IP Library › Granted Patent US 12,461,840
Granted Patent B2
US 12,461,840 · App. 18/443,747 · Granted Nov 4, 2025

Cross-correlation of log patterns across information technology assets based on log timeline generation

Inventors: William S. Burney (Apex, NC); Raghav Chitta Nagaraj (Holly Springs, NC); Peixing Sun (Cary, NC)
Assignee: Dell Products L.P.
G06F11/3476G06F11/0793G06F11/3072
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,461,840
App. No.
18/443,747
Granted
Nov 4, 2025
Kind
B2
Abstract

An apparatus comprises at least one processing device configured to determine a set of one or more log patterns to utilize for scanning a set of logs associated with one or more information technology assets, a given one of the log patterns comprising a mapping between (i) at least a portion of a given raw log entry and (ii) a given descriptive textual label representing content of the given raw log entry. The at least one processing device is also configured to scan the set of logs associated with the one or more information technology assets to identify instances of the determined set of log patterns, to generate a log timeline of the identified instances of the determined set of log patterns, and to utilize the generated log timeline to cross-correlate the identified instances of the determined set of log patterns for the one or more information technology assets.

Claims (37)

1 . An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to determine a set of two or more log patterns to utilize for scanning a set of logs associated with a cluster of two one or more information technology assets, a given one of the set of two or more log patterns comprising a mapping between (i) at least a portion of a given raw log entry and (ii) a given descriptive textual label representing content of the given raw log entry;

to scan the set of logs associated with the cluster of two or more information technology assets to identify instances of the determined set of two or more log patterns;

to generate a log timeline of the identified instances of the determined set of two or more log patterns; and

to utilize the generated log timeline to cross-correlate the identified instances of the determined set of two or more log patterns for the cluster of two or more information technology assets, the generated log timeline consolidating a first set of events occurring on a first one of the two or more information technology assets in the cluster and a second set of events occurring on a second one of the two or more information technology assets in the cluster, the first set of events and the second set of events being associated with ones of the two or more log patterns in different ones of two or more functional areas of an information technology software stack running on the cluster of two or more information technology assets.

2 . The apparatus of claim 1 wherein the first information technology asset has a defined relationship with the second information technology asset.

3 . The apparatus of claim 2 wherein the defined relationship comprises a replication relationship.

4 . The apparatus of claim 1 wherein the set of two or more log patterns is determined by parsing one or more tags, a given one of the one or more tags comprising at least two log patterns associated with a given event type.

5 . The apparatus of claim 4 wherein the at least two log patterns in the given one of the one or more tags comprise:

at least a first log pattern in a first one of the two or more functional areas of the information technology software stack running on the cluster of two or more information technology assets; and

at least a second log pattern in a second one of the two or more functional areas of the information technology software stack running on the cluster of two or more information technology assets, the second functional area being different than the first functional area.

6 . The apparatus of claim 1 wherein the set of two or more log patterns is determined by parsing two or more log pattern configuration files, and wherein the two or more log configuration pattern files are associated with different functional areas of the information technology software stack running on the cluster of two or more information technology assets.

7 . The apparatus of claim 1 wherein the set of two or more log patterns is determined by parsing two or more tag configuration files, and wherein the two or more tag configuration files are associated with two or more different types of operations of the information technology software stack running on the cluster of two or more information technology assets.

8 . The apparatus of claim 7 wherein a given one of the two or more different types of operations comprise a first set of one or more log patterns from a first functional area of the information technology software stack running on the cluster of two or more information technology assets and a second set of one or more log patterns from a second functional area of the information technology software stack running on the cluster of two or more information technology assets.

9 . The apparatus of claim 1 wherein the given one of the set of two or more log patterns utilizes regular expression matching for mapping (i) said at least a portion of the given raw log entry to (ii) the given descriptive textual label representing the content of the given raw log entry.

10 . The apparatus of claim 1 wherein the generated log timeline consolidates the first set of events occurring on the first information technology asset and the second set of events occurring on the second information technology asset into a single visualization.

11 . The apparatus of claim 1 wherein the generated log timeline utilizes a tabular format with tabs corresponding to the two or more information technology assets and entries for different times having descriptive textual labels representing the content of raw log entries for events occurring on respective ones of the two or more information technology assets at the different times.

12 . The apparatus of claim 1 wherein the at least one processing device is further configured to perform remediation of the diagnosed at least one issue encountered on said at least one of the two or more information technology assets.

13 . The apparatus of claim 1 wherein the at least one processing device is further configured to diagnose at least one issue encountered on at least one of the two or more information technology assets utilizing the cross-correlated instances of the determined set of two or more log patterns.

14 . A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device:

to determine a set of two or more log patterns to utilize for scanning a set of logs associated with a cluster of two or more information technology assets, a given one of the set of two or more log patterns comprising a mapping between (i) at least a portion of a given raw log entry and (ii) a given descriptive textual label representing content of the given raw log entry;

to scan the set of logs associated with the cluster of two or more information technology assets to identify instances of the determined set of two or more log patterns;

to generate a log timeline of the identified instances of the determined set of two or more log patterns; and

to utilize the generated log timeline to cross-correlate the identified instances of the determined set of two or more log patterns for the cluster of two or more information technology assets, the generated log timeline consolidating a first set of events occurring on a first one of the two or more information technology assets in the cluster and a second set of events occurring on a second one of the two or more information technology assets in the cluster, the first set of events and the second set of events being associated with ones of the two or more log patterns in different ones of two or more functional areas of an information technology software stack running on the cluster of two or more information technology assets.

15 . The computer program product of claim 14 wherein the set of two or more log patterns are determined by parsing two or more tag configuration files, and wherein the two or more tag configuration files are associated with two or more different types of operations of the information technology software stack running on the cluster of two or more information technology assets.

16 . The computer program product of claim 14 wherein the generated log timeline utilizes a tabular format with tabs corresponding to the two or more information technology assets and entries for different times having descriptive textual labels representing the content of raw log entries for events occurring on respective ones of the two or more information technology assets at the different times.

17 . A method comprising:

determining a set of two or more log patterns to utilize for scanning a set of logs associated with a cluster of two or more information technology assets, a given one of the set of two or more log patterns comprising a mapping between (i) at least a portion of a given raw log entry and (ii) a given descriptive textual label representing content of the given raw log entry;

scanning the set of logs associated with the cluster of two or more information technology assets to identify instances of the determined set of two or more log patterns;

generating a log timeline of the identified instances of the determined set of two or more log patterns; and

utilizing the generated log timeline to cross-correlate the identified instances of the determined set of two or more log patterns for the cluster of two or more information technology assets, the generated log timeline consolidating a first set of events occurring on a first one of the two or more information technology assets in the cluster and a second set of events occurring on a second one of the two or more information technology assets in the cluster, the first set of events and the second set of events being associated with ones of the two or more log patterns in different ones of two or more functional areas of an information technology software stack running on the cluster of two or more information technology assets;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

18 . The method of claim 17 wherein the set of two or more log patterns are determined by parsing two or more tag configuration files, and wherein the two or more tag configuration files are associated with two or more different types of operations of the information technology software stack running on the cluster of two or more information technology assets.

19 . The method of claim 17 wherein the generated log timeline utilizes a tabular format with tabs corresponding to the two or more information technology assets and entries for different times having descriptive textual labels representing the content of raw log entries for events occurring on respective ones of the two or more information technology assets at the different times.

20 . The method of claim 17 wherein the first information technology asset has a replication relationship with the second information technology asset.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2024
From: BURNEY, WILLIAM S.; CHITTA NAGARAJ, RAGHAV; SUN, PEIXING
To: DELL PRODUCTS L.P.
Reel/Frame 066755/0778 →
Continuity (1)
Related Publication 20250265170A1 · Aug 21, 2025
References Cited (14)
US 8250408B1 · Cohen · 2012 [cited by examiner]
US 8918673B1 · Rangaiah · 2014 [cited by examiner]
US 10528454B1 · Baraty · 2020 [cited by examiner]
US 12189506B1 · Wang · 2025 [cited by examiner]
US 20150294007A1 · Chen · 2015 [cited by examiner]
US 20200184355A1 · Mehta · 2020 [cited by examiner]
US 20210342204A1 · Choudhury · 2021 [cited by examiner]
US 20210406112A1 · Moss · 2021 [cited by examiner]
US 20230051921A1 · Madala · 2023 [cited by examiner]
Sematext Group, “What Is ELK Stack: Tutorial on How to Use It for Log Management,” https://sematext.com/guides/elk-stack/#:˜:text=Thus%2C ELK is a log,visualize it in real time, Accessed Feb. 1, 2024, 16 pages. [cited by applicant]
Solarwinds, “Using Journalctl,” https://www.loggly.com/ultimate-guide/using-journalctl/, Accessed Feb. 1, 2024, 9 pages. [cited by applicant]
R. Gheorghe, “Tutorial: Logging with Journald,” https://sematext.com/blog/journald-logging-tutorial/, Apr. 28, 2020, 20 pages. [cited by applicant]
Dell Technologies, “Dell PowerStore,” Data Sheet, H18234, Oct. 2023, 4 pages. [cited by applicant]
J. Schafer, “Why Journald?” https://www.loggly.com/blog/why-journald/, Jan. 5, 2016, 9 pages. [cited by applicant]