IP Library Granted Patent US 11,200,132
Granted Patent B1
US 11,200,132 · App. 17/084,221 · Granted Dec 14, 2021

Anomaly aware log retrieval from disk array enclosures (DAEs)

Inventors: Bing Liu (Tianjin, CN); Rahul Vishwakarma (Bangalore, IN)
Assignee: EMC IP Holding Company LLC
G06F11/3034G06F11/079G06F11/0787G06F11/3048G06F13/4221G06F11/3055
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,200,132
App. No.
17/084,221
Granted
Dec 14, 2021
Kind
B1
Abstract

Topology and performance metrics of a storage system are monitored for anomalies. The storage system includes a set of disk array enclosures (DAEs) connected to a host server. Each DAE is chained to another DAE. Upon detecting an anomaly associated with a DAE, log collection is triggered to obtain logs from the DAE and logs in other DAEs upstream and downstream of the DAE.

Claims (66)

1. A method comprising:

monitoring a topology of a storage system, the storage system comprising a plurality of disk array enclosures (DAEs) coupled to a host server, each DAE being chained to another DAE by first and second chains, and comprising a serial attached SCSI (SAS) expander and a peer SAS expander, the SAS expander in a DAE forming part of the first chain and the peer SAS expander in the DAE forming part of the second chain;

monitoring performance metrics of the DAEs;

detecting, from the monitoring of the topology and the performance metrics, an anomaly associated with one of a SAS expander or a peer SAS expander in a particular DAE, the one of the SAS expander or the peer SAS expander being a problematic SAS expander, the problematic SAS expander in the particular DAE being in one of the first or second chains; and

upon the detecting, triggering DAE log collections to obtain a plurality of logs, the plurality of logs comprising a log stored at the problematic SAS expander in the particular DAE, and logs stored at other SAS expanders in other DAEs upstream and downstream from the particular DAE and being in the one of the first or second chains.

2. The method of claim 1 further comprising:

tagging the plurality of logs with an anomaly class; and

storing the collected logs in a repository accessible by the host server and separate from the DAEs.

3. The method of claim 1 further comprising:

tagging the plurality of logs with an anomaly class; and

limiting, for each anomaly class, a number of logs stored.

4. The method of claim 1 wherein the DAEs are provided by a third party.

5. The method of claim 1 wherein the monitoring the topology of the storage system further comprises:

tracking a number of changes in the topology of the storage system over a predetermined period of time; and

when the number of changes over the predetermined period of time exceeds a threshold, determining that the DAE log collections should be triggered.

6. The method of claim 1 wherein the monitoring the performance metrics of the DAEs further comprises:

identifying a redundant array of inexpensive disks (RAID) group within the plurality of DAEs;

obtaining input/output (IO) latency for each drive in the RAID group;

calculating a population mean of the IO latency;

generating a z-score for each drive in the RAID group based on the population mean; and

determining that DAE log collections should be triggered when each of first and second conditions are satisfied, wherein the first condition is satisfied when a particular drive in the RAID group has an IO latency that exceeds a threshold percentage of the population mean for a threshold number of consecutive days, and

wherein the second condition is satisfied when the particular drive in the RAID group has a z-score that exceeds a threshold z-score for the threshold number of consecutive days.

7. A system comprising: a processor; and memory configured to store one or more sequences of instructions which, when executed by the processor, cause the processor to carry out the steps of:

monitoring a topology of a storage system, the storage system comprising a plurality of disk array enclosures (DAEs) coupled to a host server, each DAE being chained to another DAE by first and second chains, and comprising a serial attached SCSI (SAS) expander and a peer SAS expander, the SAS expander in a DAE forming part of the first chain and the peer SAS expander in the DAE forming part of the second chain;

monitoring performance metrics of the DAEs;

detecting, from the monitoring of the topology and the performance metrics, an anomaly associated with one of a SAS expander or a peer SAS expander in a particular DAE, the one of the SAS expander or the peer SAS expander being a problematic SAS expander, the problematic SAS expander in the particular DAE being in one of the first or second chains; and

upon the detecting, triggering DAE log collections to obtain a plurality of logs, the plurality of logs comprising a log stored at the problematic SAS expander in the particular DAE, and logs stored at other SAS expanders in other DAEs upstream and downstream from the particular DAE and being in the one of the first or second chains.

8. The system of claim 7 wherein the processor further carries out the steps of:

tagging the plurality of logs with an anomaly class; and

storing the collected logs in a repository accessible by the host server and separate from the DAEs.

9. The system of claim 7 wherein the processor further carries out the steps of:

tagging the plurality of logs with an anomaly class; and

limiting, for each anomaly class, a number of logs stored.

10. The system of claim 7 wherein the DAEs are provided by a third party.

11. The system of claim 7 wherein the monitoring the topology of the storage system further comprises:

tracking a number of changes in the topology of the storage system over a predetermined period of time; and

when the number of changes over the predetermined period of time exceeds a threshold, determining that the DAE log collections should be triggered.

12. The system of claim 7 wherein the monitoring the performance metrics of the DAEs further comprises:

identifying a redundant array of inexpensive disks (RAID) group within the plurality of DAEs;

obtaining input/output (TO) latency for each drive in the RAID group;

calculating a population mean of the IO latency;

generating a z-score for each drive in the RAID group based on the population mean; and

determining that DAE log collections should be triggered when each of first and second conditions are satisfied, wherein the first condition is satisfied when a particular drive in the RAID group has an IO latency that exceeds a threshold percentage of the population mean for a threshold number of consecutive days, and

wherein the second condition is satisfied when the particular drive in the RAID group has a z-score that exceeds a threshold z-score for the threshold number of consecutive days.

13. A computer program product, comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein, the computer-readable program code adapted to be executed by one or more processors to implement a method comprising:

monitoring a topology of a storage system, the storage system comprising a plurality of disk array enclosures (DAEs) coupled to a host server, coupled to the host server, each DAE being chained to another DAE by first and second chains, and comprising a serial attached SCSI (SAS) expander and a peer SAS expander, the SAS expander in a DAE forming part of the first chain and the peer SAS expander in the DAE forming part of the second chain;

monitoring performance metrics of the DAEs;

detecting, from the monitoring of the topology and the performance metrics, an anomaly associated with one of a SAS expander or a peer SAS expander in a particular DAE, the one of the SAS expander or the peer SAS expander being a problematic SAS expander, the problematic SAS expander in the particular DAE being in one of the first or second chains; and

upon the detecting, triggering DAE log collections to obtain a plurality of logs, the plurality of logs comprising a log stored at the problematic SAS expander in the particular DAE, and logs stored at other SAS expanders in other DAEs upstream and downstream from the particular DAE and being in the one of the first or second chains.

14. The computer program product of claim 13 wherein the method further comprises:

tagging the plurality of logs with an anomaly class; and

storing the collected logs in a repository accessible by the host server and separate from the DAEs.

15. The computer program product of claim 13 wherein the method further comprises:

tagging the plurality of logs with an anomaly class; and

limiting, for each anomaly class, a number of logs stored.

16. The computer program product of claim 13 wherein the DAEs are provided by a third party.

17. The computer program product of claim 13 wherein the monitoring the topology of the storage system further comprises:

tracking a number of changes in the topology of the storage system over a predetermined period of time; and

when the number of changes over the predetermined period of time exceeds a threshold, determining that the DAE log collections should be triggered.

18. The computer program product of claim 13 wherein the monitoring the performance metrics of the DAEs further comprises:

identifying a redundant array of inexpensive disks (RAID) group within the plurality of DAEs;

obtaining input/output (TO) latency for each drive in the RAID group;

calculating a population mean of the IO latency;

generating a z-score for each drive in the RAID group based on the population mean; and

determining that DAE log collections should be triggered when each of first and second conditions are satisfied, wherein the first condition is satisfied when a particular drive in the RAID group has an IO latency that exceeds a threshold percentage of the population mean for a threshold number of consecutive days, and

wherein the second condition is satisfied when the particular drive in the RAID group has a z-score that exceeds a threshold z-score for the threshold number of consecutive days.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2020
From: LIU, BING; VISHWAKARMA, RAHUL
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 054215/0190 →
Cited By (1)
US 12,189,506