IP Library Granted Patent US 8,966,503
Granted Patent B1
US 8,966,503 · App. 13/837,740 · Granted Feb 24, 2015

System and method for correlating anomalous events

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,966,503
App. No.
13/837,740
Granted
Feb 24, 2015
Kind
B1
Abstract

The method includes monitoring a plurality of information handling systems. The method further includes receiving an anomalous event with respect to at least one information handling system of the plurality of information handling systems. In addition, the method includes performing, via at least one correlation handler, at least one correlation algorithm on the anomalous event. Further, the method includes, responsive to the performing, creating, via the correlation handler, at least one composite event. Additionally, the method includes sending the at least one composite event to an event handler. The method also includes issuing, via the event handler, an alert for the at least one composite event.

Claims (70)

1. A method comprising:

monitoring, by an event-monitoring system comprising computer hardware, a plurality of information handling systems;

receiving an anomalous event with respect to at least one information handling system of the plurality of information handling systems;

analyzing, by the event-monitoring system via a correlation handler, the anomalous event for root cause before passing the anomalous event to an event handler for alert issuance, the analyzing comprising:

determining based, at least in part, on a data-collection schedule, that at least one data refresh is needed with respect to one or more monitored information handling systems within a correlation scope of the at least one information handling system;

delaying anomalous-event correlation relating to the anomalous event so that the at least one data refresh can be executed;

receiving at least one additional anomalous event responsive to the at least one data refresh;

performing, via at least one correlation handler on the event-monitoring system, at least one correlation algorithm on the anomalous event;

responsive to the performing, determining whether a common root cause for the anomalous event and the at least one additional anomalous event has been identified;

responsive to a determination that a common root cause has been identified, creating, by the event-monitoring system via the correlation handler, at least one composite event;

wherein the at least one composite event comprises a plurality of anomalous events deemed to have a common root cause, the plurality of anomalous events comprising the anomalous event and the at least one additional anomalous event;

sending the at least one composite event to an event handler; and

issuing, by the event-monitoring system via the event handler, an alert for the at least one composite event, thereby facilitating message-storm prevention relating to the plurality of anomalous events.

2. The method of claim 1 , wherein the correlation handler and the event handler are logically separate software components.

3. The method of claim 1 , wherein the performing comprises examining logged-event information for previous anomalous events that have been processed by the event-monitoring system.

4. The method of claim 1 , the delaying comprising waiting a configurable delay for the at least one data refresh.

5. The method of claim 1 , the delaying comprising requesting the at least one data refresh from an information handling system for which the at least one data refresh is needed.

6. The method of claim 1 , wherein the performing comprises identifying a root cause for the anomalous event.

7. The method of claim 6 , wherein the root cause is selected from the group consisting of: a weather event, an outage event on a particular information handling system, and a geographic issue.

8. The method of claim 1 , wherein the performing comprises:

examining geographic relationships among the plurality of information handling systems; and

correlating the anomalous event with other anomalous events in a geographic area.

9. The method of claim 8 , wherein the performing comprises:

correlating the anomalous event and the other anomalous events with a weather event; and

identifying the weather event as a root cause of the anomalous event and of the other anomalous events.

10. The method of claim 1 , wherein:

the performing comprises:

analyzing dynamic context information for the plurality of information handling systems; and

with respect to the anomalous event, identifying impacted information handling systems of the plurality of information handling systems; and

the at least one composite event comprises a proactive composite event.

11. The method of claim 10 , wherein:

the anomalous event comprises a weather event; and

the analyzing comprises determining a projected path of the weather event.

12. The method of claim 1 , wherein the anomalous event is selected from the group consisting of: weather event, outage event, and log-in failure event.

13. An information handling system comprising computer hardware, wherein the information handling is operable to perform a method comprising:

monitoring a plurality of information handling systems;

receiving an anomalous event with respect to at least one information handling system of the plurality of information handling systems;

analyzing, via a correlation handler, the anomalous event for root cause before passing the anomalous event to an event handler for alert issuance, the analyzing comprising:

determining based, at least in part, on a data-collection schedule, that at least one data refresh is needed with respect to one or more monitored information handling systems within a correlation scope of the at least one information handling system;

delaying anomalous-event correlation relating to the anomalous event so that the at least one data refresh can be executed;

receiving at least one additional anomalous event responsive to the at least one data refresh;

performing, via the correlation handler, at least one correlation algorithm on the anomalous event;

responsive to the performing, determining whether a common root cause for the anomalous event and the at least one additional anomalous event has been identified;

responsive to a determination that a common root cause has been identified, creating, via the correlation handler, at least one composite event;

wherein the at least one composite event comprises a plurality of anomalous events deemed to have a common root cause, the plurality of anomalous events comprising the anomalous event and the at least one additional anomalous event;

sending the at least one composite event to an event handler; and

issuing, via the event handler, an alert for the at least one composite event, thereby facilitating message-storm prevention relating to the plurality of anomalous events.

14. The information handling system of claim 13 , wherein the correlation handler and the event handler are logically separate software components.

15. The information handling system of claim 13 , wherein the performing comprises examining logged-event information for previous anomalous events that have been processed by the information handling system.

16. The information handling system of claim 13 , the delaying comprising waiting a configurable delay for the at least one data refresh.

17. The information handling system of claim 13 , the delaying comprising requesting the at least one data refresh from an information handling system for which the at least one data refresh is needed.

18. The information handling system of claim 13 , wherein the performing comprises identifying a root cause for the anomalous event.

19. The information handling system of claim 13 , wherein:

the performing comprises:

analyzing dynamic context information for the plurality of information handling systems; and

with respect to the anomalous event, identifying impacted information handling systems of the plurality of information handling systems; and

the at least one composite event comprises a proactive composite event.

20. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

monitoring, by an event-monitoring system, a plurality of information handling systems;

receiving an anomalous event with respect to at least one information handling system of the plurality of information handling systems;

analyzing, by the event-monitoring system via a correlation handler, the anomalous event for root cause before passing the anomalous event to an event handler for alert issuance, the analyzing comprising:

determining based, at least in part, on a data-collection schedule, that at least one data refresh is needed with respect to one or more monitored information handling systems within a correlation scope of the at least one information handling system;

delaying anomalous-event correlation relating to the anomalous event so that the at least one data refresh can be executed;

receiving at least one additional anomalous event responsive to the at least one data refresh;

performing, via at least one correlation handler on the event-monitoring system, at least one correlation algorithm on the anomalous event;

responsive to the performing, determining whether a common root cause for the anomalous event and the at least one additional anomalous event has been identified;

responsive to a determination that a common root cause has been identified, creating, by the event-monitoring system via the correlation handler, at least one composite event;

wherein the at least one composite event comprises a plurality of anomalous events deemed to have a common root cause, the plurality of anomalous events comprising the anomalous event and the at least one additional anomalous event;

sending the at least one composite event to an event handler; and

issuing, via the event handler, an alert for the at least one composite event, thereby facilitating message-storm prevention relating to the plurality of anomalous events.

Assignments (27)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
CHANGE OF NAME Recorded Aug 19, 2013
From: QUEST SOFTWARE, INC.
To: DELL SOFTWARE INC.
Reel/Frame 031035/0914 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2013
From: DYER, KELLY NOEL; MCALEER, DAVID; ABDUL-MATIN, OMAIR-INAM
To: QUEST SOFTWARE, INC.
Reel/Frame 030893/0807 →