IP Library Granted Patent US 10,169,122
Granted Patent B2
US 10,169,122 · App. 15/382,988 · Granted Jan 1, 2019

Methods for decomposing events from managed infrastructures

Inventors: Philip Tee (San Francisco, CA); Robert Duncan Harper (London, GB); Charles Mike Silvey (San Francisco, CA)
Assignee: Moogsoft, Inc.
G06F11/0709G06F11/079G06F11/0751G06F11/0772G06F11/0778G06F11/0793G06F11/30G06F17/30598G06F17/30958H04L41/065H04L41/0883H04L41/22H04L51/16H04L67/22H04L69/40H04L41/046H04L43/0817H04L43/0823H04L67/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,169,122
App. No.
15/382,988
Granted
Jan 1, 2019
Kind
B2
Abstract

A system for clustering events includes a first engine that receives message data from a managed infrastructure which includes managed infrastructure physical hardware and supports the flow and processing of information. A second engine determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. Events are produced that relate to the managed infrastructure while converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware. The second engine or a third engines uses a source address for each event to assign a graph coordinate to each of an event and making a change to at least a portion of the managed infrastructure.

Claims (49)

1. A system for clustering events, comprising:

a first engine that receives message data from a managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information;

a second engine that determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information, and producing events that relate to the managed infrastructure while converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware;

a compare and merge engine that receives outputs from the second engine, the compare and merge engine communicating with one or more user interfaces in a situation room; and

wherein the second engine or a third engines uses a source address for each event make a change to at least a portion of the managed infrastructure, and in response to producing events that relate to the managed infrastructure while converting the events into words and subsets physical changes are made to managed infrastructure physical hardware.

2. The system of claim 1 , wherein the first engine is an extraction engine.

3. The system of claim 2 , wherein the first engine in operation receives messages from the managed infrastructure.

4. The system of claim 3 , wherein the first engine in operation produces events that relate to the managed infrastructure.

5. The system of claim 4 , wherein the events are converted into words and subsets used to group the events into clusters that relate to failures or errors in the managed infrastructure.

6. The system of claim 1 , wherein the second engine is a signalizer engine.

7. The system of claim 1 , wherein the second engine is configured to determine one or more common characteristics of events and produces clusters relating to events.

8. The system of claim 1 , wherein the managed infrastructure is from a business organization.

9. The system of claim 8 , wherein the managed infrastructure includes, computers, network devices, appliances, mobile devices, text or numerical values from which those text or numerical values indicate a state of any hardware or software component of the managed infrastructure.

10. The system of claim 9 , wherein the managed infrastructure generates data that include attributes selected from at least one of, time, source a description of the event, textural or numerical values from which those text or numerical values indicate a state of any hardware or software component of the managed infrastructure.

11. The system of claim 1 , further comprising:

a publication message bus.

12. The system of claim 1 , further comprising:

a data bus web server coupled to one or more user interfaces.

13. The system of claim 1 , wherein a plurality of link access modules are in communication with a data bus.

14. The system of claim 1 , further comprising:

a database.

15. The system of claim 1 , wherein the extraction engine reformats data from the events to create reformatted data.

16. The system of claim 15 , wherein the reformatted data is received at The system bus.

17. A system for clustering events, comprising:

a first engine that receives message data from a managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information;

a second engine that determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information, and producing events that relate to the managed infrastructure while converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware; and

wherein the second engine or a third engine uses a source address for each event make a change to at least a portion of the managed infrastructure, and

the second engine includes one or more of an Non-negative Matrix Factorization NMF engine, a k-means clustering engine and a topology proximity engine; and

in response to producing events that relate to the managed infrastructure while converting the events into words and subsets physical changes are made to managed infrastructure physical hardware.

18. A system for clustering events, comprising:

a first engine that receives message data from a managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information;

a second engine that determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information, and producing events that relate to the managed infrastructure while converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware;

a third engine coupled to the first and second engines, the second engine or third engines use a source address for each event make a change to at least a portion of the managed infrastructure, the third engine assigning a graph coordinate to the event; and

wherein an optional subset of attributes is extracted for each event and turned into a vector; and

in response to producing events that relate to the managed infrastructure while converting the events into words and subsets physical changes are made to managed infrastructure physical hardware.

19. The system of claim 18 , wherein the third engine inputs a list of devices and a list a connections between components or nodes in the managed infrastructure.

20. The system of claim 18 , wherein the second engine includes or is coupled to a k-means clustering engine that user graph coordinates to generate one or more clusters that brings together events with similar characteristics.

21. The system of claim 18 , wherein the second engine includes or is coupled to an NMF engine that first extracts clusters that have greater importance.

22. The system of claim 21 , wherein the clusters are assign a start and an end time.

23. A system for clustering events, comprising:

a first engine that receives message data from a managed infrastructure that includes managed infrastructure physical hardware which supports the flow and processing of information;

a second engine that determines common characteristics of events and produces clusters of events relating to the failure of errors in the managed infrastructure, where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information, and producing events that relate to the managed infrastructure while converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware and;

wherein the second engine or a third engine uses a source address for each event make a change to at least a portion of the managed infrastructures;

wherein a dictionary is generated with word and subtexts using Shannon Entropy, −In(1/NGen) and normalizes the words and subtexts; and

in response to producing events that relate to the managed infrastructure while converting the events into words and subsets physical changes are made to managed infrastructure physical hardware.

24. The system of claim 23 , wherein normalized words and subtexts are mapped from a common 0.0 to a non-common 1.0.

25. The system of claim 23 , further comprising:

an entropy database that in operation normalizes entropy for events.

26. The system of claim 25 , wherein normalized entropy for events is mapped to a common, 0.0 and a non-common, 1.0.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: EMC CORPORATION
To: DELL PRODUCTS L.P.
Reel/Frame 065179/0980 →
MERGER Recorded Oct 4, 2023
From: MOOGSOFT INC.
To: EMC CORPORATION
Reel/Frame 065156/0805 →
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: STIFEL BANK
To: MOOGSOFT INC.
Reel/Frame 064569/0391 →
SECURITY INTEREST Recorded Jan 23, 2022
From: MOOGSOFT INC.
To: STIFEL BANK
Reel/Frame 058734/0193 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2018
From: TEE, PHILIP; SILVEY, CHARLES MIKE; HARPER, ROBERT DUNCAN
To: MOOGSOFT, INC.
Reel/Frame 047585/0754 →
Continuity (4)
Continuation 15350950 · Nov 14, 2016
Continuation 14262890 · Apr 28, 2014
Provisional Application 61816867 · Apr 29, 2013
Related Publication 20170161132A1 · Jun 8, 2017