IP Library Granted Patent US 8,380,752
Granted Patent B2
US 8,380,752 · App. 13/084,288 · Granted Feb 19, 2013

Customized reporting and mining of event data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,380,752
App. No.
13/084,288
Granted
Feb 19, 2013
Kind
B2
Abstract

Event data (e.g., log messages) are represented as sets of attribute/value pairs. An index maps each attribute/value pair or attribute/value tuple to a pointer that points to event data which contains the attribute/value pair or attribute/value tuple. An attribute co-occurrence map or matrix can be generated that includes attribute names that co-occur together. Queries and custom reports can be generated by projecting event data into one or more attributes or attribute/value pairs, and then determining statistics on other attributes using a combination of the inverted index, the attribute co-occurrence map or matrix, operations on sets and/or math and statistical functions.

Claims (54)

1. A method executed by a computer, comprising:

receiving a report search query from one more event data collectors;

parsing the report search query to determine a specified attribute of an event being searched;

retrieving values or statistics associated with the specified attribute;

determining a co-occurring attribute of the specified attribute;

aggregating at least one of values or statistics associated with the co-occurring attribute; and

generating a report that includes at least one of the values or statistics associated with the co-occurring attribute, wherein generating the report comprises:

projecting event data in a log file into one or more attribute/value pairs, including generating the attribute/value pairs based on a message type of the event data, the message type being determined by a signature of the event data; and

determining the statistics on the co-occurring attribute using a combination of:

an attribute co-occurrence data structure identifying a relationship between the specified attribute and the co-occurring attribute; and

an index mapping each of the one or more attribute/value pairs to an inverted reference pointer referencing an instance of the event data, the instance of event data including a raw log message corresponding to the respective attribute/value pair.

2. The method of claim 1 , wherein determining the co-occurring attribute includes searching the attribute co-occurrence data structure for the co-occurring attribute.

3. The method of claim 1 , wherein the relationship between the specified attribute and the co-occurring attribute indicates that the report search query for finding a textual message including both the specified attribute and the co-occurring attribute is allowable.

4. The method of claim 3 , wherein:

the one or more attribute/value pairs are generated from event data in a log file; and

generating the report comprises providing access to the event data in the log file using the reference pointer.

5. The method of claim 4 , wherein

the instance of the event data includes a textual message based on which each of the one or more attribute/value pairs was generated.

6. A non-transitory computer-readable storage medium storing instructions, the instructions configured to cause a computer to perform operations comprising:

receiving a report search query from one more event data collectors;

parsing the report search query to determine a specified attribute of an event being searched;

retrieving values or statistics associated with the specified attribute;

determining a co-occurring attribute of the specified attribute;

aggregating at least one of values or statistics associated with the co-occurring attribute; and

generating a report that includes at least one of the values or statistics associated with the co-occurring attribute, wherein generating the report comprises:

projecting event data in a log file into one or more attribute/value pairs, including generating the attribute/value pairs based on a message type of the event data, the message type being determined by a signature of the event data; and

determining the statistics on the co-occurring attribute using a combination of:

an attribute co-occurrence data structure identifying a relationship between the specified attribute and the co-occurring attribute; and

an index mapping each of the one or more attribute/value pairs to an inverted reference pointer referencing an instance of the event data, the instance of event data including a raw log message corresponding to the respective attribute/value pair.

7. The non-transitory computer-readable storage medium of claim 6 , wherein determining the co-occurring attribute includes searching the attribute co-occurrence data structure for the co-occurring attribute.

8. The non-transitory computer-readable storage medium of claim 6 , wherein the relationship between the specified attribute and the co-occurring attribute indicates that the report search query for finding a textual message including both the specified attribute and the co-occurring attribute is allowable.

9. The non-transitory computer-readable storage medium of claim 8 , wherein:

the one or more attribute/value pairs are generated from event data in a log file; and

generating the report comprises providing access to the event data in the log file using the reference pointer.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the instance of the event data includes a textual message based on which each of the one or more attribute/value pairs was generated.

11. A system comprising:

one or more computing devices configured to perform operations comprising:

receiving a report search query from one more event data collectors;

parsing the report search query to determine a specified attribute of an event being searched;

retrieving values or statistics associated with the specified attribute;

determining a co-occurring attribute of the specified attribute;

aggregating at least one of values or statistics associated with the co-occurring attribute; and

generating a report that includes at least one of the values or statistics associated with the co-occurring attribute, wherein generating the report comprises:

projecting event data in a log file into one or more attribute/value pairs, including generating the attribute/value pairs based on a message type of the event data, the message type being determined by a signature of the event data; and

determining the statistics on the co-occurring attribute using a combination of:

an attribute co-occurrence data structure identifying a relationship between the specified attribute and the co-occurring attribute; and

an index mapping each of the one or more attribute/value pairs to an inverted reference pointer referencing an instance of the event data, the instance of event data including a raw log message corresponding to the respective attribute/value pair.

12. The system of claim 11 , wherein determining the co-occurring attribute includes searching the attribute co-occurrence data structure for the co-occurring attribute.

13. The system of claim 11 , wherein the relationship between the specified attribute and the co-occurring attribute indicates that the report search query for finding a textual message including both the specified attribute and the co-occurring attribute is allowable.

14. The system of claim 13 , wherein:

the one or more attribute/value pairs are generated from event data in a log file; and

generating the report comprises providing access to the event data in the log file using the reference pointer.

15. The system of claim 14 , wherein

the instance of the event data includes a textual message based on which each of the one or more attribute/value pairs was generated.

Assignments (16)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
CHANGE OF NAME Recorded Feb 7, 2023
From: TIBCO SOFTWARE INC.
To: CLOUD SOFTWARE GROUP, INC.
Reel/Frame 062714/0634 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
RELEASE REEL 052115 / FRAME 0318 Recorded Oct 3, 2022
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: TIBCO SOFTWARE INC.
Reel/Frame 061588/0511 →
RELEASE (REEL 034536 / FRAME 0438) Recorded Sep 30, 2022
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 061574/0963 →
RELEASE (REEL 054275 / FRAME 0975) Recorded May 7, 2021
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 056176/0398 →
SECURITY AGREEMENT Recorded Nov 2, 2020
From: TIBCO SOFTWARE INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 054275/0975 →
SECURITY AGREEMENT Recorded Mar 6, 2020
From: TIBCO SOFTWARE INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 052115/0318 →
SECURITY INTEREST Recorded Dec 5, 2014
From: TIBCO SOFTWARE INC.; TIBCO KABIRA LLC; NETRICS.COM LLC
To: JPMORGAN CHASE BANK., N.A., AS COLLATERAL AGENT
Reel/Frame 034536/0438 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2013
From: LOGLOGIC, INC.
To: TIBCO SOFTWARE INC.
Reel/Frame 030560/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2011
From: BOTROS, SHERIF; ZHEN, JIAN L.; LIU, MINJUN; GALITSKY, BORIS
To: LOGLOGIC, INC.
Reel/Frame 026208/0591 →