IP Library Granted Patent US 9,734,005
Granted Patent B2
US 9,734,005 · App. 14/867,656 · Granted Aug 15, 2017

Log analytics for problem diagnosis

Inventors: Yaoping Ruan (White Plains, NY); Byungchul Tak (Peekskill, NY); Shu Tao (Irvington, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F11/079G06F11/0709G06F11/2257G06N5/045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,734,005
App. No.
14/867,656
Granted
Aug 15, 2017
Kind
B2
Abstract

In a set of problem log entries from a computing system, a subset of the set of problem log entries are identified, which pertain to a failed request. The subset is compared to a reference model which defines log entries per request type under a healthy state of the computing system, to identify a portion of the subset of problem log entries which deviate from corresponding log entries in the reference model. In the portion of the subset, at least one high-value log entry is identified. The at least one high-value log entry is output.

Claims (35)

1. An apparatus comprising:

a memory; and

at least one processor, coupled to said memory, and operative to:

identify, in a set of problem log entries from a computing system, a subset of said set of problem log entries which pertain to a failed request;

compare said subset to a reference model which defines log entries per request type under a healthy state of said computing system, to identify a portion of said subset of problem log entries which deviate from corresponding log entries in said reference model;

identify, in said portion of said subset, at least one high-value log entry; and

output said at least one high-value log entry.

2. The apparatus of claim 1 , wherein said computing system comprises a plurality of components distributed in a cloud environment.

3. The apparatus of claim 2 , wherein:

said failed request has an associated identifier;

said at least one processor is operative to identify said subset by:

identifying into a correlated set those entries of said set of problem log entries containing said associated identifier; and

adding to said correlated set additional entries of said set of problem log entries, based on a rule set, to obtain said subset.

4. The apparatus of claim 3 , wherein said at least one processor is operative to compare by aligning individual lines of said subset with individual lines of said corresponding log entries in said reference model, and, where any given line cannot be matched, inserting an opposing blank log entry.

5. The apparatus of claim 4 , wherein said at least one processor is operative to identify said at least one high-value log entry based on rareness of a corresponding log template.

6. The apparatus of claim 5 , wherein said at least one processor is further operative to build said reference model.

7. The apparatus of claim 6 , wherein said at least one processor is operative to build said reference model by:

generating said rule set based on identifier name value pairs; and

applying said rule set in a log correlation process to obtain said log entries per request type under said healthy state of said computing system.

8. The apparatus of claim 1 , wherein:

said at least one processor is operative to identify said subset by executing a log correlation module, embodied in a non-transitory computer readable medium;

said at least one processor is operative to compare said subset to said reference model by executing a log comparison module, embodied in said non-transitory computer readable medium; and

said at least one processor is operative to identify said at least one high-value log entry by executing a visualization module, embodied in said non-transitory computer readable medium.

9. A non-transitory computer readable medium comprising computer executable instructions which when executed by a computer cause the computer to perform the method of:

identifying, in a set of problem log entries from a computing system, a subset of said set of problem log entries which pertain to a failed request;

comparing said subset to a reference model which defines log entries per request type under a healthy state of said computing system, to identify a portion of said subset of problem log entries which deviate from corresponding log entries in said reference model;

identifying, in said portion of said subset, at least one high-value log entry; and

outputting said at least one high-value log entry.

10. The non-transitory computer readable medium of claim 9 , wherein, in said subset-identifying step of said method, said computing system comprises a plurality of components distributed in a cloud environment.

11. The non-transitory computer readable medium of claim 10 , wherein:

said failed request has an associated identifier;

said identifying of said subset comprises:

identifying into a correlated set those entries of said set of problem log entries containing said associated identifier; and

adding to said correlated set additional entries of said set of problem log entries, based on a rule set, to obtain said subset.

12. The non-transitory computer readable medium of claim 11 , wherein said comparing comprises aligning individual lines of said subset with individual lines of said corresponding log entries in said reference model, and, where any given line cannot be matched, inserting an opposing blank log entry.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2015
From: RUAN, YAOPING; TAK, BYUNGCHUL; TAO, SHU
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 036671/0457 →
Continuity (2)
Provisional Application 62073443 · Oct 31, 2014
Related Publication 20160124823A1 · May 5, 2016