IP Library Granted Patent US 11,436,285
Granted Patent B2
US 11,436,285 · App. 17/068,209 · Granted Sep 6, 2022

Anomaly database system for processing telemetry data

Inventors: Gurashish Singh Brar (Belmont, CA); Karan Jayesh Bavishi (San Francisco, CA); Gurjeet S. Arora (Sunnyvale, CA)
Assignee: Rubrik, Inc.
G06F16/906G06F16/90335G06F17/18H04L65/4092H04L65/608
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,436,285
App. No.
17/068,209
Granted
Sep 6, 2022
Kind
B2
Abstract

In some examples, an anomaly database system is provided for processing metrics in telemetry data. An example anomaly database system comprises a continuous data management (CDM) node, the CDM node including a metrics library for sending out system metrics in a sparse manner and a statistics relay for receiving streaming metrics from nodes in a node cluster, the node cluster including the CDM node, the statistics relay pushing the received metrics to a metrics collector. A sparse consumers module pulls metrics, from the metrics collector, pushed to the metrics collector by the statistics relay.

Claims (24)

1. An anomaly database system for processing metrics in telemetry data, the anomaly database system comprising:

a continuous data management (CDM) node, the CDM node including a metrics library for sending out system metrics in a sparse manner by using simple sparseness detection algorithms, wherein the simple sparseness detection algorithms comprise: a diff-value algorithm and a last-value-delta algorithm;

a statistics relay for receiving streaming metrics from a plurality of CDM nodes, and pushing the received metrics to a metrics collector;

a sparse consumers module to pull metrics, from the metrics collector, pushed to the metrics collector by the statistics relay, wherein the sparse consumers module includes at least one processor configured to run a sparse algorithm on the pulled metrics to reduce a number of data points to produce sparse metrics data, wherein the sparse algorithm is selected from a group of sparse algorithms comprising: a diff-value algorithm, a last-value-delta algorithm, a standard deviation band algorithm with a last-value fallback, and a last-value-delta with percentile algorithm;

a rollup module to operate on the sparse metrics data to compute a time weighted mean over a rollup interval to enable read queries over a designated time range, wherein the rollup interval changes based on usage data and query patterns;

a read application programming interface (API) to perform cross data source aggregations on the sparse metrics data stored in the anomaly database system in response to read queries; and

a user interface to provide visualization of query results of metrics data in the anomaly database system for the read queries.

2. The anomaly database system of claim 1 , further comprising a baseline estimator to pre-compute baselines on the streaming metrics to enable anomaly detection, correlations, and multi-series sparseness.

3. A method of processing metrics in telemetry data in an anomaly database system comprising a continuous data management (CDM) node, the CDM node including a metrics library and sending out system metrics in a sparse manner by using simple sparseness detection algorithms, the simple sparseness detection algorithms comprising a diff-value algorithm and a last-value-delta algorithm; the method comprising:

receiving, by a statistics relay, streaming metrics from a plurality of CDM nodes, the statistics relay pushing the received metrics to a metrics collector;

pulling metrics, by a sparse consumers module, from the metrics collector;

running a sparse algorithm on the pulled metrics to reduce a number of data points to produce sparse metrics data, wherein the sparse algorithm is selected from a group of sparse algorithms comprising: a diff-value algorithm, a last-value-delta algorithm, a standard deviation band algorithm with a last-value fallback, and a last-value-delta with percentile algorithm;

implementing a rollup module to operate on the sparse metrics data to compute a time weighted mean over a rollup interval to enable read queries over a designated time range, wherein the rollup interval changes based on usage data and query patterns;

implementing a read application programming interface (API) to perform cross data source aggregations on the sparse metrics data stored in the anomaly database system in response to read queries; and

implementing a user interface to provide visualization of query results of metrics data in the anomaly database system for the read queries.

4. The method of claim 3 , further comprising pre-computing baselines on the streaming metrics to enable anomaly detection, correlations, and multi-series sparseness.

5. A non-transitory machine-readable medium including instructions, which when read by a machine, cause the machine to perform operations in a method of processing metrics in telemetry data in an anomaly database system comprising a continuous data management (CDM) node, the CDM node including a metrics library and sending out system metrics in a sparse manner by using simple sparseness detection algorithms, the simple sparseness detection algorithms comprising a diff-value algorithm and a last-value-delta algorithm; the operations comprising:

receiving, by a statistics relay, streaming metrics from a plurality of CDM nodes, the statistics relay pushing the received metrics to a metrics collector;

pulling metrics, by a sparse consumers module, from the metrics collector;

running a sparse algorithm on the pulled metrics to reduce a number of data points to produce sparse metrics data, wherein the sparse algorithm is selected from a group of sparse algorithms comprising: a diff-value algorithm, a last-value-delta algorithm, a standard deviation band algorithm with a last-value fallback, and a last-value-delta with percentile algorithm;

implementing a rollup module to operate on the sparse metrics data to compute a time weighted mean over a rollup interval to enable read queries over a designated time range, wherein the rollup interval changes based on usage data and query patterns;

implementing a read application programming interface (API) to perform cross data source aggregations on the sparse metrics data stored in the anomaly database system in response to read queries; and

implementing a user interface to provide visualization of query results of metrics data in the anomaly database system for the read queries.

6. The medium of claim 5 , wherein the operations further comprise pre-computing baselines on the streaming metrics to enable anomaly detection, correlations, and multi-series sparseness.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 60333/0323 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071565/0602 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 10, 2022
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 060333/0323 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2020
From: BRAR, GURASHISH SINGH; BAVISHI, KARAN JAYESH; ARORA, GURJEET S.
To: RUBRIK, INC.
Reel/Frame 054193/0713 →
Cited By (1)
US 12,572,579