IP Library Granted Patent US 10,291,493
Granted Patent B1
US 10,291,493 · App. 14/562,474 · Granted May 14, 2019

System and method for determining relevant computer performance events

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,291,493
App. No.
14/562,474
Granted
May 14, 2019
Kind
B1
Abstract

In one embodiment, a method includes identifying at least one transaction-path node as a problem node based, at least in part, on an analysis of end-to-end response times for a group of transactions. The method further includes determining one or more event types for the at least one transaction-path node. Also, the method includes, for each of the one or more event types, inferring a first event-relevance weight from an abstract model. The method also includes, for each of the one or more event types, inferring a second event-relevance weight from a concrete model. Furthermore, the method includes, for each of the one or more event types, determining an event relevance based, at least in part, on the first event-relevance weight and the second event-relevance weight. Additionally, the method includes identifying most-relevant events among a set of active events based, at least in part, on the determined event relevance.

Claims (58)

1. A method comprising, by a computer system:

monitoring, in real-time, end-user transactions that pass through an end-to-end transaction path comprising a plurality of transaction-path nodes;

responsive to the monitoring, identifying at least one transaction-path node of the plurality of transaction-path nodes as a problem node based, at least in part, on an analysis of end-to-end response times for a group of the monitored end-user transactions;

determining one or more event types that are related to the at least one transaction-path node based, at least in part, on the one or more event types being at least indirectly connected to the at least one transaction-path node in at least one of an abstract model and a concrete model;

wherein the abstract model comprises a first probabilistic graphical model that represents a set of monitored-resource types, a plurality of event types, and a probabilistic relevance of the monitored-resource types to the plurality of event types, the set of monitored-resource types comprising a monitored-resource type of the at least one transaction-path node, the plurality of event types comprising the one or more event types;

wherein the concrete model comprises a second probabilistic graphical model that represents a real-time topology of monitored resources, the plurality of event types, and a probabilistic relevance of the monitored resources to the plurality of event types such that the monitored resources are instances of the monitored-resource types, the monitored resources comprising the at least one transaction path node;

for each of the one or more event types, inferring a first event-relevance weight from the abstract model;

for each of the one or more event types, inferring a second event-relevance weight from the concrete model;

for each of the one or more event types, determining an event relevance based, at least in part, on the first event-relevance weight and the second event-relevance weight;

identifying a set of currently-firing events that correspond to one or more of the one or more event types;

identifying most-relevant events among the set of currently-firing events based, at least in part, on the determined event relevance; and

publishing the identified most-relevant events to a user to facilitate troubleshooting of the problem node.

2. The method of claim 1 , wherein the identifying of the at least one transaction-path node comprises calculating a response-time differential between an execution time by the at least one transaction-path node in deemed unacceptable transactions and an execution time by the at least one transaction-path node in deemed acceptable transactions.

3. The method of claim 2 , comprising:

determining a base relevance value for the at least one transaction-path node;

and wherein the determining of the event relevance is based, at least in part, the base relevance value.

4. The method of claim 3 , wherein the base relevance value comprises a normalization of the response-time differential.

5. The method of claim 1 , comprising selecting the group of transactions, the group having a common end-to-end transaction path comprising a plurality of transaction-path nodes, the plurality of transaction-path nodes comprising the at least one transaction-path node.

6. The method of claim 1 , comprising transmitting a report to another system for analysis.

7. The method of claim 1 , wherein the abstract model and the concrete model each comprise a Bayesian network.

8. The method of claim 1 , comprising deferring evaluation of one or more rules associated with at least one event until the at least one event is determined sufficiently relevant as a result of the determining of the event relevance.

9. The method of claim 1 , comprising training the abstract model and the concrete model using a result of the determining of the event relevance.

10. An information handling system comprising:

a processor and memory, wherein the processor and memory in combination are operable to implement a method comprising:

monitoring, in real-time, end-user transactions that pass through an end-to-end transaction path comprising a plurality of transaction-path nodes;

responsive to the monitoring, identifying at least one transaction-path node of the plurality of transaction-path nodes as a problem node based, at least in part, on an analysis of end-to-end response times for a group of the monitored end-user transactions;

determining one or more event types that are related to the at least one transaction-path node based, at least in part, on the one or more event types being at least indirectly connected to the at least one transaction-path node in at least one of an abstract model and a concrete model;

wherein the abstract model comprises a first probabilistic graphical model that represents a set of monitored-resource types, a plurality of event types, and a probabilistic relevance of the monitored-resource types to the plurality of event types, the set of monitored-resource types comprising a monitored-resource type of the at least one transaction-path node, the plurality of event types comprising the one or more event types;

wherein the concrete model comprises a second probabilistic graphical model that represents a real-time topology of monitored resources, a plurality of event types, and a probabilistic relevance of the monitored resources to the plurality of event types such that the monitored resources are instances of the monitored-resource types, the monitored resources comprising the at least one transaction path node;

for each of the one or more event types, inferring a first event-relevance weight from the abstract model;

for each of the one or more event types, inferring a second event-relevance weight from the concrete model;

for each of the one or more event types, determining an event relevance based, at least in part, on the first event-relevance weight and the second event-relevance weight;

identifying a set of currently-firing events that correspond to one or more of the one or more event types;

identifying most-relevant events among the set of currently-firing events based, at least in part, on the determined event relevance; and

publishing the identified most-relevant events to a user to facilitate troubleshooting of the problem node.

11. The information handling system of claim 10 , wherein the identifying of the at least one transaction-path node comprises calculating a response-time differential between an execution time by the at least one transaction-path node in deemed unacceptable transactions and an execution time by the at least one transaction-path node in deemed acceptable transactions.

12. The information handling system of claim 11 , the method comprising:

determining a base relevance value for the at least one transaction-path node;

and wherein the determining of the event relevance is based, at least in part, the base relevance value.

13. The information handling system of claim 12 , wherein the base relevance value comprises a normalization of the response-time differential.

14. The information handling system of claim 10 , the method comprising selecting the group of transactions, the group having a common end-to-end transaction path comprising a plurality of transaction-path nodes, the plurality of transaction-path nodes comprising the at least one transaction-path node.

15. The information handling system of claim 10 , the method comprising transmitting a report to another system for analysis.

16. The information handling system of claim 10 , wherein the abstract model and the concrete model each comprise a Bayesian network.

17. The information handling system of claim 10 , the method comprising deferring evaluation of one or more rules associated with at least one event until the at least one event is determined sufficiently relevant as a result of the determining of the event relevance.

18. The information handling system of claim 10 , the method comprising training the abstract model and the concrete model using a result of the determining of the event relevance.

19. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed by a processor to implement a method comprising:

monitoring, in real-time, end-user transactions that pass through an end-to-end transaction path comprising a plurality of transaction-path nodes;

responsive to the monitoring, identifying at least one transaction-path node of the plurality of transaction-path nodes as a problem node based, at least in part, on an analysis of end-to-end response times for a group of the monitored end-user transactions;

determining one or more event types that are related to the at least one transaction-path node based, at least in part, on the one or more event types being at least indirectly connected to the at least one transaction-path node in at least one of an abstract model and a concrete model;

wherein the abstract model comprises a first probabilistic graphical model that represents a set of monitored-resource types, a plurality of event types, and a probabilistic relevance of the monitored-resource types to the plurality of event types, the set of monitored-resource types comprising a monitored-resource type of the at least one transaction-path node, the plurality of event types comprising the one or more event types;

wherein the concrete model comprises a second probabilistic graphical model that represents a real-time topology of monitored resources, a plurality of event types, and a probabilistic relevance of the monitored resources to the plurality of event types such that the monitored resources are instances of the monitored-resource types, the monitored resources comprising the at least one transaction path node;

for each of the one or more event types, inferring a first event-relevance weight from the abstract model;

for each of the one or more event types, inferring a second event-relevance weight from the concrete model;

for each of the one or more event types, determining an event relevance based, at least in part, on the first event-relevance weight and the second event-relevance weight;

identifying a set of currently-firing events that correspond to one or more of the one or more event types;

identifying most-relevant events among the set of currently-firing events based, at least in part, on the determined event relevance; and

publishing the identified most-relevant events to a user to facilitate troubleshooting of the problem node.

20. The computer-program product of claim 19 , wherein the identifying of the at least one transaction-path node comprises calculating a response-time differential between an execution time by the at least one transaction-path node in deemed unacceptable transactions and an execution time by the at least one transaction-path node in deemed acceptable transactions.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044719/0565 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 035104 FRAME 0043 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0123 →
RELEASE OF REEL 035103 FRAME 0809 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040027/0934 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 035103 FRAME 0536 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.
Reel/Frame 040016/0864 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035104/0043 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035103/0809 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 26, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035103/0536 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2014
From: RUSTAD, JOSEPH; WANG, XIANGRUI; JACKSON, PHILIP
To: DELL SOFTWARE INC.
Reel/Frame 034475/0795 →