IP Library Granted Patent US 11,586,972
Granted Patent B2
US 11,586,972 · App. 16/195,070 · Granted Feb 21, 2023

Tool-specific alerting rules based on abnormal and normal patterns obtained from history logs

Inventors: Yuan Wang (Beijing, CN); Lin Yang (Beijing, CN); Xiao Xi Liu (Beijing, CN); Fan Jing Meng (Beijing, CN); Jing Min Xu (Beijing, CN); William V. Da Palma (Coconut Creek, FL); Sandhya Kapoor (Austin, TX); Takayuki Kushida (Tokyo, JP); Hiroki Nakano (Shiga, JP)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06N20/00G06F16/2465G06N5/003G06F2216/03
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,586,972
App. No.
16/195,070
Granted
Feb 21, 2023
Kind
B2
Abstract

A computer-implemented method is presented for automatically generating alerting rules. The method includes identifying, via offline analytics, abnormal patterns and normal patterns from history logs based on machine learning, statistical analysis and deep learning, the history logs stored in a history log database, automatically generating the alerting rules based on the identified abnormal and normal patterns, and transmitting the alerting rules to an alerting engine for evaluation. The method further includes receiving a plurality of online log messages from a plurality of computing devices connected to a network, augmenting the plurality of online log messages, and extracting information from the plurality of augmented online log messages to be provided to the alerting engine, the alerting engine configured to approve and enforce the alerting rules automatically generated by the offline analytics processing.

Claims (49)

1. A computer-implemented method comprising:

collecting history logs until a collection threshold is met;

identifying, via offline analytics, abnormal patterns and normal patterns from the history logs based on machine learning, statistical analysis and deep learning, the history logs stored in a history log database;

feeding the abnormal patterns and the normal patterns to a subject matter expert (SME) validation module to make revisions or corrections to the abnormal patterns and the normal patterns;

automatically generating alerting rule candidates based on the identified abnormal and normal patterns detected in the history logs;

transmitting the alerting rule candidates to an alerting engine to assess whether the generated alerting rule candidates are accepted or discarded;

receiving a plurality of online log messages from a plurality of computing devices connected to a network;

augmenting the plurality of online log messages; and

extracting information from the plurality of augmented online log messages to be provided to the alerting engine, the alerting engine configured to approve and enforce the alerting rule candidates accepted by the alerting engine,

wherein the collection threshold is based on a total number of the history logs, a traffic type associated with each of the total number of the history logs, and a percentage of the total number of the history logs being of a certain traffic type.

2. The method of claim 1 , wherein the history logs are clustered into a plurality of clusters and analyzed to determine normal logs and abnormal logs.

3. The method of claim 2 , wherein rare logs are identified based on predetermined policies related to the abnormal logs.

4. The method of claim 2 , wherein the normal logs are exposed to log template mining techniques to create log templates.

5. The method of claim 4 , wherein variables are extracted from the log templates, the variables are identified by variable type, and feature extraction is performed on the variables.

6. The method of claim 1 , wherein the corrections to the abnormal patterns and the normal patterns by the SME validation module include filling in blank items.

7. The method of claim 1 , wherein the generated alerting rule candidates are provided to a knowledge database constructed from log message training data.

8. A non-transitory computer-readable storage medium comprising a computer-readable program executed on a processor in a data processing system, wherein the computer-readable program when executed on the processor causes a computer to perform the steps of:

collecting history logs until a collection threshold is met;

identifying, via offline analytics, abnormal patterns and normal patterns from the history logs based on machine learning, statistical analysis and deep learning, the history logs stored in a history log database;

feeding the abnormal patterns and the normal patterns to a subject matter expert (SME) validation module to make revisions or corrections to the abnormal patterns and the normal patterns;

automatically generating alerting rule candidates based on the identified abnormal and normal patterns detected in the history logs;

transmitting the alerting rule candidates to an alerting engine to assess whether the generated alerting rule candidates are accepted or discarded;

receiving a plurality of online log messages from a plurality of computing devices connected to a network;

augmenting the plurality of online log messages; and

extracting information from the plurality of augmented online log messages to be provided to the alerting engine, the alerting engine configured to approve and enforce the alerting rule candidates accepted by the alerting engine,

wherein the collection threshold is based on a total number of the history logs, a traffic type associated with each of the total number of the history logs, and a percentage of the total number of the history logs being of a certain traffic type.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the history logs are clustered into a plurality of clusters and analyzed to determine normal logs and abnormal logs.

10. The non-transitory computer-readable storage medium of claim 9 , wherein rare logs are identified based on predetermined policies related to the abnormal logs.

11. The non-transitory computer-readable storage medium of claim 9 , wherein the normal logs are exposed to log template mining techniques to create log templates.

12. The non-transitory computer-readable storage medium of claim 11 , wherein variables are extracted from the log templates, the variables are identified by variable type, and feature extraction is performed on the variables.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the corrections to the abnormal patterns and the normal patterns by the SME validation module include filling in blank items.

14. The non-transitory computer-readable storage medium of claim 8 , wherein the generated alerting rule candidates are provided to a knowledge database constructed from log message training data.

15. A system comprising:

a memory; and

one or more processors in communication with the memory configured to:

collect history logs until a collection threshold is met;

identify, via offline analytics, abnormal patterns and normal patterns from the history logs based on machine learning, statistical analysis and deep learning, the history logs stored in a history log database;

feed the abnormal patterns and the normal patterns to a subject matter expert (SME) validation module to make revisions or corrections to the abnormal patterns and the normal patterns;

automatically generate alerting rule candidates based on the identified abnormal and normal patterns detected in the history logs;

transmit the alerting rule candidates to an alerting engine to assess whether the generated alerting rule candidates are accepted or discarded;

receive a plurality of online log messages from a plurality of computing devices connected to a network;

augment the plurality of online log messages; and

extract information from the plurality of augmented online log messages to be provided to the alerting engine, the alerting engine configured to approve and enforce the alerting rule candidates accepted by the alerting engine,

wherein the collection threshold is based on a total number of the history logs, a traffic type associated with each of the total number of the history logs, and a percentage of the total number of the history logs being of a certain traffic type.

16. The system of claim 15 , wherein the history logs are clustered into a plurality of clusters and analyzed to determine normal logs and abnormal logs.

17. The system of claim 16 , wherein rare logs are identified based on predetermined policies related to the abnormal logs.

18. The system of claim 16 , wherein the normal logs are exposed to log template mining techniques to create log templates.

19. The system of claim 18 , wherein variables are extracted from the log templates, the variables are identified by variable type, and feature extraction is performed on the variables.

20. The system of claim 15 , wherein the corrections to the abnormal patterns and the normal patterns by the SME validation module include filling in blank items.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE SEVENTH INVENTOR'S SIGNATURE PREVIOUSLY RECORDED AT REEL: 047544 FRAME: 0077. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 4, 2023
From: WANG, YUAN; YANG, LIN; LIU, XIAO XI; MENG, FAN JING; XU, JING MIN; DA PALMA, WILLIAM V.; KAPOOR, SANDHYA; KUSHIDA, TAKAYUKI; NAKANO, HIROKI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062278/0283 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2018
From: WANG, YUAN; YANG, LIN; LIU, XIAO XI; MENG, FAN JING; XU, JING MIN; DA PALMA, WILLIAM V.; KAPOOR, SANDHYA; KUSHIDA, TAKAYUKI; NAKANO, HIROKI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047544/0077 →
Continuity (1)
Related Publication 20200160230A1 · May 21, 2020
Cited By (5)
US 12,277,137 US 12,452,261 US 12,474,978 US 12,676,868 US 12,737,253