, the method includes analyzing the set of new events to identify a pattern associated with the at least one anomaly and displaying, via a display, the pattern associated with the at least one anomaly to at least one entity. Thereafter, the method includes automatically triggering the alerts for the at least one anomaly based on the identification of the pattern associated with the at least one anomaly.

Claims (39)

1 . A method for automatically triggering alerts for at least one anomaly, the method being implemented by at least one processor, the method comprising:

receiving, by the at least one processor via a communication interface, a plurality of data logs associated with a plurality of applications;

trimming, by the at least one processor, the plurality of data logs into a set of data logs;

comparing, by the at least one processor, the set of data logs with each of a plurality of previously stored set of data logs corresponding to at least one from among previous day stored logs, previous week stored logs, two weeks prior stored logs and identifying deviations including a sudden change in data traffic at one or more cloud-based servers based on comparison results;

identifying, by the at least one processor, a set of new events associated with the at least one anomaly based on the comparison of the set of data logs with each of the plurality of previously stored set of data logs;

analyzing, by the at least one processor using a trained model, the set of new events to identify a pattern associated with the at least one anomaly;

displaying, by the at least one processor via a display, the pattern associated with the at least one anomaly to at least one entity;

automatically triggering, by the at least one processor, the alerts for the at least one anomaly based on the identification of the pattern associated with the at least one anomaly and based on an altering threshold; and

utilizing, by the at least one processor, the trained model to auto-adjust the alerting threshold based on a traffic pattern at the one or more cloud-based servers identified from the comparison results and based on a duration of an existence of the anomaly.

2 . The method as claimed in claim 1 , wherein the pattern associated with the at least one anomaly is displayed to the at least one entity in a form of a visual representation.

3 . The method as claimed in claim 1 , wherein the at least one anomaly is identified based on a deviation in the set of data logs with each of the plurality of previously stored set of data logs.

4 . The method as claimed in claim 1 , wherein the plurality of the data logs is trimmed into the set of data logs using a data modeling technique.

5 . A computing device configured to implement an execution of a method for automatically triggering alerts for at least one anomaly, the computing device comprising:

a processor;

a memory; and

a communication interface coupled to each of the processor and the memory, wherein the processor is configured to:

receive, via the communication interface, a plurality of data logs associated with a plurality of applications;

trim the plurality of data logs into a set of data logs;

compare the set of data logs with each of a plurality of previously stored set of data logs corresponding to at least one from among previous day stored logs, previous week stored logs, two weeks prior stored logs and identifying deviations including a sudden change in data traffic at one or more cloud-based servers based on comparison results;

identify a set of new events associated with the at least one anomaly based on the comparison of the set of data logs with each of the plurality of previously stored set of data logs;

analyze the set of new events to identify a pattern associated with the at least one anomaly;

display, via a display, the pattern associated with the at least one anomaly to at least one entity;

automatically trigger the alerts for the at least one anomaly based on the identification of the pattern associated with the at least one anomaly and based on an altering threshold; and

utilize the trained model to auto-adjust the alerting threshold based on a traffic pattern at the one or more cloud-based servers identified from the comparison results and based on a duration of an existence of the anomaly.

6 . The computing device as claimed in claim 5 , wherein the pattern associated with the at least one anomaly is displayed to the at least one entity in a form of a visual representation.

7 . The computing device as claimed in claim 5 , wherein the at least one anomaly is identified based on a deviation in the set of data logs with each of the plurality of previously stored set of data logs.

8 . The computing device as claimed in claim 5 , wherein the plurality of the data logs is trimmed into the set of data logs using a data modelling technique.

9 . A non-transitory computer readable storage medium storing instructions for automatically triggering alerts for at least one anomaly, the instructions comprising executable code which, when executed by a processor, causes the processor to:

receive, via a communication interface, a plurality of data logs associated with a plurality of applications;

trim the plurality of data logs into a set of data logs;

compare the set of data logs with each of a plurality of previously stored set of data logs corresponding to at least one from among previous day stored logs, previous week stored logs, two weeks prior stored logs and identifying deviations including a sudden change in data traffic at one or more cloud-based servers based on comparison results;

identify a set of new events associated with the at least one anomaly based on the comparison of the set of data logs with each of the plurality of previously stored set of data logs;

analyze the set of new events to identify a pattern associated with the at least one anomaly;

display, via a display, the pattern associated with the at least one anomaly to at least one entity;

automatically trigger the alerts for the at least one anomaly based on the identification of the pattern associated with the at least one anomaly and based on an altering threshold; and

utilize the trained model to auto-adjust the alerting threshold based on a traffic pattern at the one or more cloud-based servers identified from the comparison results and based on a duration of an existence of the anomaly.

10 . The non-transitory computer readable storage medium as claimed in claim 9 , wherein the pattern associated with the at least one anomaly is displayed to the at least one entity in a form of a visual representation.

11 . The non-transitory computer readable storage medium as claimed in claim 9 , wherein the at least one anomaly is identified based on a deviation in the set of data logs with each of the plurality of previously stored set of data logs.

12 . The non-transitory computer readable storage medium as claimed in claim 9 , wherein the plurality of the data logs is trimmed into the set of data logs using a data modelling technique.