IP Library › Granted Patent US 11,392,446
Granted Patent B2
US 11,392,446 · App. 16/355,042 · Granted Jul 19, 2022

Cross-correlation of metrics for anomaly root cause identification

Inventors: Maxwell Henry Poole (San Jose, CA); Satish Sambasivan (Cupertino, CA); Vivek Siva Kaushik (Pleasanton, CA)
Assignee: eBay Inc.
G06F11/0793G06F11/0706G06F11/079
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,392,446
App. No.
16/355,042
Granted
Jul 19, 2022
Kind
B2
Abstract

Technologies are disclosed herein for cross-correlating metrics for anomaly root cause detection. Primary and secondary metrics associated with an anomaly are cross-correlated by first using the derivative of an interpolant of data points of the primary metric to identify a time window for analysis. Impact scores for the secondary metrics can be then be generated by computing the standard deviation of a derivative of data points of the secondary metrics during the identified time window. The impact scores can be utilized to collect data relating to the secondary metrics most likely to have caused the anomaly. Remedial action can then be taken based upon the collected data in order to address the root cause of the anomaly.

Claims (51)

1. A computer-implemented method, comprising:

retrieving a primary dataset and a plurality of secondary datasets, the primary dataset comprising data points for a primary metric, and the plurality of secondary datasets comprising data points for a plurality of secondary metrics;

computing an interpolant for data points in the primary dataset;

identifying a time window by analyzing the interpolant for the primary dataset;

computing interpolants for data points in the time window for the plurality of secondary datasets;

computing an impact score for each of the plurality of secondary metrics by analyzing the interpolants for the plurality of secondary datasets;

collecting data based on the impact scores;

identifying a cause of an anomaly detected at a computing system based on the collected data; and

performing a remedial action for the anomaly detected at the computing system based on the cause, the remedial action including at least one of restoring, rebooting, reconfiguring, or initializing the computing system.

2. The computer-implemented method of claim 1 , wherein:

the interpolant for the primary dataset is computed by fitting a cubic polynomial through the data points for the primary metric; and

the interpolants for the plurality of secondary datasets are computed by fitting a cubic polynomial through the data points for the plurality of secondary metrics.

3. The computer-implemented method of claim 1 , wherein analyzing the interpolant for the primary dataset to identify the time window comprises evaluating roots of a derivative of the interpolant for the primary dataset to identify the time window.

4. The computer-implemented method of claim 1 , wherein the data points for the primary metric and the data points for the plurality of secondary metrics are collected during a time period corresponding to the anomaly detected at the computing system.

5. The computer-implemented method of claim 1 , wherein the impact score comprises a standard deviation of derivatives of the interpolants for the plurality of secondary metrics during the time window.

6. The computer-implemented method of claim 1 , wherein the primary metric and the plurality of secondary metrics comprise business metrics.

7. The computer-implemented method of claim 1 , wherein the primary metric and the plurality of secondary metrics comprise machine metrics.

8. The computer-implemented method of claim 1 , further comprising:

selecting secondary metrics of the plurality of secondary metrics based on the impact scores; and

collecting the data from data stores that correspond to the selected secondary metrics.

9. The computer-implemented method of claim 1 , further comprising:

receiving an indication of the anomaly at the computing system; and

retrieving the primary dataset and the plurality of secondary datasets based on the indication.

10. A computing system, comprising:

one or more processors; and

a computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by the one or more processors, cause the one or more processors to:

compute an interpolant for data points in a primary dataset, the primary dataset comprising data points for a first metric;

identify a time window based on a derivative of the interpolant;

compute interpolants for data points in the time window for a plurality of secondary datasets, the secondary datasets comprising data points for a plurality of second metrics;

compute impact scores for the plurality of second metrics based on the interpolants for the data points in the time window for the plurality of secondary datasets;

obtain data, the data being selected based upon the impact scores;

identifying a cause of an anomaly detected at the computing system based on the obtained data; and

perform a remedial action for the anomaly based on the cause, the remedial action including at least one of restoring, rebooting, reconfiguring, or initializing the computing system.

11. The computing system of claim 10 , wherein the interpolant for the data points in the primary dataset is computed by fitting a cubic polynomial through the data points for the first metric.

12. The computing system of claim 10 , wherein the interpolants for the data points in the time window for the plurality of secondary datasets are computed by fitting a cubic polynomial through the data points for the plurality of second metrics.

13. The computing system of claim 10 , wherein identifying the time window comprises evaluating roots of a derivative of the interpolant for the data points in the primary dataset to identify the time window.

14. The computing system of claim 10 , wherein the data points for the first metric and the data points for the plurality of second metrics are collected during a time period corresponding to the anomaly detected at the computing system.

15. The computing system of claim 10 , wherein the impact score comprises a standard deviation of derivatives of the interpolants for the plurality of second metrics during the time window.

16. The computing system of claim 10 , wherein the first metric and the plurality of second metrics comprise business metrics or machine metrics.

17. A computer-readable storage medium having computer-executable instructions stored thereupon which, when executed by a processor, cause the processor to:

retrieve a primary dataset and a plurality of secondary datasets, the primary dataset comprising data points for a primary metric, and the plurality of secondary datasets comprising data points for a plurality of secondary metrics;

compute an interpolant for data points in the primary dataset by fitting a cubic polynomial through the data points for the primary metric;

identify a time window by analyzing the interpolant for the primary dataset;

compute interpolants for data points in the time window for the plurality of secondary datasets by fitting a cubic polynomial through the data points for the plurality of secondary metrics;

compute an impact score for each of the plurality of secondary metrics by analyzing the interpolants for the plurality of secondary datasets;

collect data based on the impact scores;

identify a cause of an anomaly detected at a computing system based on the collected data; and

perform a remedial action for the anomaly detected at the computing system based on the cause, the remedial action including at least one of restoring, rebooting, reconfiguring, or initializing the computing system.

18. The computer-readable storage medium of claim 17 , wherein analyzing the interpolant for the primary dataset comprises evaluating roots of a derivative of the interpolant for the primary dataset.

19. The computer-readable storage medium of claim 17 , wherein the impact score comprises a standard deviation of derivatives of the interpolants for the plurality of secondary metrics during the time window.

20. The computer-readable storage medium of claim 17 , wherein the primary metric and the plurality of secondary metrics comprise business metrics or machine metrics.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2019
From: POOLE, MAXWELL HENRY; SAMBASIVAN, SATISH; KAUSHIK, VIVEK SIVA
To: EBAY INC.
Reel/Frame 048613/0499 →
Continuity (1)
Related Publication 20200293391A1 · Sep 17, 2020
Cited By (2)
US 12,189,466 US 12,675,359