IP Library Granted Patent US 11,755,588
Granted Patent B2
US 11,755,588 · App. 16/807,187 · Granted Sep 12, 2023

Real-time dashboards, alerts and analytics for a log intelligence system

Inventors: Karthik Seshadri (Bangalore, IN); Siddartha Laxman Karibhimanvar (Bangalore, IN); Ritesh Jha (Bangalore, IN); Radhakrishnan Devarajan (Bangalore, IN); Chaitanya Krishna Mullangi (Bangalore, IN)
Assignee: VMware, Inc.
G06F16/24568G06F16/2379G06F16/252G06F16/26G06F16/278
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,588
App. No.
16/807,187
Granted
Sep 12, 2023
Kind
B2
Abstract

This disclosure describes how data supporting real-time reporting services can be cached during a log intake process. In particular, instead of caching all the log data being generated by an operational system, only the log data relevant to existing queries associated with the real-time reporting services are cached. In some embodiments, only particular metrics contained within the log data are stored for rapid access by the real-time reporting services.

Claims (43)

1. A computer implemented method for displaying metrics associated with log data, the computer implemented method comprising:

receiving a first stream of log data being generated by an operational system;

forwarding a second stream of log data to a first location and a third stream of log data to a second location separate and distinct from the first location, wherein the second and third streams of log data are forwarded to the first location and to the second location concurrently and each of the second and third streams of log data include data describing each log contained in the first stream of log data;

storing the second stream of log data forwarded to the first location;

extracting a subset of the third stream of log data forwarded to the second location at the second location in accordance with a set of rules based on predefined queries of a real-time reporting service;

storing the subset of the third stream of log data at a third location separate and distinct from the first and second locations;

transmitting one or more metrics included in the subset of the third stream of log data to the real-time reporting service; and

providing the one or more metrics from the subset of the third stream of log data to a user of the real-time reporting service.

2. The computer implemented method as recited in claim 1 , wherein the real-time reporting service comprises a dashboard service.

3. The computer implemented method as recited in claim 2 , wherein the one or more metrics are displayed graphically to the user with a graph illustrating the number of occurrences of an event type over a predefined period of time.

4. The computer implemented method as recited in claim 1 , wherein providing the one or more metrics from the subset of the third stream of log data to a user comprises sending an alert to a subscriber of an alert service when the one or more metrics indicate a predefined threshold has been exceeded.

5. The computer implemented method as recited in claim 1 , wherein the subset of the third stream of log data comprises only the logs from the third stream of log data that include the one or more metrics.

6. The computer implemented method as recited in claim 5 , wherein extracting the subset of the third stream of log data further comprises processing the subset of the third stream of log data to generate the one or more metrics and saving the subset of the third stream of log data comprises saving the one or more metrics to a third location.

7. The computer implemented method as recited in claim 1 , wherein the first stream of log data is the same as the second stream of log data and the second stream of log data is the same as the third stream of log data.

8. The computer implemented method as recited in claim 1 , wherein the first location comprises a plurality of shards and the second stream of log data is distributed across the plurality of shards.

9. The computer implemented method as recited in claim 1 , wherein the first stream of log data is parsed to create the second stream of log data and the second stream of log data is the same as the third stream of log data.

10. The computer implemented method as recited in claim 1 , wherein the subset of the third stream of log data includes only metric data.

11. The computer implemented method as recited in claim 1 , further comprising requesting new metrics stored in the second location in response to receiving a user request to update one or more queries associated with the reporting service.

12. The computer implemented method as recited in claim 11 , further comprising updating rules associated with the second location to match the requested update to the one or more queries.

13. The computer implemented method as recited in claim 12 , further comprising requesting historical data from the first location when metrics requested by the one or more queries are not stored at the third location.

14. The computer implemented method as recited in claim 13 , further comprising sending the historical data from the first location to the second location.

15. The computer implemented method as recited in claim 14 , further comprising extracting one or more metrics from the historical data provided by the first location at the second location.

16. The computer implemented method as recited in claim 15 , further comprising:

saving the one or more metrics at the third location; and

transmitting the one or more metrics to the reporting service.

17. A non-transitory computer-readable storage medium storing instructions configured to be executed by one or more processors of a computing device cause the computing device to carry out steps that include:

receiving a first stream of log data being generated by an operational system;

forwarding a second stream of log data to a first location and a third stream of log data to a second location separate and distinct from the first location, wherein the second and third streams of log data are forwarded to the first location and to the second location concurrently and each of the second and third streams of log data include data describing each log contained in the first stream of log data;

storing the second stream of log data forwarded to the first location;

extracting a subset of the third stream of log data forwarded to the second location at the second location in accordance with a set of rules based on predefined queries of a real-time reporting service;

storing the subset of the third stream of log data at a third location separate and distinct from the first and second locations;

transmitting one or more metrics included in the subset of the third stream of log data to the real-time reporting service; and

providing the one or more metrics from the subset of the third stream of log data to a user of the real-time reporting service.

18. A computer system, comprising:

one or more processors; and

memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for:

receiving a first stream of log data being generated by an operational system;

forwarding a second stream of log data to a first location and a third stream of log data to a second location separate and distinct from the first location, wherein the second and third streams of log data are forwarded to the first location and to the second location concurrently and each of the second and third streams of log data include data describing each log contained in the first stream of log data;

storing the stream of log data forwarded to the first location;

extracting a subset of the stream of log data forwarded to the second location at the second location in accordance with a set of rules based on predefined queries of a real-time reporting service;

storing the subset of the third stream of log data at a third location separate and distinct from the first and second locations;

transmitting one or more metrics included in the subset of the third stream of log data to the real-time reporting service; and

providing the one or more metrics from the subset of the third stream of log data to a user of the real-time reporting service.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2020
From: SESHADRI, KARTHIK; LAXMAN KARIBHIMANVAR, SIDDARTHA; JHA, RITESH; DEVARAJAN, RADHAKRISHNAN; MULLANGI, CHAITANYA KRISHNA
To: VMWARE, INC.
Reel/Frame 051985/0461 →