IP Library Granted Patent US 11,164,090
Granted Patent B1
US 11,164,090 · App. 14/925,903 · Granted Nov 2, 2021

Time-based aggregation to feed a rete engine

Inventor: Laurent Pautet (Miribel, FR)
Assignee: TIBCO SOFTWARE INC.
G06N5/025G06F9/542
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,164,090
App. No.
14/925,903
Filed
Oct 28, 2015
Granted
Nov 2, 2021
Kind
B1
Art Unit
2125
USPC
706/47
Abstract

Techniques to correlate event data are disclosed. In various embodiments, an aggregation engine is used to correlate event data received from one or more source systems based on one or more correlation rules. An event group comprising at least a portion of said correlated event data is generated programmatically and is asserted as a fact in a working memory of a Rete engine configured to apply one or more Rete rules to facts in the working memory.

Claims (61)

1. A computer-implemented method of correlating streaming event data, comprising:

receiving event data from one or more source systems;

executing, using an aggregation engine, at least one aggregation policy programmatically based on one or more predefined correlation rules to:

generate event groups;

associate the event data with event groups, two or more events associated with an event group based on the one or more aggregation policies;

link a plurality of event data with a plurality of event groups based on the one or more aggregation policies;

create a temporary data structure for each event group;

populate the temporary data structure for each event group with event data, creating linked temporary data structures;

determine if the one or more aggregation policies are satisfied;

store the plurality of event groups as facts in a working memory of a Rete engine;

applying, using the Rete engine, Rete rules to the facts in the working memory, the Rete rules derived, at least in part, using the predefined correlation rules;

dynamically updating at least one selected from a group comprising the temporary data structure and the event groups in working memory based on a subsequently received event data;

wherein the predefined correlation rules comprises: at least one grouping clause, and at least one correlation constraint, at least one filtering clause, and at least one having clause;

wherein the at least one correlation constraint comprises a join constraint, sequencing constraint, and a free form constraint.

2. The method of claim 1 , wherein each of said source systems is configured to generate and provide to the aggregation engine discrete event data associated with that source system.

3. The method of claim 1 , wherein said source systems comprise an installed base of systems and said event data comprises system log data.

4. The method of claim 1 , wherein said correlation rules comprise user-defined rules.

5. The method of claim 1 , further comprising deriving one or more aggregation policies programmatically based at least in part on said correlation rules.

6. The method of claim 1 , wherein the event groups comprise a first event group and further comprising merging the first event group with a second event group.

7. The method of claim 6 , wherein the first event group is merged with the second event group based at least in part on a determination that a merger criterion is satisfied and the merger criterion is based on user-defined rules, wherein the first event group and the second event group are instantiated.

8. The method of claim 1 , wherein the aggregation engine is configured to extract one or more key-value pairs from a received event and to discard at least an unused portion of the received event.

9. The method of claim 1 , wherein the aggregation engine is configured to ignore and discard a received event that is determined to not be associated with an applicable correlation rule.

10. The method of claim 1 , wherein the aggregation engine is configured to associate a timestamp with an instance of received event data and to use the timestamp to apply one or more of said correlation rules, wherein the timestamp is used to determine how long to keep event data and/or to reorder events received out of order based on a rolling window size specified in applicable correlation rules.

11. The method of claim 10 , wherein the timestamp is used to implement a sliding window associated with one or more of said correlation rules.

12. The method of claim 1 , wherein a change in at least one rule of the Rete rules causes a change to at least one event group.

13. A system to correlate streaming event data, comprising:

a communication interface; and

a processor coupled to the communication interface and configured to:

receive event data from one or more source systems;

execute at least one aggregation policy programmatically based on one or more predefined correlation rules to:

generate event groups;

associate the event data with event groups, two or more events associated with an event group based on the one or more aggregation policies;

link a plurality of event data with a plurality of event groups based on the one or more aggregation policies;

create a temporary data structure for each event group;

populate the temporary data structure for each event group with event data, creating linked temporary data structures;

determine if the one or more aggregation policies are satisfied;

store the plurality of event groups as facts in a working memory of a Rete engine;

applying, using the Rete engine, Rete rules to the facts in the working memory, the Rete rules derived, at least in part, using the predefined correlation rules;

updating at least one selected from a group comprising the temporary data structure and the event groups in working memory based on a subsequently received event data;

wherein the predefined correlation rules comprises: at least one grouping clause, and at least one correlation constraint, at least one filtering clause, and at least one having clause;

wherein the at least one correlation constraint comprises a join constraint, sequencing constraint, and a free form constraint.

14. The system of claim 13 , wherein said correlation rules comprise user-defined rules.

15. The system of claim 13 , wherein the event groups comprise a first event group and further comprising merging the first event group with a second event group.

16. The system of claim 13 , wherein the processor is configured to extract one or more key-value pairs from a received event and to discard at least an unused portion of the received event.

17. The system of claim 13 , wherein the processor is configured to ignore and discard a received event that is determined to not be associated with an applicable correlation rule.

18. The system of claim 13 , wherein a change in at least one rule of the Rete rules causes a change to at least one event group.

19. A computer program product to correlate streaming event data, the computer program product being embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving event data from one or more source systems;

executing at least one aggregation policy programmatically based on one or more predefined correlation rules to:

generate event groups;

associate the event data with event groups, two or more events associated with an event group based on the one or more aggregation policies;

link a plurality of event data with a plurality of event groups based on the one or more aggregation policies;

create a temporary data structure for each event;

populate the temporary data structure for each event group with event data, creating linked temporary data structures;

determine if the one or more aggregation policies are satisfied;

store the plurality of event groups as facts in a working memory of a Rete engine;

applying, using the Rete engine, Rete rules to the facts in the working memory, the Rete rules derived, at least in part, using the predefined correlation rules;

dynamically updating at least one selected from a group comprising the temporary data structure and the event groups in working memory based on a subsequently received event data;

wherein the predefined correlation rules comprises: at least one grouping clause, and at least one correlation constraint, at least one filtering clause, and at least one having clause;

wherein the at least one correlation constraint comprises a loin constraint, sequencing constraint, and a free form constraint.

20. The computer program product of claim 19 , wherein a change in at least one rule of the Rete rules causes a change to at least one event group.

Assignments (18)
CHANGE OF NAME Recorded Jul 1, 2026
From: CLOUD SOFTWARE GROUP, INC.
To: CLOUD SOFTWARE GROUP, LLC
Reel/Frame 075874/0220 →
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
CHANGE OF NAME Recorded Feb 7, 2023
From: TIBCO SOFTWARE INC.
To: CLOUD SOFTWARE GROUP, INC.
Reel/Frame 062714/0634 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
RELEASE REEL 052115 / FRAME 0318 Recorded Oct 3, 2022
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: TIBCO SOFTWARE INC.
Reel/Frame 061588/0511 →
RELEASE (REEL 038382 / FRAME 0242) Recorded Sep 30, 2022
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 061575/0018 →
RELEASE (REEL 052096 / FRAME 0061) Recorded Sep 30, 2022
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 061575/0900 →
RELEASE (REEL 054275 / FRAME 0975) Recorded May 7, 2021
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 056176/0398 →
SECURITY AGREEMENT Recorded Nov 2, 2020
From: TIBCO SOFTWARE INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 054275/0975 →
SECURITY AGREEMENT Recorded Mar 6, 2020
From: TIBCO SOFTWARE INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 052115/0318 →
SECURITY AGREEMENT Recorded Mar 5, 2020
From: TIBCO SOFTWARE INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 052096/0061 →
SECURITY AGREEMENT Recorded Apr 7, 2016
From: TIBCO SOFTWARE INC., AS PLEDGOR
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 038382/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2016
From: PAUTET, LAURENT
To: TIBCO SOFTWARE INC.
Reel/Frame 037434/0564 →
Continuity (1)
Provisional Application 62073231 · Oct 31, 2014