IP Library › Granted Patent US 12,355,785
Granted Patent B2
US 12,355,785 · App. 17/548,636 · Granted Jul 8, 2025

Revealing rare and anomalous events in system automation logs

Inventors: Dave Willoughby (Austin, TX); Marco Selig (Leipzig, DE); Pavel Kravetskiy (Grafenau, DE); Juri Dragoun (Öhringen, DE)
Assignee: International Business Machines Corporation
H04L63/1425G06F16/285G06N20/00G06N20/10H04L63/1416G06F21/56G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,785
App. No.
17/548,636
Granted
Jul 8, 2025
Kind
B2
Abstract

A computer-implemented method, system, and computer program product for classifying a sequence of log entries of a computing system may be provided. The method may include pre-processing the log entries. The method may also include predicting, as a first output of a first trained machine-learning system, a likelihood of a particular next log entry after the window. The method may also include, predicting, as a second output of a second trained machine-learning system, whether the next log entry is unprecedented. The method may also include combining the first output and the second output for determining a classification of the sequence of log entries.

Claims (43)

1. A computer-implemented method for classifying a sequence of log entries of a computing system, the method comprising:

pre-processing the log entries;

forming a plurality of feature vectors from the log entries that are anomaly-free log data;

training a first machine-learning system using the plurality of feature vectors as input training data resulting in a first machine learning model for predicting a likelihood value for an appearance of a next log entry after a window of the sequence of log entries;

training a second machine-learning system using the plurality of feature vectors as input training data resulting in a second machine learning model for predicting a probability value of whether the next log entry after the window of the sequence of log entries is unprecedented, wherein the first machine-learning model and the second machine-learning model are trained in parallel;

predicting, as a first output of the first trained machine-learning system, a likelihood of a particular next log entry after the window;

predicting, as a second output of the second trained machine-learning system, whether the next log entry is unprecedented; and

combining the first output and the second output for determining a classification of the sequence of log entries.

2. The method according to claim 1 , wherein the first machine learning model uses a long short-term memory architecture.

3. The method according to claim 1 , wherein the second machine learning model uses a 1-class support vector machine-learning architecture.

4. The method according to claim 1 , further comprising:

in response to combining the first output and the second output, classifying an entry in a log sequence as normal, rare, or anomalous.

5. The method according to claim 1 , further comprising:

triggering a preventive recovery action for a resource upon detecting an anomalous log sequence entry.

6. The method according to claim 1 , wherein the next log entry after the window of the sequence of log entries is a sequence of log entries.

7. The method according to claim 1 , wherein the classification of the sequence of log entries is a combination of a predicted likelihood value for an appearance of the next log entry and a predicted probability value of whether the next log entry is unprecedented.

8. The method according to claim 1 , further comprising:

skipping a log entry unrelated to one or more previous log entries in the window of the sequence of log entries.

9. An automation manager system for classifying a sequence of log entries of a computing system, the system comprising:

a processor and a memory, communicatively coupled to the processor, wherein the memory stores program code portions that, when executed, further configure the processor, to:

pre-process the log entries;

forming a plurality of feature vectors from the log entries that are anomaly-free log data;

train a first machine-learning system using the plurality of feature vectors as input training data resulting in a first machine learning model for predicting a likelihood value for an appearance of a next log entry after a window of the sequence of log entries;

train a second machine-learning system using the plurality of feature vectors as input training data resulting in a second machine learning model for predicting a probability value of whether the next log entry after the window of the sequence of log entries is unprecedented, wherein the first machine-learning model and the second machine-learning model are trained in parallel;

predict, as a first output of the first trained machine-learning system, a likelihood of a particular next log entry after the window;

predict, as a second output of the second trained machine-learning system, whether the next log entry is unprecedented; and

combine the first output and the second output for determining a classification of the sequence of log entries.

10. The automation manager system according to claim 9 , wherein the first machine learning model is a long short-term memory machine-learning system.

11. The automation manager system according to claim 9 , wherein the second machine learning model is a 1-class support vector machine-learning system.

12. The automation manager system according to claim 9 , wherein the processor is also configured to:

in response to combining the first output and the second output, classifying an entry in a log sequence as normal, rare, or anomalous.

13. The automation manager system according to claim 9 , wherein the processor is also configured to:

trigger a preventive recovery action for a resource upon detecting an anomalous log sequence entry.

14. The automation manager system according to claim 9 , wherein the processor is also configured to:

skip a log entry unrelated to one or more previous log entries in the window of the sequence of log entries.

15. A computer program product for classifying a sequence of log entries of a computing system, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a server to cause the server to perform a method, the method comprising:

pre-processing the log entries;

forming a plurality of feature vectors from the log entries that are anomaly-free log data;

training a first machine-learning system using the plurality of feature vectors as input training data resulting in a first machine learning model for predicting a likelihood value for an appearance of a next log entry after a window of the sequence of log entries;

training a second machine-learning system using the plurality of feature vectors as input training data resulting in a second machine learning model for predicting a probability value of whether the next log entry after the window of the sequence of log entries is unprecedented, wherein the first machine-learning model and the second machine-learning model are trained in parallel;

predicting, as a first output of the first trained machine-learning system, a likelihood of a particular next log entry after the window;

predicting, as a second output of the second trained machine-learning system, whether the next log entry is unprecedented; and

combining the first output and the second output for determining a classification of the sequence of log entries.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2021
From: WILLOUGHBY, DAVE; SELIG, MARCO, DR.; KRAVETSKIY, PAVEL; DRAGOUN, JURI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058367/0321 →
Continuity (1)
Related Publication 20230188549A1 · Jun 15, 2023
References Cited (19)
US 7269684B2 · Konson et al. · 2007 [cited by applicant]
US 7529654B2 · Dowedeit et al. · 2009 [cited by applicant]
US 20010018710A1 · Clarke et al. · 2001 [cited by applicant]
US 20190228296A1 · Gefen et al. · 2019 [cited by applicant]
US 20190362074A1 · Wang et al. · 2019 [cited by applicant]
US 20200076842A1 · Zhou et al. · 2020 [cited by applicant]
US 20210224676A1 · Arzani · 2021 [cited by examiner]
US 20220103418A1 · Acharjee · 2022 [cited by examiner]
CN 111767957A · 2020 [cited by applicant]
CN 113282920A · 2021 [cited by applicant]
CN 113312485A · 2021 [cited by applicant]
CN 113468035A · 2021 [cited by applicant]
WO 2019060327A1 · 2019 [cited by applicant]
Farzad et al., “Log Message Anomaly Detection and Classication Using Auto-B/LSTM and Auto-GRU,” Research Gate, Nov. 2019, arXiv:1911.08744v2 [cs.LG] Apr. 7, 2021, 19 pages. [cited by applicant]
Cimino et al., “Tandem LSTM-SVM Approach for Sentiment Analysis,” Printed Dec. 6, 2021, 6 pages. [cited by applicant]
Li, “Automatic Log Analysis using Machine Learning,” Awesome Automatic Log Analysis version 2.0, Nov. 2013, 50 pages. [cited by applicant]
Levy, “A Machine Learning Approach to Log Analytics,” Jan. 19, 2017, 12 pages. [cited by applicant]
Kaur, “Automatic Log Analysis using Deep Learning and AI,” Data Science, Aug. 25, 2020, 18 pages. [cited by applicant]
“A Method and System for Log Parsing with Contextualized Embeddings in Cloud Microservices,” IP.Com, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000265628D, IP.com Electronic Publication Date: Apr… [cited by applicant]