IP Library › Granted Patent US 10,212,023
Granted Patent B2
US 10,212,023 · App. 15/286,337 · Granted Feb 19, 2019

Methods and systems to identify and respond to low-priority event messages

Inventor: Darren Brown (Seattle, WA)
Assignee: VMware, Inc.
H04L41/0609H04L41/069H04L67/1097H04L67/36H04L41/22H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,212,023
App. No.
15/286,337
Granted
Feb 19, 2019
Kind
B2
Abstract

Methods and systems to identify and respond to low-priority event messages are described. Methods identify types of event messages recorded in event-log files as low-priority event messages. Methods enable an information technology (“IT”) administrator, or other user, to determine which low-priority event messages may be deleted, how the low-priority event messages may be sampled for storage, or how long the low-priority event messages may be stored in a data-storage device.

Claims (95)

1. A method to identify and respond to low-priority event messages, the method comprising:

identifying each event message of an event-log file as belonging to an event type;

identifying certain event types as low-priority event types;

deleting the event messages of each low-priority event type in accordance with a storage requirement assigned to each low-priority event type;

identifying candidate low-priority event types of the event types that have not been previously identified as low-priority event types;

displaying storage space of the event messages of each low-priority event type occupy in one or more data-storage devices; and

displaying options for changing how each of the low-priority event type is stored in the one or more data-storage devices.

2. The method of claim 1 , wherein identifying certain event types as low-priority event types comprises:

for each event type,

counting event messages of the event type over a time period to obtain a count of event messages of the event type;

counting user interactions with event messages of the event type over the time period to determine a number user interactions for the event type; and

identifying the event type as a low-priority event type and corresponding event messages as low priority when the count of event messages is less than or equal to a count threshold and the number of user interactions is greater than or equal to a number of interactions threshold.

3. The method of claim 1 , wherein identifying certain event types as low-priority event types comprises identifying an event type as a low-priority event type and corresponding event messages as low priority, when a user identifies the event type as low priority.

4. The method of claim 1 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

identifying event messages of the low-priority event type for deletion, when the low-priority event type is selected for deletion; and

deleting the event message of the low-priority event type selected for deletion.

5. The method of claim 1 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

receiving a percentage of event messages to store in an event-log file;

for each event message,

generating a random number between zero and one;

storing the event message in an event-log file when the random number is less the percentage multiplied by one hundred; and

deleting the event message when the random number is greater than the percentage multiplied by one hundred.

6. The method of claim 1 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

receiving a retention time for storing the event message in an event-log file;

for each event message, deleting the event message form the event-log file when the difference between a current time stamp and a time stamp of the event message is greater than the retention time.

7. The method of claim 1 , wherein identifying the candidate low-priority event types of the event types comprises:

calculating an amount of storage occupied by event messages of an event type;

determining total storage for an event-log file that stores event messages of the event type;

calculating storage of the event-log file without the event type as a different between the total storage of the event-log file and the amount of storage occupied by the event message;

displaying the event type as the candidate low-priority event type, the amount of storage occupied by event messages of the event type, the total storage for the event-log file that stores event messages of the event type, storage of the event-log file without the event type; and

changing status of the event type to a low-priority event type when a user selects an option to change the status of the event type.

8. A system to identify and respond to low-priority event messages, the system comprising:

one or more processors;

one or more data-storage devices; and

machine-readable instructions stored in the one or more data-storage devices that when executed using the one or more processors controls the system to carry out identifying each event message of an event-log file as belonging to an event type;

identifying certain event types as low-priority event types;

deleting the event messages of each low-priority event type in accordance with a storage requirement assigned to each low-priority event type;

identifying candidate low-priority event types of the event types that have not been previously identified as low-priority event types;

displaying storage space of the event messages of each low-priority event type occupy in one or more data-storage devices; and

displaying options for changing how each of the low-priority event type is stored in the one or more data-storage devices.

9. The system of claim 1 , wherein identifying certain event types as low-priority event types comprises:

for each event type,

counting event messages of the event type over a time period to obtain a count of event messages of the event type;

counting user interactions with event messages of the event type over the time period to determine a number user interactions for the event type; and

identifying the event type as a low-priority event type and corresponding event messages as low priority when the count of event messages is less than or equal to a count threshold and the number of user interactions is greater than or equal to a number of interactions threshold.

10. The system of claim 1 , wherein identifying certain event types as low-priority event types comprises identifying an event type as a low-priority event type and corresponding event messages as low priority, when a user identifies the event type as low priority.

11. The system of claim 1 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

identifying event messages of the low-priority event type for deletion, when the low-priority event type is selected for deletion; and

deleting the event message of the low-priority event type selected for deletion.

12. The system of claim 1 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

receiving a percentage of event messages to store in an event-log file;

for each event message,

generating a random number between zero and one;

storing the event message in an event-log file when the random number is less the percentage multiplied by one hundred; and

deleting the event message when the random number is greater than the percentage multiplied by one hundred.

13. The system of claim 1 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

receiving a retention time for storing the event message in an event-log file;

for each event message, deleting the event message form the event-log file when the difference between a current time stamp and a time stamp of the event message is greater than the retention time.

14. The system of claim 1 , wherein identifying the candidate low-priority event types of the event types comprises:

calculating an amount of storage occupied by event messages of an event type;

determining total storage for an event-log file that stores event messages of the event type;

calculating storage of the event-log file without the event type as a different between the total storage of the event-log file and the amount of storage occupied by the event message;

displaying the event type as the candidate low-priority event type, the amount of storage occupied by event messages of the event type, the total storage for the event-log file that stores event messages of the event type, storage of the event-log file without the event type; and

changing status of the event type to a low-priority event type when a user selects an option to change the status of the event type.

15. A non-transitory computer-readable medium encoded with machine-readable instructions that implement a method carried out by one or more processors of a computer system to perform the operations of

identifying each event message of an event-log file as belonging to an event type;

identifying certain event types as low-priority event types;

deleting the event messages of each low-priority event type in accordance with a storage requirement assigned to each low-priority event type;

identifying candidate low-priority event types of the event types that have not been previously identified as low-priority event types;

displaying storage space of the event messages of each low-priority event type occupy in one or more data-storage devices; and

displaying options for changing how each of the low-priority event type is stored in the one or more data-storage devices.

16. The medium of claim 15 , wherein identifying certain event types as low-priority event types comprises:

for each event type,

counting event messages of the event type over a time period to obtain a count of event messages of the event type;

counting user interactions with event messages of the event type over the time period to determine a number user interactions for the event type; and

identifying the event type as a low-priority event type and corresponding event messages as low priority when the count of event messages is less than or equal to a count threshold and the number of user interactions is greater than or equal to a number of interactions threshold.

17. The medium of claim 15 , wherein identifying certain event types as low-priority event types comprises identifying an event type as a low-priority event type and corresponding event messages as low priority, when a user identifies the event type as low priority.

18. The medium of claim 15 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

identifying event messages of the low-priority event type for deletion, when the low-priority event type is selected for deletion; and

deleting the event message of the low-priority event type selected for deletion.

19. The medium of claim 15 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

receiving a percentage of event messages to store in an event-log file;

for each event message,

generating a random number between zero and one;

storing the event message in an event-log file when the random number is less the percentage multiplied by one hundred; and

deleting the event message when the random number is greater than the percentage multiplied by one hundred.

20. The medium of claim 15 , wherein deleting the event messages of each low-priority event type in accordance with the storage requirement comprises:

receiving a retention time for storing the event message in an event-log file;

for each event message, deleting the event message form the event-log file when the difference between a current time stamp and a time stamp of the event message is greater than the retention time.

21. The medium of claim 15 , wherein identifying the candidate low-priority event types of the event types comprises:

calculating an amount of storage occupied by event messages of an event type;

determining total storage for an event-log file that stores event messages of the event type;

calculating storage of the event-log file without the event type as a different between the total storage of the event-log file and the amount of storage occupied by the event message;

displaying the event type as the candidate low-priority event type, the amount of storage occupied by event messages of the event type, the total storage for the event-log file that stores event messages of the event type, storage of the event-log file without the event type; and

changing status of the event type to a low-priority event type when a user selects an option to change the status of the event type.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2016
From: BROWN, DARREN
To: VMWARE, INC.
Reel/Frame 039949/0146 →
Continuity (1)
Related Publication 20180097687A1 · Apr 5, 2018