Grouping evens into episodes using a streaming data processor

    公开(公告)号:US11675816B1

    公开(公告)日:2023-06-13

    申请号:US17163258

    申请日:2021-01-29

    Applicant: Splunk Inc.

    CPC classification number: G06F16/285 G06N20/00

    Abstract: Systems and methods are described for using a streaming data processor to group notable events reflecting operation of a computing system into episodes of related events reflecting an incident on the computing system, such as to enable root cause analysis of the incident. Each notable event can be generated based on one or more events detected within raw machine data. The streaming data processor can ingest a data stream of notable events, and apply a clustering algorithm to the events to cluster those events into episodes. When the episodes satisfy an action rule, the streaming data processor can take an action appropriate to that rule, such as transmitting an alert or programmatically altering operation of the computing system. The streaming data processor can utilize feedback as to the grouping of events into episodes to modify the clustering algorithm and improve accuracy of clustering.

Patent Agency Ranking