IP Library Granted Patent US 12,326,864
Granted Patent B2
US 12,326,864 · App. 16/819,143 · Granted Jun 10, 2025

Method and system for operation objects discovery from operation data

Inventors: Jia Qi Li (Beijing, CN); Fan Jing Meng (Beijing, CN); Pei Ni Liu (Beijing, CN); Junmei Qu (Beijing, CN); Zi Xiao Zhu (Beijing, CN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F16/24558G06F16/215G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,326,864
App. No.
16/819,143
Granted
Jun 10, 2025
Kind
B2
Abstract

A method and system for operation objects discovery from operation data includes performing pattern matching of operation data with patterns in a database. Fields in the operation data are identified as having matching patterns with the database as first potential objects. Data profiling is performed on unmatched fields of the operation data to generate data profiles. The data profiles are field classified and second potential objects are generated. The first potential objects and the second potential objects are de-duplicated, and operation objects are generated.

Claims (45)

1. A computer-implemented method of monitoring operation objects of a distributed workload multi-cloud computing platform, comprising:

receiving a workload;

distributing the received workload to the multi-cloud computing platform;

monitoring a real-time streaming operation data of the distributed workload multi-cloud computing platform by a pattern matching module of a computing device;

performing, by the pattern matching module of the computing device, pattern matching of the real-time streaming operation data with patterns in a database;

identifying each field in the operation data having matching patterns with the database as first potential objects;

performing data profiling on each of unmatched fields of the operation data to generate data profiles to profile the distribution of each field with various types of values, wherein the data profiling comprises analyzing the unmatched fields of the operation data and collecting statistics therefrom;

field classifying the data profiles to generate second potential objects based on the data profiles of the unmatched fields of the operation data, by a field classifier module operative to identify a particular class, a possible error pattern, and/or a warning pattern in the data profiles of the unmatched fields;

relieving a storage space of the multi-cloud computing platform by de-duplicating the first potential objects and the second potential objects by deleting duplicative data of the first potential objects and the second potential objects when generating operation objects in response to determining that at least two of the first potential objects and the second potential objects have a same value and different field names in different indices;

updating a knowledge base of the de-duplicated data of the first potential objects and the second potential objects; and

detecting at least one of segmented operations, errors, and/or faults in the distributed workload multi-cloud computing platform based on the generated operation objects.

2. The computer-implemented method according to claim 1 , wherein identifying fields is performed automatically without a selection of fields by using a field name or a meaning.

3. The computer-implemented method according to claim 1 , further comprising updating the database with the generated data profiles.

4. The computer-implemented method according to claim 1 , further comprising updating the database with the generated operation objects.

5. The computer-implemented method according to claim 1 , further comprising training a field classifier with the generated data profiles prior to generating the second potential objects.

6. The computer-implemented method according to claim 5 , wherein training the field classifier includes inputting one or more of patterns, rules, data profiles, and models from the database.

7. The computer-implemented method according to claim 1 , wherein a pattern matching module performs the pattern matching with operation data retrieved from a system log.

8. A computer implemented system having a computer processor coupled to a memory configured to monitor operation objects of a distributed workload multi-cloud computing platform, comprising:

receiving a workload;

distributing the received workload to the multi-cloud computing platform;

monitoring a real-time streaming operation data of the distributed workload multi-cloud computing platform by the computer processor;

a pattern matching module stored in the memory configured to perform pattern matching on the real-time streaming operation data with patterns in a database, and to identify each field in the operation data having matching patterns with the database as first potential objects;

a data profiling module stored in the memory configured to perform data profiling on each of unmatched fields of the operation data to generate data profiles to profile the distribution of each field with various types of values, wherein the data profiling comprises analyzing the unmatched fields of the operation data and collects statistics therefrom;

a field classifier module stored in the memory operative to classify the generated data profiles and to generate second potential objects based on the data profiles of the unmatched fields of the operation data and identify a particular class, a possible error pattern, and/or a warning pattern in the data profiles of the unmatched fields;

a de-duplication module stored in the memory configured to relieve a storage space of the multi-cloud computing platform by removing duplicate objects among the first potential objects and the second potential objects, and to generate operation objects in response to determining that at least two of the first potential objects and the second potential objects have a same value and different field names in different indices; and

detecting at least one of segmented operations, errors, and/or faults in the distributed workload multi-cloud computing platform based on the generated operation objects.

9. The system according to claim 8 , wherein the pattern matching module stored in the memory is further configured to perform identifying fields automatically without a selection of fields by using a field name or a meaning.

10. The system according to claim 8 , further comprising a middle events module stored in the memory configured to update the database with the generated data profiles generated by the data profiling module.

11. The system according to claim 8 , wherein the middle events module stored in the memory is configured to update the database with generated operation objects.

12. The system according to claim 8 , wherein the field classifier module stored in the memory is trained with a training set comprising the generated data profiles prior to generating the second potential objects.

13. The system according to claim 8 , wherein the field classifier module stored in the memory is trained with a training set comprising one or more of patterns, rules, data profiles or models from the database.

14. The system according to claim 8 , wherein the operation data is retrieved from a system log.

15. A non-transitory computer readable storage medium tangibly embodying a computer readable program code having computer readable instructions that, when executed, causes a computer device to perform a method of monitoring operation objects of a distributed workload multi-cloud computing platform, the method comprising:

receiving a workload;

distributing the received workload to the multi-cloud computing platform;

monitoring a real-time streaming operation data of the distributed workload multi-cloud computing platform by a pattern matching module of a computing device;

performing, by the pattern matching module of the computing device, pattern matching of the real-time streaming operation data with patterns in a database;

identifying each field in the operation data having matching patterns with the database as first potential objects;

performing data profiling on each of unmatched fields of the operation data to generate data profiles to profile the distribution of each field with various types of values, wherein the data profiling comprises analyzing the unmatched fields of the operation data and collects statistics therefrom;

field classifying the data profiles to generate second potential objects based on the data profiles of the unmatched fields of the operation data, by a field classifier module operative to identify a particular class, a possible error pattern, and/or a warning pattern in the data profiles of the unmatched fields;

relieving a storage space of the multi-cloud computing platform by de-duplicating the first potential objects and the second potential objects by deleting duplicative data of the first potential objects and the second potential objects when generating operation objects in response to determining that at least two of the first potential objects and the second potential objects have a same value and different field names in different indices;

updating a knowledge base of the de-duplicated data of the first potential objects and the second potential objects; and

detecting at least one of segmented operations, errors, and/or faults in the distributed workload multi-cloud computing platform based on the generated operation objects.

16. The non-transitory computer readable storage medium according to claim 15 , wherein identifying fields is performed automatically without a selection of fields by using a field name or a meaning.

17. The non-transitory computer readable storage medium according to claim 15 , further comprising training a field classifier with the generated data profiles prior to generating the second potential objects.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2021
From: LI, JIA QI; MENG, FAN JING; LIU, PEI NI; QU, JUNMEI; ZHU, ZI XIAO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 055759/0023 →
Continuity (1)
Related Publication 20210286819A1 · Sep 16, 2021
References Cited (58)
US 7639868B1 · Regli et al. · 2009 [cited by applicant]
US 7827186B2 · Hicks · 2010 [cited by applicant]
US 8738972B1 · Bakman et al. · 2014 [cited by applicant]
US 8862728B2 · Jayachandran et al. · 2014 [cited by applicant]
US 9244983B2 · Yang et al. · 2016 [cited by applicant]
US 9734005B2 · Ruan et al. · 2017 [cited by applicant]
US 10373094B2 · Naous et al. · 2019 [cited by applicant]
US 10505825B1 · Bettaiah et al. · 2019 [cited by applicant]
US 10725982B2 · Scheideler et al. · 2020 [cited by applicant]
US 11244345B2 · Pradeep · 2022 [cited by applicant]
US 20030212654A1 · Harper · 2003 [cited by examiner]
US 20040078364A1 · Ripley · 2004 [cited by applicant]
US 20040143508A1 · Bohn · 2004 [cited by applicant]
US 20040243548A1 · Hulten et al. · 2004 [cited by applicant]
US 20070038938A1 · Canora · 2007 [cited by applicant]
US 20080184001A1 · Stager · 2008 [cited by examiner]
US 20080213768A1 · Cai et al. · 2008 [cited by applicant]
US 20090024555A1 · Rieck · 2009 [cited by applicant]
US 20100332540A1 · Moerchen et al. · 2010 [cited by applicant]
US 20110225173A1 · Gulhane · 2011 [cited by applicant]
US 20120272249A1 · Beaty · 2012 [cited by examiner]
US 20120323921A1 · Chen · 2012 [cited by applicant]
US 20140074764A1 · Duftler · 2014 [cited by examiner]
US 20140344622A1 · Huang et al. · 2014 [cited by applicant]
US 20150170022A1 · Malik et al. · 2015 [cited by applicant]
US 20150242384A1 · Reiter · 2015 [cited by applicant]
US 20160062972A1 · Ramakrishnan · 2016 [cited by examiner]
US 20160124823A1 · Ruan et al. · 2016 [cited by applicant]
US 20170132060A1 · Nomura et al. · 2017 [cited by applicant]
US 20170185910A1 · Appel et al. · 2017 [cited by applicant]
US 20170186249A1 · Bandy et al. · 2017 [cited by applicant]
US 20170213127A1 · Duncan · 2017 [cited by applicant]
US 20170249200A1 · Mustafi et al. · 2017 [cited by applicant]
US 20170262429A1 · Harper · 2017 [cited by applicant]
US 20170270154A1 · Stephens · 2017 [cited by examiner]
US 20180144041A1 · Chen et al. · 2018 [cited by applicant]
US 20190058643A1 · Knowles et al. · 2019 [cited by applicant]
US 20190095313A1 · Xu · 2019 [cited by examiner]
US 20190303459A1 · Yan · 2019 [cited by applicant]
US 20200004813A1 · Galitsky · 2020 [cited by applicant]
US 20200380212A1 · Butler · 2020 [cited by examiner]
US 20210117868A1 · Sriharsha · 2021 [cited by examiner]
US 20210149915A1 · Lee · 2021 [cited by examiner]
US 20210286826A1 · Li et al. · 2021 [cited by applicant]
US 20220032982A1 · Shenton · 2022 [cited by applicant]
CN 109921938A · 2019 [cited by applicant]
List of IBM Patents or Patent Applications Treated as Related, 2 pgs. [cited by applicant]
Debnath, B. et al., “LogLens: A Real-time Log Analysis System”; IEEE 38th International Conference on Distributed Computing Systems (2018), pp. 1052-1062. [cited by applicant]
Mell, P. et al., “Recommendations of the National Institute of Standards and Technology”; NIST Special Publication 800-145 (2011); 7 pgs. [cited by applicant]
Disclosed Anonymously, IP.com No. IPCOM000224872D “Method and system to detect and predict problems based on pattern recognition of large amounts of logs in multiple dimensions under cloud environment”, Jan. 9, 2013, 16… [cited by applicant]
Disclosed Anonymously, IP.com No. IPCOM000251608D “Method and System for Automated Problem Detection in A Multi-System Distributed Cloud Computing Environment”, Nov. 15, 2017, 4 pages. [cited by applicant]
Lin et al. “Log Clustering based Problem Identification for Online Service Systems”; ICSE, May 2016, 10 pages. [cited by applicant]
Puri Colin., “Event Correlation across Log Files: What is it and Why is it Important?”; Accenture.com, Technology Labs Blog, Apr. 30, 2014, 3 pages. [cited by applicant]
Wang et al. “Grano: Interactive Graphbased Root Cause Analysis for CloudNative Distributed Data Platform”, Proceedings of the VLDB Endowment, Aug. 1, 2019, pp. 1942-1945, vol. 12, Issue 12. [cited by applicant]
Xu et al., “Detecting Large-Scale System Problems by Mining Console Logs”; SOSP '09: Proceedings of the ACM SIGOPS 22nd symposium on Operating systems principles, Oct. 11, 2009, pp. 117-132. [cited by applicant]
Zheng et al., “System Log Pre-processing to Improve Failure Prediction”, Proceedings of DSN, 2009, 6 pages. [cited by applicant]
Disclosed Anonymously. IP.com No. IPCOM000220081D, “Intelligent log framework for distributed environment applications”, Jul. 20, 2012, 7 pages. [cited by applicant]
Disclosed Anonymously. IP.com No. IPCOM000258375D, An interactive system for the automated workload discovery, visualization and analysis in complex IT environments, May 6, 2019, 10 pages. [cited by applicant]