IP Library Granted Patent US 10,474,520
Granted Patent B2
US 10,474,520 · App. 15/350,950 · Granted Nov 12, 2019

Methods for decomposing events from managed infrastructures

Inventors: Philip Tee (San Francisco, CA); Robert Duncan Harper (London, GB); Charles Mike Silvey (San Francisco, CA)
Assignee: Moogsoft, Inc.
G06F11/079G06F11/0709G06F11/0751G06F11/0778G06F11/30G06F16/285G06F16/9024H04L41/06H04L41/0631H04L43/045H04L43/0823H04L51/063H04L67/36H04L41/046H04L41/0893H04L41/12H04L43/0817
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,474,520
App. No.
15/350,950
Granted
Nov 12, 2019
Kind
B2
Abstract

A method is provided for clustering events. Messages are received at an extraction engine from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information. Events are produced that relate to the managed infrastructure. The events are converted into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware. One or more common characteristics of events are determined and clusters of events are produced relating to the failure or errors in the managed infrastructure. A source address is used for each event as is a graph topology of the managed infrastructure to assign a graph coordinate to the event. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. In response to production of the clusters one or more physical changes are made in the managed infrastructure hardware.

Claims (22)

1. A method for clustering events, comprising:

receiving messages at an extraction engine from a managed infrastructure that includes physical hardware managed infrastructure that supports infrastructure data;

providing a text input module coupled to the extraction engine;

producing events that relate to the managed infrastructure and converting the events into a sequence of attributes that have text or numerical values indicative of a state of a hardware component;

using the extraction engine to extract text or numerical values from event messages and convert them into words and subtexts

determining one or more common steps to ascertain how many clusters to extract from events, where membership in a cluster indicates a common factor that can be a failure or an actionable problem in the managed infrastructure, where membership in a cluster indicates a common set of attributes of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to infrastructure data, in response to production of the clusters of events one or more physical changes in a managed infrastructure hardware is made;

using a source address for each event and a graph topology of the managed infrastructure to assign a graph coordinate to the event when a graph topology is executed.

2. The method of claim 1 , wherein the managed infrastructure is from a business organization.

3. The method of claim 1 , wherein the managed infrastructure includes, computers, network devices, appliances, mobile devices, text or numerical values from which those text or numerical values indicate a state of any hardware or software component of the managed infrastructure.

4. The method of claim 1 , further comprising: a publication message bus.

5. The method of claim 1 , further comprising: a data bus web server coupled to one or more user interfaces.

6. The method of claim 1 , wherein a plurality of link access modules are in communication with a data bus.

7. The method of claim 1 , further comprising: a database.

8. The method of claim 1 , wherein a dictionary is generated with the word and subtexts using Shannon Entropy, −ln(1/NGen) and normalizes the words and subtexts.

9. The method of claim 8 , wherein normalized words and subtexts are mapped from a common 0.0 to a non-common 1.0.

10. The method of claim 1 , further comprising: an entropy database that in operation normalizes entropy for events.

11. The method of claim 10 , wherein normalized entropy for events is mapped to a common, 0.0 and a non-common, 1.0.

12. The method of claim 1 , wherein entropy is assigned to alerts.

13. The method of claim 12 , wherein the alerts are passed to a sigalizer engine.

14. The method of claim 13 , wherein the sigalizer engine generates clusters of alerts.

15. The method of claim 1 , further comprising: determining hop and a proximity of the source of the event.

16. The method of claim 1 , further comprising: calculating one or more distances between tile vectors.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: EMC CORPORATION
To: DELL PRODUCTS L.P.
Reel/Frame 065179/0980 →
MERGER Recorded Oct 4, 2023
From: MOOGSOFT INC.
To: EMC CORPORATION
Reel/Frame 065156/0805 →
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: STIFEL BANK
To: MOOGSOFT INC.
Reel/Frame 064569/0391 →
SECURITY INTEREST Recorded Jan 23, 2022
From: MOOGSOFT INC.
To: STIFEL BANK
Reel/Frame 058734/0193 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2020
From: TEE, PHILIP; HARPER, ROBERT DUNCAN; SILVEY, CHARLES MIKE
To: MOOGSOFT, INC.
Reel/Frame 051501/0708 →
Continuity (3)
Continuation 14262890 · Apr 28, 2014
Provisional Application 61816867 · Apr 29, 2013
Related Publication 20170060663A1 · Mar 2, 2017
Cited By (1)
US 12,511,186