IP Library › Granted Patent US 11,675,647
Granted Patent B2
US 11,675,647 · App. 17/034,730 · Granted Jun 13, 2023

Determining root-cause of failures based on machine-generated textual data

Inventors: Yaron Lehmann (Tel Aviv, IL); Gabby Menahem (Petach Tikva, IL); Dror Mann (Tel Aviv, IL)
Assignee: ServiceNow, Inc.
G06F11/079G06F11/0775
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,675,647
App. No.
17/034,730
Granted
Jun 13, 2023
Kind
B2
Abstract

A method and system for determining root-causes of incidences using machine-generated textual data. The method comprises receiving machine-generated textual data from at least one data source; classifying the received machine-generated textual data into at least one statistical metric; processing the statistical metric to recognize a plurality of incidence patterns; correlating the plurality of incidence patterns to identify at least a root-cause of an incidence that occurred in a monitored environment; and generating an alert indicating at least the identified root-cause.

Claims (44)

1. A system, comprising:

a processor; and

a memory, accessible by the processor, the memory storing instructions, that when executed by the processor, cause the processor to perform operations comprising:

receiving machine-generated textual data associated with one or more computing resources of a managed network;

classifying the machine-generated textual data into one or more statistical metrics;

identifying a plurality of incident patterns indicative of one or more potential incidents that might develop in the managed network based on the one or more statistical metrics;

correlating at least two incident patterns of the plurality of incident patterns;

determining a root cause of the one or more potential incidents associated with the at least two incident patterns; and

generating an alert for the one or more potential incidents associated with the at least two incident patterns, wherein the alert indicates the determined root cause.

2. The system of claim 1 , wherein the one or more statistical metrics are represented as a gauge, a meter, or a histogram, or a combination thereof.

3. The system of claim 1 , wherein classifying the machine-generated textual data into the one or more statistical metrics comprises:

processing the machine-generated textual data into one or more elements including one or more events, one or more tokens, one or more key-value pairs, or one or more properties, or a combination thereof, and

generating one or more graphical representations of the one or more statistical metrics based on the one or more elements.

4. The system of claim 3 , wherein the alert comprises the one or more elements.

5. The system of claim 1 , wherein the at least two incident patterns are correlated based on an amplitude of an incident pattern of the at least two incident patterns, a frequency of the incident pattern of the at least two incident patterns, or a similarity of the incident pattern of the at least two incident patterns to a previously detected incident pattern, or a combination thereof.

6. The system of claim 1 , wherein the operations comprise grouping the alert with one or more additional alerts generated at the same time or substantially at the same time.

7. The system of claim 1 , wherein the root cause of the one or more potential incidents associated with the at least two incident patterns is based on an increase in a trend of one of the at least two incident patterns toward a threshold, or a time proximity between respective anomalies in the at least two incident patterns, or both.

8. A method, comprising:

receiving, by one or more processors, machine-generated textual data associated with one or more computing resources of a managed network;

classifying, by the one or more processors, the machine-generated textual data into one or more statistical metrics;

identifying, by the one or more processors, a plurality of incident patterns indicative of one or more potential incidents that might develop in the managed network based on the one or more statistical metrics;

correlating, by the one or more processors, at least two incident patterns of the plurality of incident patterns;

determining, by the one or more processors, a root cause of the one or more potential incidents associated with the at least two incident patterns; and

generating, by the one or more processors, an alert for the one or more potential incidents associated with the at least two incident patterns, wherein the alert indicates the determined root cause.

9. The method of claim 8 , wherein the one or more statistical metrics are represented as a gauge, a meter, or a histogram, or a combination thereof.

10. The method of claim 8 , wherein classifying the machine-generated textual data into the one or more statistical metrics comprises:

processing, by the one or more processors, the machine-generated textual data into one or more elements including one or more events, one or more tokens, one or more key-value pairs, or one or more properties, or a combination thereof; and

generating, by the one or more processors, one or more graphical representations of the one or more statistical metrics based on the one or more elements.

11. The method of claim 10 , wherein the alert comprises the one or more elements.

12. The method of claim 8 , wherein the at least two incident patterns are correlated based on an amplitude of an incident pattern of the at least two incident patterns, a frequency of the incident pattern of the at least two incident patterns, or a similarity of the incident pattern of the at least two incident patterns to a previously detected incident pattern, or a combination thereof.

13. The method of claim 8 , comprising grouping the alert with one or more additional alerts generated at the same time or substantially at the same time.

14. The method of claim 8 , wherein the root cause of the one or more potential incidents associated with the at least two incident patterns is based on an increase in a trend of one of the at least two incident patterns toward a threshold, or a time proximity between respective anomalies in the at least two incident patterns, or both.

15. A non-transitory, computer-readable medium, comprising instructions that when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving machine-generated textual data associated with one or more computing resources of a managed network;

classifying the machine-generated textual data into one or more statistical metrics based on one or more elements;

identifying a plurality of incident patterns indicative of one or more potential incidents that might develop in the managed network based on the one or more statistical metrics;

correlating at least two incident patterns of the plurality of incident patterns;

determining a root cause of the one or more potential incidents associated with the at least two incident patterns; and

generating an alert for the one or more potential incidents associated with the at least two incident patterns, wherein the alert indicates the determined root cause.

16. The non-transitory, computer-readable medium of claim 15 , wherein the one or more statistical metrics are represented as a gauge, a meter, or a histogram, or a combination thereof.

17. The non-transitory, computer-readable medium of claim 15 , wherein the one or more elements comprise one or more events, one or more tokens, one or more key-value pairs, or one or more properties, or a combination thereof.

18. The non-transitory, computer-readable medium of claim 15 , wherein the at least two incident patterns are correlated based on an amplitude of an incident pattern of the at least two incident patterns, a frequency of the incident pattern of the at least two incident patterns, or a similarity of the incident pattern of the at least two incident patterns to a previously detected incident pattern, or a combination thereof.

19. The non-transitory, computer-readable medium of claim 15 , wherein the operations comprise grouping the alert with one or more additional alerts generated at the same time or substantially at the same time.

20. The non-transitory, computer-readable medium of claim 15 , wherein the root cause of the one or more potential incidents associated with the at least two incident patterns is based on an increase in a trend of one of the at least two incident patterns toward a threshold, or a time proximity between respective anomalies in the at least two incident patterns, or both.

Continuity (3)
Continuation 15499060 · Apr 27, 2017
Continuation In Part 15228272 · Aug 4, 2016
Related Publication 20210011793A1 · Jan 14, 2021