IP Library Patent Application 18069951
Patent Application
App. No. 18/069,951

LOG ENTRY ANALYSIS IN MANAGED ENDPOINTS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/069,951
Abstract

A method may include monitoring a log file at an endpoint of a managed network, and an error log entry that indicates a technical error experienced at the endpoint may be identified. The method may include ignoring the log entries that are generated during a first time period following identification of the error log entry. A first set of log entries may be collected during a first time interval beginning at the end of the first time period and going back a second time period. A second set of log entries may be collected during a second time interval beginning at the end of the first time period and moving forward for a third time period. The first and second sets of log entries may be aggregated, and a mitigation action determined based on analysis of the aggregated log entries may be implemented as a solution to the technical error.

Claims (61)

1 . A method, comprising:

monitoring a log file at an endpoint of a managed network, the log file including one or more log entries generated by the endpoint;

while monitoring the log file, identifying an error log entry that indicates a technical error is experienced at the endpoint;

ignoring the log entries that are generated during a first time period following identification of the error log entry, wherein the first time period is configured to reduce a duplicate error log associated with the technical error;

after the first time period:

collecting a first plurality of log entries during a first time interval from the endpoint, the first time interval beginning at the end of the first time period and going back a second time period; and

collecting a second plurality of log entries during a second time interval from the endpoint, the second time interval beginning at the end of the first time period and moving forward for a third time period;

aggregating the first and the second pluralities of log entries;

receiving a mitigation action from an administrative device, the mitigation action being based on an analysis of the aggregated log entries and determination of a solution to the technical error; and

implementing the mitigation action to implement the solution at the endpoint.

2 . The method of claim 1 , further comprising receiving a log monitor command configured to initiate the monitoring of the log file at the endpoint.

3 . The method of claim 2 , wherein the log monitor command is received from the administrative device in response to an error report that indicates an occurrence of the technical error at the endpoint.

4 . The method of claim 1 , wherein:

the second time period is substantially similar to the third time period; and

the first time period is shorter than the second time period.

5 . The method of claim 4 , wherein:

the second time period is about five minutes; and

the first time period is about ten seconds.

6 . The method of claim 1 , wherein the first time period, the second time period, and the third time period are set according to a characteristic of the endpoint.

7 . The method of claim 1 , further comprising communicating the aggregated log entries to a particular storage location at an administrative device.

8 . One or more non-transitory computer-readable storage media configured to store instructions that, in response to being executed, cause a system to perform operations, the operations comprising:

monitoring a log file at an endpoint of a managed network, the log file including one or more log entries generated by the endpoint;

while monitoring the log file, identifying an error log entry that indicates a technical error is experienced at the endpoint;

ignoring the log entries that are generated during a first time period following identification of the error log entry, wherein the first time period is configured to reduce a duplicate error log associated with the technical error;

after the first time period:

collecting a first plurality of log entries during a first time interval from the endpoint, the first time interval beginning at the end of the first time period and going back a second time period; and

collecting a second plurality of log entries during a second time interval from the endpoint, the second time interval beginning at the end of the first time period and moving forward for a third time period;

aggregating the first and the second pluralities of log entries;

receiving a mitigation action from an administrative device, the mitigation action being based on an analysis of the aggregated log entries and determination of a solution to the technical error; and

implementing the mitigation action to implement the solution at the endpoint.

9 . The one or more non-transitory computer-readable storage media of claim 8 , further comprising receiving a log monitor command configured to initiate the monitoring of the log file at the endpoint.

10 . The one or more non-transitory computer-readable storage media of claim 9 , wherein the log monitor command is received from the administrative device in response to an error report that indicates an occurrence of the technical error at the endpoint.

11 . The one or more non-transitory computer-readable storage media of claim 8 , wherein:

the second time period is substantially similar to the third time period; and

the first time period is shorter than the second time period.

12 . The one or more non-transitory computer-readable storage media of claim 11 , wherein:

the second time period is about five minutes; and

the first time period is about ten seconds.

13 . The one or more non-transitory computer-readable storage media of claim 8 , wherein the first time period, the second time period, and the third time period are set according to a characteristic of the endpoint.

14 . The one or more non-transitory computer-readable storage media of claim 8 , further comprising communicating the aggregated log entries to a particular storage location at an administrative device.

15 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable storage media configured to store instructions that, in response to being executed, cause the system to perform operations, the operations comprising:

monitoring a log file at an endpoint of a managed network, the log file including one or more log entries generated by the endpoint;

while monitoring the log file, identifying an error log entry that indicates a technical error is experienced at the endpoint;

ignoring the log entries that are generated during a first time period following identification of the error log entry, wherein the first time period is configured to reduce a duplicate error log associated with the technical error;

after the first time period:

collecting a first plurality of log entries during a first time interval from the endpoint, the first time interval beginning at the end of the first time period and going back a second time period; and

collecting a second plurality of log entries during a second time interval from the endpoint, the second time interval beginning at the end of the first time period and moving forward for a third time period;

aggregating the first and the second pluralities of log entries;

receiving a mitigation action from an administrative device, the mitigation action being based on an analysis of the aggregated log entries and determination of a solution to the technical error; and

implementing the mitigation action to implement the solution at the endpoint.

16 . The system of claim 15 , further comprising receiving a log monitor command configured to initiate the monitoring of the log file at the endpoint.

17 . The system of claim 16 , wherein the log monitor command is received from the administrative device in response to an error report that indicates an occurrence of the technical error at the endpoint.

18 . The system of claim 15 , wherein:

the second time period is substantially similar to the third time period; and

the first time period is shorter than the second time period.

19 . The system of claim 15 , wherein:

the second time period is about five minutes; and

the first time period is about ten seconds.

20 . The system of claim 15 , wherein the first time period, the second time period, and the third time period are set according to a characteristic of the endpoint.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2023
From: BRANTON, PAUL
To: IVANTI, INC.
Reel/Frame 062409/0707 →