IP Library Granted Patent US 11,151,014
Granted Patent B2
US 11,151,014 · App. 16/038,370 · Granted Oct 19, 2021

System operational analytics using additional features for health score computation

Inventors: Shiri Gaber (Beer Sheva, IL); Omer Sagi (Mazkeret Batya, IL); Amihai Savir (Sansana, IL); Ohad Arnon (Beit Nir, IL)
Assignee: EMC IP Holding Company LLC
G06F11/3476G06F11/3006G06F17/15G06N20/00H04L67/1002
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,151,014
App. No.
16/038,370
Granted
Oct 19, 2021
Kind
B2
Abstract

Techniques are provided for system operational analytics using additional features over time-series counters for health score computation. An exemplary method comprises: obtaining log data from data sources of a monitored system; applying a counting function to the log data to obtain time-series counters for a plurality of distinct features within the log data; applying an additional function to the time-series counters for the plurality of distinct features; and processing an output of the additional function using a machine learning model to obtain a health score for the monitored system based on the output of the additional function. The additional function comprises, for example, an entropy function representing a load balancing of a plurality of devices in the monitored system; one or more clustered counts for a plurality of entities in the monitored system; a number of unique values; and/or one or more modeled operations based on correlations between a plurality of different operations in the monitored system.

Claims (37)

1. A method, comprising:

obtaining log data from one or more data sources associated with a monitored system;

applying at least one counting function to said log data to obtain a plurality of time-series counters for a plurality of distinct features within the log data;

applying, using at least one processing device, at least one additional function to at least two of said plurality of time-series counters for the plurality of distinct features to generate an output of the at least one additional function, wherein the output of the at least one additional function is indicative of one or more of a failure and a degradation in performance of the monitored system;

applying, using the at least one processing device, the output of the at least one additional function to at least one machine learning model that generates a health score for said monitored system based on said output of the at least one additional function; and

detecting an anomaly in the monitored system based on said health score.

2. The method of claim 1 , wherein the one or more data sources comprise one or more of a monitoring log and a monitoring sensor.

3. The method of claim 1 , wherein the time-series counters are substantially continuous signals.

4. The method of claim 1 , wherein the at least one additional function comprises an entropy function representing a load balancing of a plurality of devices in the monitored system.

5. The method of claim 1 , wherein the at least one additional function comprises one or more clustered counts for a plurality of entities in the monitored system.

6. The method of claim 1 , wherein the at least one additional function comprises a number of unique values.

7. The method of claim 1 , wherein the at least one additional function comprises one or more modeled operations based on correlations between a plurality of different operations in the monitored system.

8. The method of claim 1 , wherein the log data is obtained from a plurality of layers of the monitored system.

9. The method of claim 1 , wherein the at least one additional function is selected from an engineered function set comprising two or more of: an entropy function, a clustered counts function for a plurality of entities, a number of unique values function, and one or more modeled operations functions based on correlations between a plurality of different operations.

10. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

obtaining log data from one or more data sources associated with a monitored system;

applying at least one counting function to said log data to obtain a plurality of time-series counters for a plurality of distinct features within the log data;

applying, using at least one processing device, at least one additional function to at least two of said plurality of time-series counters for the plurality of distinct features to generate an output of the at least one additional function, wherein the output of the at least one additional function is indicative of one or more of a failure and a degradation in performance of the monitored system;

applying, using the at least one processing device, the output of the at least one additional function to at least one machine learning model that generates a health score for said monitored system based on said output of the at least one additional function; and

detecting an anomaly in the monitored system based on said health score.

11. The system of claim 10 , wherein the at least one additional function comprises an entropy function representing a load balancing of a plurality of devices in the monitored system.

12. The system of claim 10 , wherein the at least one additional function comprises one or more clustered counts for a plurality of entities in the monitored system.

13. The system of claim 10 , wherein the at least one additional function comprises a number of unique values.

14. The system of claim 10 , wherein the at least one additional function comprises one or more modeled operations based on correlations between a plurality of different operations in the monitored system.

15. A computer program product, comprising a non-transitory machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

obtaining log data from one or more data sources associated with a monitored system;

applying at least one counting function to said log data to obtain a plurality of time-series counters for a plurality of distinct features within the log data;

applying, using at least one processing device, at least one additional function to at least two of said plurality of time-series counters for the plurality of distinct features to generate an output of the at least one additional function, wherein the output of the at least one additional function is indicative of one or more of a failure and a degradation in performance of the monitored system;

applying, using the at least one processing device, the output of the at least one additional function to at least one machine learning model that generates a health score for said monitored system based on said output of the at least one additional function; and

detecting an anomaly in the monitored system based on said health score.

16. The computer program product of claim 15 , wherein the at least one additional function comprises an entropy function representing a load balancing of a plurality of devices in the monitored system.

17. The computer program product of claim 15 , wherein the at least one additional function comprises one or more clustered counts for a plurality of entities in the monitored system.

18. The computer program product of claim 15 , wherein the at least one additional function comprises a number of unique values.

19. The computer program product of claim 15 , wherein the at least one additional function comprises one or more modeled operations based on correlations between a plurality of different operations in the monitored system.

20. The computer program product of claim 15 , wherein the at least one additional function is selected from an engineered function set comprising two or more of: an entropy function, a clustered counts function for a plurality of entities, a number of unique values function, and one or more modeled operations functions based on correlations between a plurality of different operations.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2019
From: GOLFZON NEWDIN HOLDINGS CO., LTD.
To: NEWDIN CONTENTS CO., LTD.
Reel/Frame 047896/0430 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2018
From: GABER, SHIRI; SAGI, OMER; SAVIR, AMIHAI; ARNON, OHAD
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046381/0142 →