IP Library › Granted Patent US 12,406,026
Granted Patent B2
US 12,406,026 · App. 17/363,147 · Granted Sep 2, 2025

Abnormal log event detection and prediction

Inventors: Yi Ming Wang (Xian, CN); Hui Dong (Xian, CN); Zhong Fang Yuan (Xian, CN); Tong Liu (Xian, CN); Yan Fen Liu (Tianjin, CN); Ling Chen (Beijing, CN)
Assignee: International Business Machines Corporation
G06F18/23213G06F16/1805G06F16/90332G06F16/906G06F18/214
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,406,026
App. No.
17/363,147
Filed
Jun 30, 2021
Granted
Sep 2, 2025
Kind
B2
Art Unit
2162
USPC
707/737
Abstract

The embodiments of the present disclosure disclose a computer-implemented method, computer system and a computer program product for detecting and predicting an abnormal log event. In the method, a current event cluster from a plurality of event clusters for a log line in a log file is determined. The plurality of event clusters include at least one abnormal event cluster. Then, a time of event transition from the current event cluster to at least one abnormal event cluster is predicted.

Claims (69)

1. A computer-implemented method comprising:

receiving a current log line of a log file indicative of a current log event reflecting a portion of processing performed by one or more computer(s) in an information technology (IT) system;

categorizing the current log event as belonging to a first event cluster of a plurality of event clusters with the first event cluster being a central processing unit (CPU) normal type cluster;

determining a probability value that the first event cluster will be followed by event(s) from a second event cluster of the plurality of event clusters, with the second event cluster being a CPU abnormal type cluster;

responsive to determining the probability value that the first event cluster will be followed by the event(s) from the second event cluster, determining that the probability value exceeds a first threshold;

responsive to determining that the probability value exceeds the first threshold, predicting, by machine logic, a predicted time of event transition from a time of the current log event until event(s) of the second event cluster are likely to occur;

responsive to predicting the predicted time of the event transition, determining that the predicted time of the event transition from the time of the current log event until event(s) of the second event cluster are likely to occur is below a second threshold; and

responsive to the determination that the probability value that the first event cluster will be followed by the event(s) from the second event cluster exceeds the first threshold and further responsive to the determination that the predicted time of the event transition is below the second threshold, communicating a warning that abnormal CPU operations are likely to occur so that countermeasures can be taken so that the CPU remains operational, wherein predicting the predicted time of the event transition comprises:

obtaining, by one or more processors, a probability of the event transition from the current event cluster to each of the plurality of event clusters to form a plurality of obtained event transitions;

determining, by the one or more processors, an obtained event transition having a highest probability from the plurality of obtained event transitions; and

in response to the obtained event transition having the highest probability being directed to at least one abnormal event cluster, calculating, by the one or more processors, a mean time of the obtained event transition having the highest probability in an operational history of the IT system as the predicted time.

2. The computer-implemented method of claim 1 , further comprising:

converting the current log line to a sentence vector:

determining relevance between the sentence vector and the plurality of event clusters; and

determining the current event cluster based on the relevance between the sentence vector and the plurality of event clusters.

3. The computer-implemented method of claim 2 , wherein the first event cluster is determined based on relevance between the sentence vector and the plurality of event clusters.

4. The computer-implemented method of claim 1 , wherein the warning comprises the probability value and the predicted time.

5. The computer-implemented method of claim 1 , further comprising:

in response to the obtained event transition having the highest probability not being directed to the at least one abnormal event cluster;

determining, by the one or more processors, a next event cluster from the plurality of event clusters for a next log line in the log file; and

predicting, by the one or more processors, a time of event transition from the next event cluster to the at least one abnormal event cluster.

6. The computer-implemented method of claim 1 , wherein the plurality of event clusters comprises CPU normal, CPU abnormal, memory normal, memory abnormal, disk normal, and disk abnormal.

7. A computer program product comprising program code executable by a processor to perform steps of:

receiving a current log line of a log file indicative of a current log event reflecting a portion of processing performed by one or more computer(s) in an information technology (IT) system;

categorizing the current log event as belonging to a first event cluster of a plurality of event clusters with the first event cluster being a disk normal type cluster;

determining a probability value that the first event cluster will be followed by event(s) from a second event cluster of the plurality of event clusters, with the second event cluster being a disk abnormal type cluster;

responsive to determining the probability value that the first event cluster will be followed by the event(s) from the second event cluster, determining that the probability value exceeds a first threshold;

responsive to determining that the probability value exceeds the first threshold, predicting, by machine logic, a predicted time of event transition from a time of the current log event until event(s) of the second event cluster are likely to occur;

responsive to predicting the predicted time of the event transition, determining that the predicted time of the event transition from the time of the current log event until event(s) of the second event cluster are likely to occur is below a second threshold; and

responsive to the determination that the probability value that the first event cluster will be followed by the event(s) from the second event cluster exceeds the first threshold and further responsive to the determination that the predicted time of the event transition is below the second threshold, communicating a warning that abnormal disk operations are likely to occur so that countermeasures can be taken so that the disk remains operational, wherein predicting the predicted time of the event transition comprises:

obtaining, by one or more processors, a probability of the event transition from the current event cluster to each of the plurality of event clusters to form a plurality of obtained event transitions;

determining, by the one or more processors, an obtained event transition having a highest probability from the plurality of obtained event transitions; and

in response to the obtained event transition having the highest probability being directed to at least one abnormal event cluster, calculating, by the one or more processors, a mean time of the obtained event transition having the highest probability in an operational history of the IT system as the predicted time.

8. The computer program product of claim 7 , further comprising:

converting the current log line to a sentence vector:

determining relevance between the sentence vector and the plurality of event clusters; and

determining the current event cluster based on the relevance between the sentence vector and the plurality of event clusters.

9. The computer program product of claim 8 , wherein the first event cluster is determined based on relevance between the sentence vector and the plurality of event clusters.

10. The computer program product of claim 7 , wherein the warning comprises the probability value and the predicted time.

11. The computer program product of claim 7 , further comprising:

in response to the obtained event transition having the highest probability not being directed to the at least one abnormal event cluster;

determining, by the one or more processors, a next event cluster from the plurality of event clusters for a next log line in the log file; and

predicting, by the one or more processors, a time of event transition from the next event cluster to the at least one abnormal event cluster.

12. The computer program product of claim 7 , wherein the plurality of event clusters comprises CPU normal, CPU abnormal, memory normal, memory abnormal, disk normal, and disk abnormal.

13. The computer program product of claim 7 , where each event cluster of the plurality of event clusters includes one or more log events.

14. A computer system comprising:

a processor coupled to a memory including instructions executable by the processor to perform steps of:

receiving a current log line of a log file indicative of a current log event reflecting a portion of processing performed by one or more computer(s) in an information technology (IT) system;

categorizing the current log event as belonging to a first event cluster of a plurality of event clusters with the first event cluster being a memory normal type cluster;

determining a probability value that the first event cluster will be followed by event(s) from a second event cluster of the plurality of event clusters, with the second event cluster being a memory abnormal type cluster;

responsive to determining the probability value that the first event cluster will be followed by the event(s) from the second event cluster, determining that the probability value exceeds a first threshold;

responsive to determining that the probability value exceeds the first threshold, predicting, by machine logic, a predicted time of event transition from a time of the current log event until event(s) of the second event cluster are likely to occur;

responsive to predicting the predicted time of the event transition, determining that the predicted time of the event transition from the time of the current log event until event(s) of the second event cluster are likely to occur is below a second threshold; and

responsive to the determination that the probability value that the first event cluster will be followed by the event(s) from the second event cluster exceeds the first threshold and further responsive to the determination that the predicted time of the event transition is below the second threshold, communicating a warning that abnormal memory operations are likely to occur so that countermeasures can be taken so that the memory remains operational, wherein predicting the predicted time of the event transition comprises:

obtaining, by one or more processors, a probability of the event transition from the current event cluster to each of the plurality of event clusters to form a plurality of obtained event transitions;

determining, by the one or more processors, an obtained event transition having a highest probability from the plurality of obtained event transitions; and

in response to the obtained event transition having the highest probability being directed to at least one abnormal event cluster, calculating, by the one or more processors, a mean time of the obtained event transition having the highest probability in an operational history of the IT system as the predicted time.

15. The computer system of claim 14 , further comprising:

converting the current log line to a sentence vector:

determining relevance between the sentence vector and the plurality of event clusters; and

determining the current event cluster based on the relevance between the sentence vector and the plurality of event clusters.

16. The computer system of claim 15 , wherein the first event cluster is determined based on relevance between the sentence vector and the plurality of event clusters.

17. The computer system of claim 14 , wherein the warning comprises the probability value and the predicted time.

18. The computer system of claim 14 , further comprising:

in response to the obtained event transition having the highest probability not being directed to the at least one abnormal event cluster;

determining, by the one or more processors, a next event cluster from the plurality of event clusters for a next log line in the log file; and

predicting, by the one or more processors, a time of event transition from the next event cluster to the at least one abnormal event cluster.

19. The computer system of claim 14 , wherein the plurality of event clusters comprises CPU normal, CPU abnormal, memory normal, memory abnormal, disk normal, and disk abnormal.

20. The computer system of claim 14 , where each event cluster of the plurality of event clusters includes one or more log events.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2021
From: WANG, YI MING; DONG, HUI; YUAN, ZHONG FANG; LIU, TONG; LIU, YAN FEN; CHEN, LING
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 056715/0387 →
Continuity (1)
Related Publication 20230004750A1 · Jan 5, 2023
References Cited (44)
US 9306962B1 · Pinto · 2016 [cited by examiner]
US 10083403B2 · Flores · 2018 [cited by examiner]
US 10409789B2 · Zoll · 2019 [cited by examiner]
US 10530809B1 · Hart · 2020 [cited by examiner]
US 11226858B1 · Srivastava · 2022 [cited by examiner]
US 11336507B2 · Acharjee · 2022 [cited by examiner]
US 11436631B2 · Lyman · 2022 [cited by examiner]
US 11477077B1 · Berg · 2022 [cited by examiner]
US 20010019586A1 · Kang · 2001 [cited by examiner]
US 20010051928A1 · Brody · 2001 [cited by examiner]
US 20080250265A1 · Chang · 2008 [cited by examiner]
US 20110220779A1 · Takaoka · 2011 [cited by examiner]
US 20120047548A1 · Rowlands · 2012 [cited by examiner]
US 20130086431A1 · Arndt · 2013 [cited by examiner]
US 20150278603A1 · Boriah · 2015 [cited by examiner]
US 20160019470A1 · Lightner · 2016 [cited by examiner]
US 20160299938A1 · Malhotra · 2016 [cited by examiner]
US 20170076217A1 · Krumm · 2017 [cited by examiner]
US 20170250855A1 · Patil · 2017 [cited by examiner]
US 20180285779A1 · Zhou · 2018 [cited by examiner]
US 20190286747A1 · Modarresi · 2019 [cited by examiner]
US 20190317961A1 · Brener · 2019 [cited by examiner]
US 20200160230A1 · Wang · 2020 [cited by examiner]
US 20200219372A1 · Kwatra · 2020 [cited by examiner]
US 20200349199A1 · Jayaraman · 2020 [cited by examiner]
US 20210357282A1 · Verma · 2021 [cited by examiner]
US 20210382746A1 · Sharma · 2021 [cited by examiner]
US 20210382770A1 · Lu · 2021 [cited by examiner]
US 20220103444A1 · Ranjan · 2022 [cited by examiner]
US 20220327204A1 · Abbaszadeh · 2022 [cited by examiner]
US 20220400060A1 · Sethi · 2022 [cited by examiner]
US 20220411094A1 · Dillard · 2022 [cited by examiner]
US 20230385342A1 · Berko · 2023 [cited by examiner]
CN 102831020A · 2012 [cited by applicant]
CN 103514398A · 2014 [cited by applicant]
CN 109086186A · 2018 [cited by applicant]
CN 111190804A · 2020 [cited by applicant]
CN 111611218A · 2020 [cited by examiner]
WO 2019060327A1 · 2019 [cited by applicant]
“Chapter 8: Markov Chains”, The University of Auckland, New Zealand, provided by inventors in invention record Aug. 24, 2020, <: https://www.stat.auckland.ac.nz/˜fewster/325/notes/ch8.pdf>, 25 pages. [cited by applicant]
“K-Nearest Neighbors Algorithm”, Wikipedia, the Free Encyclopedia, Wikimedia Foundation, last edited on Jun. 2, 2021, downloaded from the Internet on Jun. 7, 2021, 11 pgs., <https://en.wikipedia.org/wiki/K-nearest_neigh… [cited by applicant]
Kikos, et al., “Skip-Thought Vectors”, Advances in Neural Information Processing Systems 28 (NIPS 2015), Dec. 7-12, 2015, 9 pgs., Montreal, Canada, Neural Information Processing Systems Foundation. [cited by applicant]
Zhang et al., “Automated IT System Failure Prediction: A Deep Learning Approach”, Conference Paper—Dec. 2016, DOI: 10.1109/BigData.2016.7840733, ResearchGate, 11 pages. [cited by applicant]
Mell, et al., “The NIST Definition of Cloud Computing”, Recommendations of the National Institute of Standards and Technology, National Institute of Standard and Technology, U.S. Department of Commerce, Sep. 2011, 7 pgs… [cited by applicant]