IP Library › Granted Patent US 12,499,027
Granted Patent B2
US 12,499,027 · App. 17/715,443 · Granted Dec 16, 2025

Models for detecting and managing excessive log patterns

Inventors: Nagarajan Muthukrishnan (Foster City, CA); Ravi Shankar Thammaiah (Redwood City, CA); Sumanta Kumar Chatterjee (Menlo Park, CA); Binoy Sukumaran (Foster City, CA); Abhishek Chitre (Karnataka, IN); Mohit Singal (Karnataka, IN)
Assignee: Oracle International Corporation
G06F11/3072G06F11/3006G06F11/3476G06F16/1734G06F16/174
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,027
App. No.
17/715,443
Filed
Apr 7, 2022
Granted
Dec 16, 2025
Kind
B2
Art Unit
2161
USPC
707/822
Abstract

Embodiments described herein include a log management system that detects and addresses excessive log patterns at runtime. In some embodiments, the log management system tracks cumulative attributes associated with patterns that repeat within a set monitoring files, such as a set of log or trace records. The cumulative attributes that are monitored may include the cumulative storage size and/or cumulative count of patterns detected in the monitoring files. The log management system may determine whether a triggering condition is satisfied for initiating a responsive action to reduce the amount of log data that is transmitted and/or stored. If the triggering condition is satisfied, then the log management system may remove one or more instances of the pattern from the monitoring files and/or perform other actions to reduce the overhead of logging operations.

Claims (62)

1 . One or more non-transitory computer-readable media storing instructions which, when executed by one or more hardware processors, cause:

identifying, by a log management system during runtime of a computer system that records log entries associated with events to one or more log files, a plurality of instances of a text pattern in the one or more log files;

determining, by the log management system, a cumulative attribute associated with the text pattern, wherein the cumulative attribute comprises at least one of a cumulative storage size associated with the plurality of instances of the text pattern in the one or more log files or a cumulative count of the plurality of instances of the text pattern in the one or more log files;

determining, by the log management system, that a triggering condition is satisfied based at least on the cumulative attribute associated with the text pattern; and

responsive to determining that the triggering condition is satisfied: performing, by the log management system, at least one action that reduces computational resources consumed in association with a future event,

wherein the at least one action does not prevent the future event from occurring,

wherein without the at least one action, the future event would trigger storage of at least one log entry comprising at least one instance of the text pattern in the one or more log files, and

wherein the at least one action comprises at least one of:

filtering the at least one instance of the text pattern to prevent storage of the at least one log entry in the one or more log files,

filtering the at least one instance of the text pattern to omit the at least one instance of the text pattern from the at least one log entry, or

limiting further generation of log messages conforming to log entries comprising the text pattern.

2 . The media of claim 1 ,

wherein the at least one action further comprises modifying at least one of the log files to one or more instances of the text pattern within the one or more log files, and

wherein the instructions further cause:

retaining, within the one or more log files, at least one message that conforms to the text pattern.

3 . The media of claim 1 , wherein the instructions further cause:

determining whether the text pattern has been registered as a known problem;

responsive to determining that the text pattern has not been registered as a known problem:

storing the text pattern in a pattern repository; and

generating a classification for the text pattern based at least in part on which components in a computing system generated messages conforming to the text pattern in the one or more log files.

4 . The media of claim 3 , wherein the instructions further cause: sending an alert to one or more recipients that are determined based at least in part on the classification for the text pattern.

5 . The media of claim 1 , wherein determining that the triggering condition is satisfied comprises determining that the cumulative storage size for at least one of the one or more log files exceeds a threshold.

6 . The media of claim 1 , wherein determining that the triggering condition is satisfied comprises determining that the cumulative storage size for the text pattern across a plurality of log files exceeds a threshold.

7 . The media of claim 1 , wherein determining that the triggering condition is satisfied comprises determining that the cumulative count for the text pattern exceeds a threshold.

8 . The media of claim 1 , wherein the one or more log files store log messages generated by a plurality of components within a computing system, wherein a plurality of different log messages generated by two or more components of the plurality of components are mapped to the text pattern.

9 . The media of claim 1 , wherein the instructions further cause:

responsive to determining the triggering condition is satisfied, generating an analytic report that identifies the cumulative count of the text pattern in the one or more log files and one or more sources that caused generation of the text pattern in the one or more log files.

10 . One or more non-transitory computer-readable media storing instructions which, when executed by one or more hardware processors cause:

identifying at least a first text pattern in a first set of log data;

generating a pattern representation for the first text pattern based at least in part on overlapping parts of two or more messages in the set of log data that conform to the first text pattern;

generating a pattern classification for the first text pattern based at least in part on whether the first text pattern is associated with problematic behavior;

mapping, within a pattern repository, the pattern representation for the first text pattern to the pattern classification;

detecting, by a log management system during runtime of a computer system that records log entries associated with events to one or more log files as a second set of log data, one or more messages in the second set of log data that match the first text pattern; and

responsive to detecting the one or more messages in the second set of log data that match the first text pattern: performing, by the log management system, at least one action that reduces computational resources consumed in association with a future event,

wherein the at least one action does not prevent the future event from occurring,

wherein without the at least one action, the future event would trigger storage of at least one instance of the first text pattern in the one or more log files, and

wherein the at least one action comprises at least one of:

filtering the at least one instance of the text pattern to prevent storage of the at least one log entry in the one or more log files,

filtering the at least one instance of the text pattern to omit the at least one instance of the text pattern from the at least one log entry, or

limiting further generation of log entries comprising the text pattern.

11 . The media of claim 10 , wherein generating the pattern representation for the first text pattern comprises substituting at least one variable portion of the two or more messages with at least one metacharacter or placeholder value.

12 . The media of claim 10 , wherein the pattern representation for the first text pattern is a regional expression comprising at least one metacharacter and at least one literal.

13 . The media of claim 10 , wherein the instructions further cause:

training a machine learning model to classify log patterns based on features associated with the log patterns; and

applying the machine learning model to the first text pattern to generate the pattern classification.

14 . The media of claim 10 , wherein the pattern classification is generated based at least in part on a set of metrics associated with execution of the first text pattern.

15 . The media of claim 10 , wherein the instructions further cause:

publishing the first text pattern to a plurality of nodes in a distributed compute environment;

wherein the plurality of nodes monitor local log data for the first text pattern.

16 . One or more non-transitory computer-readable media storing instructions which, when executed by one or more hardware processors cause:

training a machine learning model to classify text patterns detected in log data;

identifying, by a log management system during runtime of a computer system in which events are logged to one or more log files as a set of log data, a text pattern in the set of log data;

applying, by the log management system, the machine learning model to generate a classification for the text pattern in the set of log data; and

based at least in part on the classification for the text pattern in the set of log data: performing, by the log management system, at least one action that reduces computational resources consumed in association with a future event,

wherein the at least one action does not prevent the future event from occurring,

wherein without the at least one action, the future event would trigger storage of at least one instance of the text pattern in the one or more log files, and

wherein the at least one action comprises at least one of:

filtering the at least one instance of the text pattern to prevent storage of the at least one log entry in the one or more log files,

filtering the at least one instance of the text pattern to omit the at least one instance of the text pattern from the at least one log entry, or

limiting further generation of log entries comprising the text pattern.

17 . The media of claim 16 , wherein applying the machine learning model to generate the classification for the text pattern comprises estimating a label for the text pattern based at least in part on a feature vector associated with the text pattern.

18 . The media of claim 17 , wherein the feature vector is generated based at least in part on a set of metrics associated with executing the text pattern.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2022
From: MUTHUKRISHNAN, NAGARAJAN; THAMMAIAH, RAVI SHANKAR; CHATTERJEE, SUMANTA KUMAR; SUKUMARAN, BINOY; CHITRE, ABHISHEK; SINGAL, MOHIT
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 059533/0439 →
Continuity (1)
Related Publication 20230325294A1 · Oct 12, 2023
References Cited (23)
US 10817604B1 · Kimball · 2020 [cited by examiner]
US 10885167B1 · Lador et al. · 2021 [cited by applicant]
US 11113144B1 · Gadepalli · 2021 [cited by examiner]
US 20090187560A1 · Arning · 2009 [cited by examiner]
US 20130332601A1 · Nakil · 2013 [cited by examiner]
US 20140157407A1 · Krishnan · 2014 [cited by examiner]
US 20150101044A1 · Martin et al. · 2015 [cited by applicant]
US 20170031741A1 · Seigel · 2017 [cited by applicant]
US 20170180187A1 · Whitner et al. · 2017 [cited by applicant]
US 20180059965A1 · Goodman · 2018 [cited by examiner]
US 20180060191A1 · Goodman · 2018 [cited by examiner]
US 20180107411A1 · Goodman · 2018 [cited by examiner]
US 20190079818A1 · Handa et al. · 2019 [cited by applicant]
US 20190182101A1 · Kulshreshtha · 2019 [cited by examiner]
US 20190332508A1 · Goyal · 2019 [cited by examiner]
US 20190340057A1 · Brown et al. · 2019 [cited by applicant]
US 20200125725A1 · Petersen et al. · 2020 [cited by applicant]
US 20210406106A1 · Moss · 2021 [cited by examiner]
US 20210406112A1 · Moss · 2021 [cited by examiner]
US 20220012633A1 · Molahalli · 2022 [cited by examiner]
US 20220197717A1 · Pandey · 2022 [cited by examiner]
US 20230229540A1 · King · 2023 [cited by examiner]
US 20230325294A1 · Muthukrishnan · 2023 [cited by examiner]