IP Library Granted Patent US 9,171,037
Granted Patent B2
US 9,171,037 · App. 13/668,847 · Granted Oct 27, 2015

Searching for associated events in log data

Inventors: Boris Galitsky (Palo Alto, CA); Sherif Botros (Redwood Shores, CA)
Assignee: TIBCO Software Inc.
G06F17/30424G06F17/30637G06F17/30666
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,171,037
App. No.
13/668,847
Granted
Oct 27, 2015
Kind
B2
Abstract

To retrieve a sequence of associated events in log data, a request expression is parsed to retrieve types of dependencies between events which are searched, and the constraints (e.g., keywords) which characterize each event. Based on the parsing results, query components can be formed, expressing the constraints for individual events and interrelations (e.g., time spans) between events. A resultant span query comprising the query components can then be run against an index of events, which encodes a mutual location of associated events in storage.

Claims (60)

1. A computer-implemented method, comprising:

receiving, by a processor, a query searching for associated events in log data, the associated events being multiple events that are related to one another by a common component;

parsing the received query, including:

locating a reserved term from the received query;

identifying an intermediate component of the received query, the intermediate component including a portion of the received query that is located after the reserved term; and

identifying a final component of the received query, the final component including a portion of the received query preceding the reserved term, wherein the reserved term comprises a term indicating that the intermediate component constrains a variable in the final component;

forming an intermediate query for the intermediate component, including constructing a first search term for the intermediate component, the first search term explicitly indicating one or more first keywords that appeared in the intermediate component of the received query;

performing the intermediate query, including determining, using the intermediate query, one or more second keywords, each second keyword satisfying the search term in the intermediate query;

forming a final query for the final component, including constructing a second search term for the final component, the second search term explicitly indicates the one or more second keywords resulted from performing the intermediate query;

merging a result of performing the intermediate query and a result of performing the final query; and

designating the merged results as the associated events in response to the received query,

wherein the method is performed by one or more computers.

2. The computer-implemented method of claim 1 , wherein:

the common component includes at least one of a device or a user, and

the reserved term includes a reserved word for identifying the device or a reserved word for identifying the user.

3. The computer-implemented method of claim 2 , wherein the reserved word for identifying the device is “which” and the reserved word for identifying the user is “who”.

4. The computer-implemented method of claim 1 , wherein the result of the intermediate query is designated as a selection constraint in the final query.

5. The computer-implemented method of claim 1 , wherein designating the merged results as the associated events comprises:

providing for display a user interface view that presents an individual event from the intermediate query along with a set of events from the final query associated with the individual event.

6. The computer-implemented method of claim 1 , wherein each of the received query, the intermediate query, and the final query is written in a structured query language.

7. A system comprising:

a storage device operable for storing one or more events as log messages; and

a processor coupled to the storage device and configured to perform operations comprising:

receiving a query searching for associated events in log data, the associated events being multiple events that are related to one another by a common component;

parsing the received query, including:

locating a reserved term from the received query;

identifying an intermediate component of the received query, the intermediate component including a portion of the received query that is located after the reserved term; and

identifying a final component of the received query, the final component including a portion of the received query preceding the reserved term, wherein the reserved term comprises a term indicating that the intermediate component constrains a variable in the final component;

forming an intermediate query for the intermediate component, including constructing a first search term for the intermediate component, the first search term explicitly indicating one or more first keywords that appeared in the intermediate component of the received query;

performing the intermediate query, including determining, using the intermediate query, one or more second keywords, each second keyword satisfying the first search term in the intermediate query;

forming a final query for the final component, including constructing a second search term for the final component, the second search term explicitly indicates the one or more second keywords resulted from performing the intermediate query;

merging a result of performing the intermediate query and a result of performing the final query; and

designating the merged results as the associated events in response to the received query.

8. The system of claim 7 , wherein:

the common component includes at least one of a device or a user, and

the reserved term includes a reserved word for identifying the device or a reserved word for identifying the user.

9. The system of claim 8 , wherein the reserved word for identifying the device is “which” and the reserved word for identifying the user is “who”.

10. The system of claim 7 , wherein the result of the intermediate query is designated as a selection constraint in the final query.

11. The system of claim 7 , wherein designating the merged results as the associated events comprises:

providing for display a user interface view that presents an individual event from the intermediate query along with a set of events from the final query associated with the individual event.

12. The system of claim 7 , wherein each of the received query, the intermediate query, and the final query is written in a structured query language.

13. A non-transitory storage device storing instructions operable to cause one or more computers to perform operations comprising:

receiving a query searching for associated events in log data, the associated events being multiple events that are related to one another by a common component;

parsing the received query, including:

locating a reserved term from the received query;

identifying a portion of the received query that is located after the reserved term;

identifying a final component of the received query, the final component including a portion of the received query preceding the reserved term, wherein the reserved term comprises a term indicating that the intermediate component constrains a variable in the final component;

forming an intermediate query for the intermediate component, including constructing a first search term for the intermediate component, the first search term explicitly indicating one or more first keywords that appeared in the intermediate component of the received query;

performing the intermediate query, including determining, using the intermediate query, one or more second keywords, each second keyword satisfying the first search term in the intermediate query;

forming a final query for the final component, including constructing a second search term for the final component, the second search term explicitly indicates the one or more second keywords resulted from performing the intermediate query;

merging a result of performing the intermediate query and a result of performing the final query; and

designating the merged results as the associated events in response to the received query.

14. The non-transitory storage device of claim 13 , wherein:

the common component includes at least one of a device or a user, and

the reserved term includes a reserved word for identifying the device or a reserved word for identifying the user.

15. The non-transitory storage device of claim 14 , wherein the reserved word for identifying the device is “which” and the reserved word for identifying the user is “who”.

16. The non-transitory storage device of claim 13 , wherein the result of the intermediate query is designated as a selection constraint in the final query.

17. The non-transitory storage device of claim 13 , wherein designating the merged results as the associated events comprises:

providing for display a user interface view that presents an individual event from the intermediate query along with a set of events from the final query associated with the individual event.

18. The non-transitory storage device of claim 13 , wherein each of the received query, the intermediate query, and the final query is written in a structured query language.

Assignments (16)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
CHANGE OF NAME Recorded Feb 7, 2023
From: TIBCO SOFTWARE INC.
To: CLOUD SOFTWARE GROUP, INC.
Reel/Frame 062714/0634 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
RELEASE REEL 052115 / FRAME 0318 Recorded Oct 3, 2022
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: TIBCO SOFTWARE INC.
Reel/Frame 061588/0511 →
RELEASE (REEL 034536 / FRAME 0438) Recorded Sep 30, 2022
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 061574/0963 →
RELEASE (REEL 054275 / FRAME 0975) Recorded May 7, 2021
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 056176/0398 →
SECURITY AGREEMENT Recorded Nov 2, 2020
From: TIBCO SOFTWARE INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 054275/0975 →
SECURITY AGREEMENT Recorded Mar 6, 2020
From: TIBCO SOFTWARE INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 052115/0318 →
SECURITY INTEREST Recorded Dec 5, 2014
From: TIBCO SOFTWARE INC.; TIBCO KABIRA LLC; NETRICS.COM LLC
To: JPMORGAN CHASE BANK., N.A., AS COLLATERAL AGENT
Reel/Frame 034536/0438 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2014
From: GALITSKY, BORIS; BOTROS, SHERIF
To: LOGLOGIC, INC.
Reel/Frame 034191/0388 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2013
From: LOGLOGIC, INC.
To: TIBCO SOFTWARE INC.
Reel/Frame 030560/0473 →
Continuity (2)
Continuation 11866337 · Oct 2, 2007
Related Publication 20130185286A1 · Jul 18, 2013