IP Library Granted Patent US 12,032,637
Granted Patent B2
US 12,032,637 · App. 17/383,066 · Granted Jul 9, 2024

Single click delta analysis

Inventors: Matt K. Amel (Campbell, CA); Christian Friedrich Beedgen (San Carlos, CA); Kumar Saurabh (Menlo Park, CA); Bruno Kurtic (Belmont, CA)
Assignee: Sumo Logic, Inc.
G06F16/951G06F16/245G06F16/248G06F16/2428G06F16/2462G06F16/24568G06F16/285G06F21/552G06F21/566G06Q10/06H04L43/0817H04L63/08H04L63/1408H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,032,637
App. No.
17/383,066
Granted
Jul 9, 2024
Kind
B2
Abstract

Single-click delta analysis is disclosed. A user query of status information collected from one or more monitored devices is received from a user. In response to receiving an indication from the user to determine a variance between different portions of the collected status information, a target query and a baseline query are generated using the user query. The generated target query and the generated baseline query are performed, respectively, against data in a data store including the status information collected from the one or more monitored devices. A target set of status information results and a baseline set of status information results are obtained in response to performing, respectively, the generated target query and the generated baseline query. The obtained target and baseline sets of results are combined. Output indicative of a variance between the target and baseline sets of status information results is provided based at least in part on the combining.

Claims (44)

1. A system, comprising:

one or more processors configured to:

receive, from a user, a first query for status information collected from a plurality of nodes and stored in a data store;

collect the status information from the data store based on the first query;

present the status information on a user interface;

receive, via the user interface, a user request to determine a variance between the collected status information for a first node and the collected status information for other nodes in the plurality of nodes, wherein the status information includes a plurality of logs messages or metrics collected from the first node and a plurality of log messages or metrics collected from the other nodes;

modify, in response to the user request, the first query to obtain a second query for the first node, wherein modifying the first query to obtain the second query comprises rewriting the first query to include a set of operator components for the first node to obtain the second query;

modify the first query to obtain a third query for the other nodes, wherein modifying the first query to obtain the third query comprises rewriting the first query to include a set of operator components for the other nodes to obtain the third query;

receive a first set of status information results and a second set of status information results from the data store in response to performing, respectively, the second query and the third query against data in the data store;

determine a variance between the first set of status information results and the second set of status information results; and

present, via the user interface, information on the variance between the first node and the other nodes; and

a memory coupled to the one or more processors and configured to provide the one or more processors with instructions.

2. The system of claim 1 , wherein the user request comprises a selection of a user interface element.

3. The system of claim 1 , wherein the first and second sets of status information results are divided based on a spatial characteristic based on the node that generated the logs messages or metrics.

4. The system of claim 1 , wherein the user request further comprises requesting variance for at least one of a time window and a cohort of users.

5. The system of claim 1 , wherein the first and second sets of status information results comprise tables, and wherein the one or more processors are further configured to join the first and second sets of status information results on a key column.

6. The system of claim 1 , wherein the second query and the third query generated from the first query comprise a same query, associated with different nodes.

7. The system of claim 1 , wherein the second query and the third query generated from the first query comprise different queries associated with different nodes.

8. The system of claim 1 , wherein the first query comprises a query for log messages, and wherein the user request comprises an indication to compare a first group of log messages from the first node against a second group of log messages from the other nodes.

9. The system of claim 8 , wherein the first and second sets of status information results comprise first and second sets of log messages.

10. The system of claim 9 , wherein the one or more processors are further configured to cluster the first set of log messages and to cluster the second set of log messages, and wherein a cluster is associated with a corresponding signature comprising a template for log messages included in the cluster.

11. The system of claim 10 , wherein the one or more processors are further configured to determine a count of a number of log messages in a given cluster.

12. The system of claim 11 , wherein the one or more processors are further configured to join, based at least in part on signatures, the first set of clustered log messages and the second set of clustered log messages.

13. The system of claim 12 , wherein determining the variance between the first set of status information results and the second set of status information results comprises determining at least one of a difference in a number of logs in a given cluster, a presence of a cluster in the first set of status information results but not in the second set of status information results, and a presence of a cluster in the second set of status information results but not the first set of status information results.

14. A method, comprising:

receiving, from a user, a first query for status information collected from a plurality of nodes and stored in a data store;

collecting the status information from the data store based on the first query;

presenting the status information on a user interface;

receiving, via the user interface, a user request to determine a variance between the collected status information for a first node and the collected status information for other nodes in the plurality of nodes, wherein the status information includes a plurality of logs messages or metrics collected from the first node and a plurality of log messages or metrics collected from the other nodes;

modifying, in response to the user request, the first query to obtain a second query for the first node, wherein modifying the first query to obtain the second query comprises rewriting the first query to include a set of operator components for the first node to obtain the second query;

modifying the first query to obtain a third query for the other nodes, wherein modifying the first query to obtain the third query comprises rewriting the first query to include a set of operator components for the other nodes to obtain the third query;

receiving a first set of status information results and a second set of status information results from the data store in response to performing, respectively, the second query and the third query against data in the data store;

determining a variance between the first set of status information results and the second set of status information results; and

presenting, via the user interface, information on the variance between the first node and the other nodes.

15. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving, from a user, a first query for status information collected from a plurality of nodes and stored in a data store;

collecting the status information from the data store based on the first query;

presenting the status information on a user interface;

receiving, via the user interface, a user request to determine a variance between the collected status information for a first node and the collected status information for other nodes in the plurality of nodes, wherein the status information includes a plurality of logs messages or metrics collected from the first node and a plurality of log messages or metrics collected from the other nodes;

modifying, in response to the user request, the first query to obtain a second query for the first node, wherein modifying the first query to obtain the second query comprises rewriting the first query to include a set of operator components for the first node to obtain the second query;

modifying the first query to obtain a third query for the other nodes, wherein modifying the first query to obtain the third query comprises rewriting the first query to include a set of operator components for the other nodes to obtain the third query;

receiving a first set of status information results and a second set of status information results from the data store in response to performing, respectively, the second query and the third query against data in the data store;

determining a variance between the first set of status information results and the second set of status information results; and

presenting, via the user interface, information on the variance between the first node and the other nodes.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded May 12, 2023
From: SUMO LOGIC, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS COLLATERAL AGENT
Reel/Frame 063633/0648 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE ASSIGNEE TO SUMO LOGIC, INC. PREVIOUSLY RECORDED ON REEL 057120 FRAME 0316. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 21, 2021
From: AMEL, MATT K.; BEEDGEN, CHRISTIAN FRIEDRICH; SAURABH, KUMAR; KURTIC, BRUNO
To: SUMO LOGIC, INC.
Reel/Frame 057556/0457 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2021
From: AMEL, MATT K.; BEEDGEN, CHRISTIAN FRIEDRICH; SAURABH, KUMAR; KURTIC, BRUNO
To: SUMO LOGIC
Reel/Frame 057120/0316 →
Continuity (4)
Continuation 16872180 · May 11, 2020
Continuation 15406281 · Jan 13, 2017
Provisional Application 62278862 · Jan 14, 2016
Related Publication 20210349953A1 · Nov 11, 2021