发明授权
- 专利标题: Fingerprinting event logs for system management troubleshooting
- 专利标题(中): 指纹事件日志用于系统管理故障排除
-
申请号: US12394451申请日: 2009-02-27
-
公开(公告)号: US08069374B2公开(公告)日: 2011-11-29
- 发明人: Rina Panigrahy , Chad Verbowski , Yinglian Xie , Junfeng Yang , Ding Yuan
- 申请人: Rina Panigrahy , Chad Verbowski , Yinglian Xie , Junfeng Yang , Ding Yuan
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 代理机构: Vierra Magen Marcus & DeNiro LLP
- 主分类号: G06F11/00
- IPC分类号: G06F11/00
摘要:
A technique for automatically detecting and correcting configuration errors in a computing system. In a learning process, recurring event sequences, including e.g., registry access events, are identified from event logs, and corresponding rules are developed. In a detecting phase, the rules are applied to detected event sequences to identify violations and to recover from failures. Event sequences across multiple hosts can be analyzed. The recurring event sequences are identified efficiently by flattening a hierarchical sequence of the events such as is obtained from the Sequitur algorithm. A trie is generated from the recurring event sequences and edges of nodes of the trie are marked as rule edges or non-rule edges. A rule is formed from a set of nodes connected by rule edges. The rules can be updated as additional event sequences are analyzed. False positive suppression policies include a violation-consistency policy and an expected event disappearance policy.
公开/授权文献
信息查询