IP Library Granted Patent US 11,086,919
Granted Patent B2
US 11,086,919 · App. 15/997,512 · Granted Aug 10, 2021

Service regression detection using real-time anomaly detection of log data

Inventors: Sriram Parthasarathy (Fremont, CA); Raghvendra Singh (Fremont, CA); Parnian Zargham (Santa Clara, CA); Rishikesh Singh (Sunnyvale, CA); Jyoti Bansal (San Francisco, CA)
Assignee: Harness Inc.
G06F16/355G06F11/3065G06F16/3347G06F40/284G06K9/6215G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,086,919
App. No.
15/997,512
Granted
Aug 10, 2021
Kind
B2
Abstract

The present system provides continuous delivery and service regression detection in real time based on log data. The log data is clustered based on textual and contextual similarity and can serve as an indicator for the behavior of a service or application. The clusters can be augmented with the frequency distribution of its occurrences bucketed at a temporal level. Collectively, the textual and contextual similarity clusters serve as a strong signature (e.g., learned representation) of the current service date and a strong indicator for predicting future behavior. Machine learning techniques are used to generate a signature from log data to represent the current state and predict the future behavior of the service at any instant in time.

Claims (32)

1. A method for automatically continuously deploying code changes, comprising:

receiving, by a manager application on a server, log data from a delegate on a remote machine, the delegate collecting log data from a node within an application that is currently executing, the log data including a first log data associated with a change in code within the node and a second log data;

generating a first learned representation for the received first log data and a second learned representation for the received second log data by the manager application, wherein each of the first learned representation and the second learned representation includes a textual learned representation and a contextual learned representation, the contextual learned representation associated with a context for the log data;

generating a first cluster from the first learned representation and a second cluster from the second learned representation during execution of the application that is executing;

generating a homogeneity score for the first cluster generated from the first learned representation and the second cluster generated from the second learned representation;

comparing, during execution of the application that is executing, the first learned representation to the second learned representation to identify unexpected events or unexpected frequencies, wherein comparing includes calculating a distance between the first and second learned representations, wherein the distance is determined based on the homogeneity score and a threshold; and

determining if the change in code is acceptable based on the comparison.

2. The method of claim 1 , further comprising generating tokens from the log data and computing vectors from token data, the first and second learned representation generated from the vectors.

3. The method of claim 1 , wherein the unexpected events include unexpected log events.

4. The method of claim 1 , wherein the unexpected frequencies include unexpected frequencies of log events.

5. The method of claim 1 , wherein the clusters of the first and second learned representations are created for real time processing.

6. A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for automatically continuously deploying code changes, the method comprising:

receiving log data from a delegate on a remote machine, the delegate collecting log data from a node within an application that is currently executing, the log data including a first log data associated with a change in code within the node and a second log data;

generating a first learned representation for the received first log data and a second learned representation for the received second log data;

generating a first cluster from the first learned representation and a second cluster from the second learned representation during execution of the application that is executing;

generating a homogeneity score for the first cluster generated from the first learned representation and the second cluster generated from the second learned representation;

comparing, during execution of the application that is executing, the first learned representation to the second learned representation to identify unexpected events or unexpected frequencies, wherein each of the first learned representation and the second learned representation includes a textual learned representation and a contextual learned representation, the contextual learned representation associated with a context for the log data, wherein comparing includes calculating a distance between the first and second learned representations wherein the distance is determined based on the homogeneity score and a threshold; and

determining if the change in code is acceptable based on the comparison.

7. The non-transitory computer readable storage medium of claim 6 , further comprising generating tokens from the log data and computing vectors from token data, the first and second learned representation generated from the vectors.

8. The non-transitory computer readable storage medium of claim 6 , wherein the unexpected events include unexpected log events.

9. The non-transitory computer readable storage medium of claim 6 , wherein the unexpected frequencies include unexpected frequencies of log events.

10. The non-transitory computer readable storage medium of claim 6 , wherein the first and second learned representations are created for real time processing.

11. The non-transitory computer readable storage medium of claim 6 , wherein calculating a distance includes comparing the clusters of the first and second learned representations.

12. A system for automatically continuously deploying code changes, comprising:

a server including a memory and a processor; and

one or more modules stored in the memory and executed by the processor to

receive, by a manager application on the server, log data from a delegate on a remote machine, the delegate collecting log data from a node within an application that is currently executing, the log data including a first log data associated with a change in code within the node and a second log data,

generate a first learned representation for the received first log data and a second learned representation for the received second log data by the manager application, wherein each of the first learned representation and the second learned representation includes a textual learned representation and a contextual learned representation, the contextual learned representation associated with a context for the log data,

generating a first cluster from the first learned representation and a second cluster from the second learned representation during execution of the application that is executing;

generating a homogeneity score for the first cluster generated from the first learned representation and the second cluster generated from the second learned representation;

compare, during execution of the application that is executing, the first learned representation to the second learned representation to identify unexpected events or unexpected frequencies, wherein comparing includes calculating a distance between the first and second learned representations, wherein the distance is determined based on the homogeneity score and a threshold, and

determine if the change in code is acceptable based on the comparison.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075690/0701 →
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075690/0915 →
SECURITY INTEREST Recorded Nov 24, 2024
From: HARNESS INC.; HARNESS INTERNATIONAL, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 069387/0805 →
SECURITY INTEREST Recorded Nov 24, 2024
From: HARNESS INC.; HARNESS INTERNATIONAL, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
Reel/Frame 069387/0816 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2019
From: PARTHASARATHY, SRIRAM; SINGH, RAGHVENDRA; ZARGHAM, PARNIAN; SINGH, RISHIKESH; BANSAL, JYOTI
To: HARNESS, INC.
Reel/Frame 048757/0984 →
Continuity (2)
Continuation In Part 15899232 · Feb 19, 2018
Related Publication 20190258725A1 · Aug 22, 2019
Cited By (1)
US 12,470,459