IP Library › Granted Patent US 12,511,297
Granted Patent B2
US 12,511,297 · App. 18/434,044 · Granted Dec 30, 2025

Techniques for detecting similar incidents

Inventors: Alexander Page (Orlando, FL); Omri Telem (Ness Ziona, IL); Frank A. Gallagher, Jr. (Boulder City, NV); Tomer Ben Levi (Tel Aviv, IL)
Assignee: BigPanda, Inc.
G06F16/24578G06F16/2237G06F16/285
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,511,297
App. No.
18/434,044
Filed
Feb 6, 2024
Granted
Dec 30, 2025
Kind
B2
Art Unit
2154
USPC
707/728
Abstract

A system and method for detecting similar incident records for initiating remediation actions in a computing environment is provided. The method includes: receiving a plurality of incident records, each incident record generated based on extracted values from a plurality of event records; generating an indexed incident record based on a plurality of predetermined categorical attributes; vectorizing a string of categorical attributes to generate a vectorized indexed incident record; storing the vectorized indexed incident record in a vector database; vectorizing a new incident record; querying the vector database based on the vectorized new incident record to detect a similar vector; and generating a similar incident record based on the detected similar vector.

Claims (70)

1 . A method for detecting similar incident records for initiating remediation actions in a computing environment, comprising:

receiving a plurality of incident records, each incident record generated based on extracted values from a plurality of event records;

generating, for each of the incident records, an indexed incident record based on a plurality of predetermined categorical attributes;

vectorizing a string of categorical attributes to generate a vectorized indexed incident record for each of the incident records;

storing the vectorized indexed incident record for each of the incident records in a vector database;

vectorizing a new incident record that is not one of the plurality of incident records;

querying the vector database based on the vectorized new incident record to detect a similar vector; and

generating a similar incident record based on the detected similar vector.

2 . The method of claim 1 , wherein vectorizing an indexed incident record further comprises:

generating a prompt for a large language model (LLM), based on a plurality of indices of an incident record; and

executing the prompt utilizing the LLM.

3 . The method of claim 2 , further comprising:

generating a second prompt for the LLM, based on the similar incident record and the new incident record, wherein the prompt, when executed, configures the LLM to output a textual explanation of similarity.

4 . The method of claim 1 , further comprising:

generating a similarity score between the similar incident record and the new incident record based on a vector distance of the vectorized indexed incident record and the vectorized new incident record.

5 . The method of claim 2 , further comprising:

receiving an input based on the similar incident record; and

training the LLM based on the received input.

6 . The method of claim 1 , further comprising:

populating a categorical attribute of a first index of the incident record based on a first matching data field.

7 . The method of claim 6 , further comprising:

populating a list of categorical attributes of a second index of the incident record based on each matching data field.

8 . The method of claim 1 , further comprising:

querying the vector database to detect a plurality of similar incident records, each similar incident corresponding to a vectorized indexed incident record having a vector distance less than a predetermined threshold value.

9 . The method of claim 8 , further comprising:

generating a visualization of the plurality of similar incident records, wherein the similar incident records are displayed in an order corresponding to a similarity score associated with each similar incident record.

10 . The method of claim 1 , further comprising:

determining a vector distance based on a first group of vectors of a similar incident record, and a second group of vectors of the new incident record, each vector generated based on an index of categorical attributes.

11 . A non-transitory computer-readable medium storing a set of instructions for detecting similar incident records for initiating remediation actions in a computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

receive a plurality of incident records, each incident record generated based on extracted values from a plurality of event records;

generate, for each of the incident records, an indexed incident record based on a plurality of predetermined categorical attributes;

vectorize a string of categorical attributes to generate a vectorized indexed incident record for each of the incident records;

store the vectorized indexed incident record for each of the incident records in a vector database;

vectorize a new incident record that is not one of the plurality of incident records;

query the vector database based on the vectorized new incident record to detect a similar vector; and

generate a similar incident record based on the detected similar vector.

12 . A system for detecting similar incident records for initiating remediation actions in a computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

receive a plurality of incident records, each incident record generated based on extracted values from a plurality of event records;

generate, for each of the incident records, an indexed incident record based on a plurality of predetermined categorical attributes;

vectorize a string of categorical attributes to generate a vectorized indexed incident record for each of the incident records;

store the vectorized indexed incident record for each of the incident records in a vector database;

vectorize a new incident record that is not one of the plurality of incident records;

query the vector database based on the vectorized new incident record to detect a similar vector; and

generate a similar incident record based on the detected similar vector.

13 . The system of claim 12 , wherein the memory contains further instructions that, when executed by the processing circuitry for vectorizing an indexed incident record, further configure the system to:

generate a prompt for a large language model (LLM), based on a plurality of indices of an incident record; and

execute the prompt utilizing the LLM.

14 . The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a second prompt for the LLM, based on the similar incident record and the new incident record, wherein the prompt, when executed, configures the LLM to output a textual explanation of similarity.

15 . The system of claim 13 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

receive an input based on the similar incident record; and

train the LLM based on the received input.

16 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a similarity score between the similar incident record and the new incident record based on a vector distance of the vectorized indexed incident record and the vectorized new incident record.

17 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

populate a categorical attribute of a first index of the incident record based on a first matching data field.

18 . The system of claim 17 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

populate a list of categorical attributes of a second index of the incident record based on each matching data field.

19 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

query the vector database to detect a plurality of similar incident records, each similar incident corresponding to a vectorized indexed incident record having a vector distance less than a predetermined threshold value.

20 . The system of claim 19 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a visualization of the plurality of similar incident records, wherein the similar incident records are displayed in an order corresponding to a similarity score associated with each similar incident record.

21 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

determine a vector distance based on a first group of vectors of a similar incident record, and a second group of vectors of the new incident record, each vector generated based on an index of categorical attributes.

22 . The method of claim 1 , further comprising:

performing a remediation action that was performed for the detected similar vector.

23 . The method of claim 1 , wherein the computing environment is a cloud computing environment implemented on a cloud computing infrastructure.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2024
From: PAGE, ALEXANDER; TELEM, OMRI; GALLAGHER, FRANK A., JR.; BEN LEVI, TOMER
To: BIGPANDA, INC.
Reel/Frame 066430/0657 →
Continuity (1)
Related Publication 20250252108A1 · Aug 7, 2025
References Cited (8)
US 10067760B2 · Ryali · 2018 [cited by examiner]
US 10911470B2 · Muddu et al. · 2021 [cited by applicant]
US 11853415B1 · Wainer · 2023 [cited by examiner]
US 12014428B1 · Turner · 2024 [cited by examiner]
US 20190097909A1 · Puri · 2019 [cited by examiner]
US 20240134774A1 · Sydow · 2024 [cited by examiner]
AU 2014214545A1 · 2015 [cited by examiner]
CN 110008311A · 2019 [cited by examiner]