IP Library Granted Patent US 8,875,129
Granted Patent B2
US 8,875,129 · App. 12/701,493 · Granted Oct 28, 2014

Systems and methods for monitoring and alerting events that virtual machine software produces in a virtual infrastructure

Inventors: Andrew Wagner (Portland, OR); Chyna Trople (Portland, OR); Robert DiFalco (Portland, OR)
Assignee: Tripwire, Inc.
G06F9/542
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,875,129
App. No.
12/701,493
Granted
Oct 28, 2014
Kind
B2
Abstract

Embodiments of the present disclosure provide methods and systems for generating an alert based upon detection of a pattern of events within a virtual infrastructure. Other embodiments may be described and claimed.

Claims (52)

1. A method of managing a computer network configured with a virtual infrastructure, the virtual infrastructure comprising one or more first hosts configured to include a plurality of virtual machines and virtual objects and one or more second hosts configured to include a virtual center server and a monitoring component configured to monitor the virtual infrastructure, the first hosts and the second hosts being different physical hosts, the method comprising:

defining one or more patterns of virtual machine events detectable within at least one of the virtual machines and/or at least one of the virtual objects of the one or more first hosts, the virtual machine events including changes in configuration and conditions of the virtual infrastructure;

with the virtual center server, detecting a plurality of virtual machine events within one or more of the at least one of the virtual machines and/or the virtual objects and communicating the detected virtual machine events to the monitoring component;

with the monitoring component, monitoring the virtual infrastructure based on the communicated virtual machine events to detect at least one of the patterns of virtual machine events in the virtual infrastructure;

correlating at least one of the detected conditions for a first one of the virtual machines or virtual objects to a second one of the virtual machines or objects; and

if the at least one pattern of virtual machine events is detected for the second one of the virtual machines or objects, generating an alert in response to the detection of the pattern.

2. The method of claim 1 , wherein multiple patterns of events are defined relating to multiple virtual machines and multiple virtual objects.

3. The method of claim 1 , further comprising generating a flag for at least one virtual machine and/or at least one virtual object that is affected by occurrence of the at least one pattern of virtual machine events.

4. The method of claim 1 , further comprising remediating one or more virtual machine events with respect to the affected at least one virtual machine and/or virtual object.

5. The method of claim 4 , wherein the remediating is performed automatically.

6. The method of claim 1 , wherein multiple virtual machines and/or virtual objects are affected by occurrence of the pattern of virtual machine events and the method further comprises correlating the affected virtual machines and/or the virtual objects.

7. The method of claim 6 , further comprising generating a flag for each affected virtual machine and/or virtual object.

8. The method of claim 6 , further comprising remediating one or more virtual machine events with respect to the affected virtual machines and/or virtual objects.

9. The method of claim 1 , wherein the pattern of events includes at least one or more of the following: configuration change events, virtual machine events, and relationship change events.

10. The method of claim 1 , wherein the pattern of events includes at least one or more of the following: event occurrences, configuration changes, and conditions that may cause an alert.

11. The method of claim 1 , wherein the pattern of events includes multiple occurrences of an event but not a single occurrence of the event.

12. The method of claim 1 , wherein the configuration changes include changes to the security policy of a virtual network.

13. The method of claim 1 , wherein the configuration changes include modifications to resource allocations within a resource pool.

14. The method of claim 1 , wherein the conditions include at least one or more of the following: detection of snapshots that are older than a predefined threshold, detection of datastores with less than a predefined threshold of free space, or detected failure of a Logical Unit Number path.

15. The method of claim 1 , wherein the conditions include detection of a failed vMotion.

16. A system comprising:

a virtual infrastructure implemented on one or more physical hosts, the virtual infrastructure comprising:

a virtual control center comprising a component that provides control and intra-partitioning of the physical hosts into the virtual infrastructure, each of the partitioned hosts comprising:

at least one virtual machine, and

at least one virtual object,

wherein the virtual control center is configured to detect virtual machine events in the at least one virtual machine and the at least one virtual object; and

a component configured to:

define at least one pattern of multiple virtual machine migration events detectable within the virtual infrastructure,

monitor the virtual infrastructure by receiving detected virtual machine events from the virtual control center, and

if the at least one pattern is detected, generate an alert in response to detection of the pattern.

17. The system of claim 16 , wherein multiple patterns of virtual machine migration events are defined relating to multiple virtual machines and multiple virtual objects.

18. The system of claim 16 , wherein the component is further configured to generate a flag for at least one virtual machine and/or at least one virtual object that is affected by occurrence of the at least one pattern of events.

19. The system of claim 16 , wherein the component is further configured to remediate one or more events with respect to the affected at least one virtual machine and/or virtual object.

20. The system of claim 19 , wherein the remediating is performed automatically.

21. The system of claim 16 , wherein multiple virtual machines and/or virtual objects are affected by occurrence of the pattern of virtual machine migration events and the component is further configured to correlate the affected virtual machines and/or the virtual objects.

22. The system of claim 21 , wherein the component is further configured to generate a flag for each affected virtual machine and/or virtual object.

23. The system of claim 21 , wherein the component is further configured to remediate one or more events with respect to the affected virtual machines and/or virtual objects.

24. The system of claim 23 , wherein the remediating is performed automatically.

25. The system of claim 16 , wherein the migration events include the assignment of a host to a cluster of hosts.

26. The system of claim 16 , wherein the migration events include the detection of a failed migration event.

27. One or more machine-accessible storage memory storing software instructions that when executed by one or more processors within a computing environment cause the processors to perform a method, the method comprising:

receiving at least one pattern of events defined by a user or system administrator for a virtual infrastructure relating to at least one virtual machine and/or at least one virtual object implemented on one or more physical hosts in the virtual infrastructure;

monitoring the virtual infrastructure for the occurrence of the pattern of events;

if the at least one pattern of events is detected within a first one of the at least one virtual machine or the virtual object, generating an alert for a second affected one of the at least one virtual machine or the virtual object in response to detection of the pattern based on a correlation of the detected pattern of events to a pattern of events for the second affected virtual machine or virtual object;

remediating one or more events with respect to the first virtual machine or object and the second affected at least one virtual machine and/or virtual object; and

marshaling the second affected virtual machine or virtual object.

28. The storage memory of claim 27 , wherein multiple patterns of events are defined relating to multiple virtual machines and multiple virtual objects.

29. The storage memory of claim 27 , wherein the plurality of operations further comprise generating a flag for at least one virtual machine and/or at least one virtual object that is affected by occurrence of the at least one pattern of events.

30. The storage memory of claim 27 , wherein the remediating is performed manually.

31. The storage memory of claim 27 , wherein the remediating is performed automatically.

32. The storage memory of claim 27 , wherein multiple virtual machines and/or virtual objects are affected by occurrence of the pattern of events and the plurality of operations further comprise correlating the affected virtual machines and/or the virtual objects.

33. The storage memory of claim 32 , wherein the plurality of operations further comprise generating a flag for each affected virtual machine and/or virtual object.

Assignments (14)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
SECURITY AGREEMENT Recorded May 23, 2011
From: TRIPWIRE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 026322/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2010
From: WAGNER, ANDREW; TROPLE, CHYNA; DIFALCO, ROBERT
To: TRIPWIRE, INC.
Reel/Frame 023918/0808 →
Continuity (1)
Related Publication 20110197205A1 · Aug 11, 2011