IP Library Granted Patent US 11,126,533
Granted Patent B2
US 11,126,533 · App. 16/008,968 · Granted Sep 21, 2021

Temporal analysis of a computing environment using event data and component relationship data

Inventors: Christopher Knowles (London, CA); Blair Doyle (Hamilton, CA); Alex Bewley (Toronto, CA); Jimmy Park (London, CA)
Assignee: VMware, Inc.
G06F11/3495G06F3/0482G06F3/04847G06F9/45558G06F11/301G06F11/3006G06F11/3051G06F16/26G06F16/288G06F16/9024H04L41/064H04L41/065H04L41/0645H04L41/0686H04L41/12H04L41/145H04L41/16H04L43/045G06F2009/45562G06F2009/45591G06F2009/45595H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,126,533
App. No.
16/008,968
Granted
Sep 21, 2021
Kind
B2
Abstract

In a computer-implemented method for temporal analysis of a computing environment using event data and managed component relationship data, a temporal topology graph of a computing environment including a plurality of managed components is accessed at a service provider, wherein the temporal topology graph includes managed component relationship data, wherein the service provider is remote to the computing environment. Event data for the plurality of managed components of the computing environment is received. Anomaly detection of the computing environment is performed based on the event data and the temporal topology graph of the computing environment, where an anomaly is indicative of a non-ideal state of the computing environment.

Claims (65)

1. A computer-implemented method for temporal analysis of a computing environment using event data and managed component relationship data, the method comprising:

receiving, at a service provider, managed component relationship data for a plurality of managed components of a computing environment, the managed component relationship data comprising parent/child information for a managed component of the plurality of managed components at a moment in time, wherein the managed component relationship data is generated at each managed component of the plurality of managed components and is communicated from the plurality of managed components to the service provider;

transforming, by the service provider, the managed component relationship data into graphical data of a temporal topology graph of the computing environment, wherein the temporal topology graph includes the moment in time for each instance of the managed component relationship data within the temporal topology graph;

generating, by the service provider, the temporal topology graph of the computing environment;

receiving event data for the plurality of managed components of the computing environment; and

performing anomaly detection of the computing environment based on the event data and the temporal topology graph of the computing environment, where an anomaly is indicative of a non-ideal state of the computing environment.

2. The computer-implemented method of claim 1 , further comprising:

identifying at least one ameliorative action to apply to the computing environment for correcting the anomaly.

3. The computer-implemented method of claim 2 , further comprising:

correlating the event data to the temporal topology graph; and

identifying an instance of the event data causing a change in topology of the computing environment.

4. The computer-implemented method of claim 3 , wherein the identifying the at least one ameliorative action to apply to the computing environment for correcting the anomaly comprises:

utilizing the instance of the event data causing a change in topology of the computing environment to identify the ameliorative action.

5. The computer-implemented method of claim 2 , further comprising:

effectuating application of the at least one ameliorative action to the computing environment.

6. The computer-implemented method of claim 5 , wherein the effectuating the application of the at least one ameliorative action to the computing environment comprises:

communicating the ameliorative action to an administrator of the computing environment.

7. The computer-implemented method of claim 5 , wherein the effectuating the application of the at least one ameliorative action to the computing environment comprises:

automatically applying the ameliorative action to the computing environment.

8. The computer-implemented method of claim 1 , wherein the computing environment is a datacenter and the plurality of managed components comprises hardware components and virtual components of the datacenter.

9. The computer-implemented method of claim 1 , wherein the performing the anomaly detection of the plurality of managed components comprises:

accessing analytics for other computing environments; and

performing the anomaly detection of the computing environment utilizing the analytics for other computing environments.

10. The computer-implemented method of claim 1 , wherein the performing the anomaly detection of the plurality of managed components comprises:

applying a plurality of rules to the temporal topology graph; and

identifying the anomaly based on the plurality of rules.

11. The computer-implemented method of claim 1 , wherein the performing the anomaly detection of the plurality of managed components comprises:

accessing a plurality of event patterns;

performing pattern matching on the event data by comparing a portion of the event data to the plurality of event patterns; and

identifying the anomaly based on the pattern matching.

12. The computer-implemented method of claim 11 , wherein the pattern matching is performed utilizing machine-learning.

13. A non-transitory computer readable storage medium having computer readable program code stored thereon for performing a method of temporal analysis of a computing environment using event data and managed component relationship data, the method comprising:

receiving, at a service provider, managed component relationship data for a plurality of managed components of a computing environment, the managed component relationship data comprising parent/child information for a managed component of the plurality of managed components at a moment in time, wherein the managed component relationship data is generated at each managed component of the plurality of managed components and is communicated from the plurality of managed components to the service provider;

transforming, by the service provider, the managed component relationship data into graphical data of a temporal topology graph of the computing environment, wherein the temporal topology graph includes the moment in time for each instance of the managed component relationship data within the temporal topology graph;

generating, by the service provider, the temporal topology graph of the computing environment;

receiving event data for the plurality of managed components of the computing environment;

performing anomaly detection of the computing environment based on the event data and the temporal topology graph of the computing environment, where an anomaly is indicative of a non-ideal state of the computing environment;

identifying at least one ameliorative action to apply to the computing environment for correcting the anomaly; and

effectuating application of the at least one ameliorative action to the computing environment.

14. The non-transitory computer readable storage medium of claim 13 , wherein the performing the anomaly detection of the plurality of managed components comprises:

accessing analytics for other computing environments; and

performing the anomaly detection of the computing environment utilizing the analytics for other computing environments.

15. The non-transitory computer readable storage medium of claim 13 , wherein the performing the anomaly detection of the plurality of managed components comprises:

applying a plurality of rules to the temporal topology graph; and

identifying the anomaly based on the plurality of rules.

16. The non-transitory computer readable storage medium of claim 13 , wherein the performing the anomaly detection of the plurality of managed components comprises:

accessing a plurality of event patterns;

performing pattern matching on the event data by comparing a portion of the event data to the plurality of event patterns; and

identifying the anomaly based on the pattern matching.

17. The non-transitory computer readable storage medium of claim 16 , wherein the pattern matching is performed utilizing machine-learning.

18. The non-transitory computer readable storage medium of claim 13 , the method further comprising:

correlating the event data to the temporal topology graph; and

identifying an instance of the event data causing a change in topology of the computing environment.

19. The non-transitory computer readable storage medium of claim 18 , wherein the identifying the at least one ameliorative action to apply to the computing environment for correcting the anomaly comprises:

utilizing the instance of the event data causing a change in topology of the computing environment to identify the ameliorative action.

20. A system for temporal analysis of a computing environment using event data and managed component relationship data, the system comprising:

a data storage unit; and

a processor communicatively coupled with the data storage unit, the processor configured to:

receive, at a service provider, managed component relationship data for a plurality of managed components of a computing environment, the managed component relationship data comprising parent/child information for a managed component of the plurality of managed components at a moment in time, wherein the managed component relationship data is generated at each managed component of the plurality of managed components and is communicated from the plurality of managed components to the service provider;

transform, by the service provider, the managed component relationship data into graphical data of a temporal topology graph of the computing environment, wherein the temporal topology graph includes the moment in time for each instance of the managed component relationship data within the temporal topology graph;

generate, by the service provider, the temporal topology graph of the computing environment;

receive event data for the plurality of managed components of the computing environment;

perform anomaly detection of the computing environment based on the event data and the temporal topology graph of the computing environment, where an anomaly is indicative of a non-ideal state of the computing environment;

identify at least one ameliorative action to apply to the computing environment for correcting the anomaly; and

effectuate application of the at least one ameliorative action to the computing environment.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2018
From: KNOWLES, CHRISTOPHER; DOYLE, BLAIR; BEWLEY, ALEX; PARK, JIMMY
To: VMWARE, INC.
Reel/Frame 046094/0495 →
Cited By (76)
US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897