IP Library Granted Patent US 7,925,678
Granted Patent B2
US 7,925,678 · App. 11/623,010 · Granted Apr 12, 2011

Customized reporting and mining of event data

Assignee: LogLogic, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,925,678
App. No.
11/623,010
Filed
Jan 12, 2007
Granted
Apr 12, 2011
Kind
B2
Art Unit
2161
USPC
707/102
Abstract

Event data (e.g., log messages) are represented as sets of attribute/value pairs. An index maps each attribute/value pair or attribute/value tuple to a pointer that points to event data which contains the attribute/value pair or attribute/value tuple. An attribute co-occurrence map or matrix can be generated that includes attribute names that co-occur together. Queries and custom reports can be generated by projecting event data into one or more attributes or attribute/value pairs, and then determining statistics on other attributes using a combination of the inverted index, the attribute co-occurrence map or matrix, operations on sets and/or math and statistical functions.

Claims (41)

1. A computer-implemented method, comprising:

receiving event data in a log file;

transforming the event data into attribute/value pairs;

generating an index mapping at least one of the attribute/value pairs to a reference pointer that references an instance of event data in the log file, the instance of event data in the log file including a textual message from which the attribute/value pair was transformed;

generating an attribute co-occurrence data structure, the attribute co-occurrence data structure identifying a relationship between a first attribute in the attribute/value pairs and a second attribute in the attribute/value pairs, where existence of the relationship between the first attribute and the second attribute indicates that reports for finding a textual message including both the first attribute and the second attribute are allowable; and

in response to a query including the first attribute, generating a report based on the attribute co-occurrence data structure and the attribute/value pairs in the index, including:

identifying the second attribute based on the relationship identified in the attribute co-occurrence data structure;

identifying an attribute/value pair that includes the second attribute; and

generating the report, including providing access to the event data in the log file using a reference pointer that is mapped to the identified attribute/value pair in the index,

where the method is performed by one or more processors.

2. The method of claim 1 , where identifying the relationship between the first attribute and the second attribute includes identifying a sender-recipient relationship between the first attribute and the second attribute according to an email message.

3. The method of claim 1 , wherein generating the report further comprises:

projecting the event data into one or more attributes or attribute/value pairs; and

determining statistics on other attributes using a combination of the index and the attribute co-occurrence data structure.

4. The method of claim 3 , wherein the statistics are determined using operations on sets of attribute/value pairs.

5. The method of claim 3 , wherein the statistics are determined using statistical functions.

6. The method of claim 1 , wherein the index maps an attribute/value tuple to a reference pointer that references an instance of event data that contains the attribute/value tuple.

7. The method of claim 6 , further comprising:

determining a count representing a number of occurrences of an attribute/value pair or attribute/value tuple for a predetermined period of time.

8. A system, comprising:

a storage device operable for storing event data in a log file; and

one or more data processing devices configured to perform operations comprising:

transforming the event data into attribute/value pairs;

generating an index mapping at least one of the attribute/value pairs to a reference pointer that references an instance of event data in the log file, the instance of event data in the log file including a textual message from which the attribute/value pair was transformed;

generating an attribute co-occurrence data structure, the attribute co-occurrence data structure identifying a relationship between a first attribute in the attribute/value pairs and a second attribute in the attribute/value pairs, where existence of the relationship between the first attribute and the second attribute indicates that reports for finding a textual message including both the first attribute and the second attribute are allowable; and

in response to a query including the first attribute, generating a report based on the attribute co-occurrence data structure and the attribute/value pairs in the index, including:

identifying the second attribute based on the relationship identified in the attribute co-occurrence data structure;

identifying an attribute/value pair that includes the second attribute; and

generating the report, including providing access to the event data in the log file using a reference pointer that is mapped to the identified attribute/value pair in the index.

9. The system of claim 8 , wherein the event data includes log messages.

10. The system of claim 8 , wherein the index is operable to determine a count representing a number of occurrences of an attribute/value pair or attribute/value tuple for a predetermined period of time.

11. The system of claim 8 , further comprising:

a pre-parser adapted for coupling with a number of collectors to receive the event data, the pre-parser operable for identifying a source of the event data.

12. The system of claim 8 , wherein the storage device is a persistent storage device configured to store the event data for a user-specified period of time.

13. The system of claim 8 , wherein transforming the event data into attribute/value pairs includes generating the attribute/value pairs by applying rules to the event data.

14. The system of claim 13 , wherein the rules include a first set of rules for generating the attribute/value pairs from the event data, and a second set of rules for segmenting a space of the attribute/value pairs into regions and labeling the regions with new attribute/value pairs.

15. The system of claim 8 , wherein the attribute/value pairs represent particular instances of event data.

16. The system of claim 8 , wherein at least one attribute in an attribute/value pair is an action result.

17. The system of claim 8 , wherein at least one attribute in an attribute/value pair is a user name.

18. The system of claim 8 , wherein at least one attribute is user-definable.

19. The system of claim 8 , wherein the attribute co-occurrence data structure comprises a two-dimensional matrix having rows and columns, each row and column representing a different attribute, the matrix including a value at each intersection of a row and column of the matrix, the value for indicating a relationship between the attributes represented by the intersecting row and column.

Assignments (17)
CHANGE OF NAME Recorded Jul 1, 2026
From: CLOUD SOFTWARE GROUP, INC.
To: CLOUD SOFTWARE GROUP, LLC
Reel/Frame 075874/0220 →
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
CHANGE OF NAME Recorded Feb 7, 2023
From: TIBCO SOFTWARE INC.
To: CLOUD SOFTWARE GROUP, INC.
Reel/Frame 062714/0634 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
RELEASE REEL 052115 / FRAME 0318 Recorded Oct 3, 2022
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: TIBCO SOFTWARE INC.
Reel/Frame 061588/0511 →
RELEASE (REEL 034536 / FRAME 0438) Recorded Sep 30, 2022
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 061574/0963 →
RELEASE (REEL 054275 / FRAME 0975) Recorded May 7, 2021
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 056176/0398 →
SECURITY AGREEMENT Recorded Nov 2, 2020
From: TIBCO SOFTWARE INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 054275/0975 →
SECURITY AGREEMENT Recorded Mar 6, 2020
From: TIBCO SOFTWARE INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 052115/0318 →
SECURITY INTEREST Recorded Dec 5, 2014
From: TIBCO SOFTWARE INC.; TIBCO KABIRA LLC; NETRICS.COM LLC
To: JPMORGAN CHASE BANK., N.A., AS COLLATERAL AGENT
Reel/Frame 034536/0438 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2013
From: LOGLOGIC, INC.
To: TIBCO SOFTWARE INC.
Reel/Frame 030560/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2007
From: BOTROS, SHERIF; ZHEN, JIAN L.; LIU, MINJUN; GALITSKY, BORIS
To: LOGLOGIC, INC.
Reel/Frame 018959/0354 →
Continuity (1)
Related Publication 20080172409A1 · Jul 17, 2008