IP Library Granted Patent US 12,676,056
Granted Patent B1
US 12,676,056 · App. 18/301,836 · Granted Jul 7, 2026

Generating predictive models using clusters

Inventors: Adam Jamison Oliner (San Francisco, CA); Jonathan La (San Francisco, CA); Colleen Kinross (San Francisco, CA); Hongyang Zhang (San Francisco, CA); Jacob Leverich (San Francisco, CA); Shang Cai (San Francisco, CA); Mihai Ganea (San Francisco, CA); Alex Cruise (San Francisco, CA); Toufic Boubez (Vancouver, CA); Manish Sainani (San Francisco, WA)
Assignee: Cisco Technology, Inc.
G08B6/00B06B1/0644G06F3/016H02N2/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,676,056
App. No.
18/301,836
Filed
Apr 17, 2023
Granted
Jul 7, 2026
Kind
B1
Art Unit
2685
USPC
340/407.1
Abstract

In some implementations, sequences of time series values determined from machine data are obtained. Each sequence corresponds to a respective time series. A plurality of predictive models is generated for a first time series from the sequences of time series values. Each predictive model is to generate predicted values associated with the first time series using values of a second time series. For each of the plurality of predictive models, an error is determined between the corresponding predicted values and values associated with the first time series. A predictive model is selected for anomaly detection based on the determined error of the predictive model. Transmission is caused of an indication of an anomaly detected using the selected predictive model.

Claims (36)

1 . A computer-implemented method comprising:

obtaining a set of time series for which to apply anomaly detection;

generating a set of clusters, wherein each cluster of the set of clusters includes at least one time series of the set of time series;

determining a representative time series for a first cluster of time series;

generating a predictive model for the representative time series, wherein the predictive model is configured to predict values associated with the representative time series; and

performing the anomaly detection, using the generated predictive model, on a time series associated with the first cluster of time series from which the predictive model is generated.

2 . The computer-implemented method of claim 1 , wherein the predictive model is configured to predict the values associated with the representative time series using first values associated with another time series of a second cluster.

3 . The computer-implemented method of claim 1 further comprising identifying the set of time series based on a user selection or interaction associated with the set of time series.

4 . The computer-implemented method of claim 1 , wherein the representative time series for the first cluster of time series corresponds to an aggregation of a plurality of the time series in the set of time series.

5 . The computer-implemented method of claim 1 , wherein the predictive model learns to predict the values using first values associated with another time series of a second cluster different from the first cluster of time series.

6 . The computer-implemented method of claim 1 further comprising performing the anomaly detection, using the generated predictive model, on each time series of the set of time series.

7 . The computer-implemented method of claim 1 , wherein the predictive model comprises one or more of a polynomial model, a neural network, or a decision tree model.

8 . The computer-implemented method of claim 1 , wherein data points of the set of time series are associated with respective time stamps of respective events.

9 . The computer-implemented method of claim 1 , further comprising training the predictive model over a training period using time series values corresponding to a different time series than the representative time series.

10 . One or more non-transitory computer-readable storage media having instructions stored thereon, wherein the instructions, when executed by one or more processors, cause the one or more processors to perform a computer- implemented method comprising:

obtaining a set of time series for which to apply anomaly detection;

generating a set of clusters, wherein each cluster of the set of clusters includes at least one time series of the set of time series;

determining a representative time series for a first cluster of time series;

generating a predictive model for the representative time series, wherein the predictive model is configured to predict values associated with the representative time series; and

performing the anomaly detection, using the generated predictive model, on a time series associated with the first cluster of time series from which the predictive model is generated.

11 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the predictive model is configured to predict the values associated with the representative time series using first values associated with another time series of a second cluster.

12 . The one or more non-transitory computer-readable storage media of claim 10 further comprising identifying the set of time series based on a user selection or interaction associated with the set of time series.

13 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the representative time series for the first cluster of time series corresponds to an aggregation of a plurality of the time series in the set of time series.

14 . The one or more non-transitory computer-readable storage media of claim 10 , wherein the predictive model learns to predict the values using first values associated with another time series of a second cluster different from the first cluster of time series.

15 . A computer-implemented system comprising:

one or more hardware processors;

one or more computer-readable storage media having instructions stored thereon, wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform a method comprising:

obtaining a set of time series for which to apply anomaly detection;

generating a set of clusters, wherein each cluster of the set of clusters includes at least one time series of the set of time series;

determining a representative time series for a first cluster of time series;

generating a predictive model for the representative time series, wherein the predictive model is configured to predict values associated with the representative time series; and

performing the anomaly detection, using the generated predictive model, on a time series associated with the first cluster of time series from which the predictive model is generated.

16 . The system of claim 15 , wherein the predictive model learns to predict the values using first values associated with another time series of a second cluster different from the first cluster of time series.

17 . The system of claim 15 , wherein the method further comprises performing the anomaly detection, using the generated predictive model, on each time series of the set of time series.

18 . The system of claim 15 , wherein the predictive model comprises one or more of a polynomial model, a neural network, or a decision tree model.

19 . The system of claim 15 , wherein data points of the set of time series are associated with respective time stamps of respective events.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
Continuity (1)
Continuation 17075928 · Oct 21, 2020
References Cited (40)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10581977B2 · Goldfarb · 2020 [cited by examiner]
US 20070192863A1 · Kapoor et al. · 2007 [cited by applicant]
US 20100057662A1 · Collier et al. · 2010 [cited by applicant]
US 20110126111A1 · Gill et al. · 2011 [cited by applicant]
US 20110185421A1 · Wittenstein et al. · 2011 [cited by applicant]
US 20110185422A1 · Khayam et al. · 2011 [cited by applicant]
US 20110214187A1 · Wittenstein et al. · 2011 [cited by applicant]
US 20110267964A1 · Baltatu et al. · 2011 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150229661A1 · Balabine et al. · 2015 [cited by applicant]
US 20150234869A1 · Chan et al. · 2015 [cited by applicant]
US 20150235152A1 · Eldardiry et al. · 2015 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160285700A1 · Gopalakrishnan · 2016 [cited by examiner]
US 20160330225A1 · Kroyzer et al. · 2016 [cited by applicant]
US 20180150547A1 · Pallath · 2018 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
Baah, George K. et al. On-line Anomaly Detection of Deployed Software: A Statistical Machine Learning Approach. Proceedings of the 3rd International Workshop on Software Quality Assurance, SOQUA '06.https://dl.acm.org/c… [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Carasso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, pp. 156. [cited by applicant]
Computer Desktop Encyclopedia definition of “processor”: http://lookup.computerlanguage.com/host_app/search?cid=C999999&term=processor&lookup.x=O&lookup.y=0 (Year: 2014). [cited by applicant]
Gunnemann, S., et al., Detecting Anomalies in Dynamic Rating Data: A Robust Probabilistic Model for Rating Evolution. Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. h… [cited by applicant]
Josef, K., et al., “Domain Anomaly Detection in Machine Perception: A System Architecture and Taxonomy,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 36, Issue 5, pp. 845-859 (2014). [cited by applicant]
Lavin, Alexander; Ahmad, Subutai. Evaluating Real-time Anomaly DetectionAlgorithms—the Numenta Anomaly Benchmark. 2015 IEEE 14th International Conference on Machine Learning and Applications. https://ieeexplore.ieee.org… [cited by applicant]
Laxhammar, R., and Falkman, Goran., “Online Learning and Sequential Anomaly Detection in Trajectories”, IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 36, Issue: 6, pp. 1-16 (Year: 2013). [cited by applicant]
Qin, D., et al., “Virtual machine anomaly detection based on partitioning detection domain,” 2016 7th IEEE International Conference on Software Engineering and Service Science (ICSESS), pp. 434-437 (2016). [cited by applicant]
Rana, A.I., et al., “Anomaly Detection Guidelines for Data Streams in Big Data,” 2016 3rd International Conference on Soft Computing & Machine Intelligence (ISCMI), pp. 94-98 (2016). [cited by applicant]
Dragos, M., et al. “Data Mining Methods for Anomaly Detection KDD-2005 Workshop Report. ACM SIGKDD Explorations Newsletter”, vol. 7, Issue: 2. https://dl.acm.org/citation.cfm?id=1117473 (Year: 2005). [cited by applicant]
Mohiuddin, S., et al., “Statistical Technique for Online Anomaly Detection Using Spark Over Heterogeneous Data from Multi-source VMware Performance Data”, 2014 IEEE International Conference on Big Data. https://ieeexplo… [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com, pp. 66. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com, pp. 17. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020, pp. 6. [cited by applicant]
Yasami, Y., et al., “Stochastic learning automata-based time series analysis for network anomaly detection”, 2008 International Conference on Telecommunications, pp. 1-6 (Year: 2008). [cited by applicant]