STREAMING GRAPH DISPLAY SYSTEM WITH ANOMALY DETECTION

    公开(公告)号:US20180336437A1

    公开(公告)日:2018-11-22

    申请号:US15981109

    申请日:2018-05-16

    Abstract: A computer-implemented method, system, and computer program product are provided for a streaming graph display system with anomaly detection. The method includes receiving, by a processor, data or signals for creating a streaming graph. The method also includes creating, by the processor, a streaming graph from a plurality of vertices and edges in the data or the signals. The method additionally includes identifying, by the processor, an anomaly in the streaming graph based on a distance between edge codes and all current cluster centers determined by the plurality of vertices and edges. The method further includes controlling, by the processor, an operation of a processor-based machine to change a state of the processor-based machine, responsive to the anomaly. The method also includes displaying the streaming graph with the anomaly to a user.

    Power Plant System Fault Diagnosis by Learning Historical System Failure Signatures

    公开(公告)号:US20180299877A1

    公开(公告)日:2018-10-18

    申请号:US15880979

    申请日:2018-01-26

    Abstract: A method, computer program product, and a system is provided for power plant system fault diagnosis. The method includes detecting, using an invariant model, a fault event based on a broken pair-wise correlation. The method also includes constructing a fault signature based on the fault event. The method further includes generating a feature vector in a feature subspace for the fault signature, wherein said feature vector includes at least one status of at least one system component during the fault event. The method additionally includes determining a corrective action correlated to the fault signature, from among a plurality of candidate corrective actions associated with the one or more historical representative signature, based on a Jaccard similarity using the feature vector in the feature subspace. The method also includes initiating the corrective action on a hardware device to mitigate expected harm.

    Periodicity Analysis on Heterogeneous Logs
    13.
    发明申请

    公开(公告)号:US20170132523A1

    公开(公告)日:2017-05-11

    申请号:US15340255

    申请日:2016-11-01

    CPC classification number: G06N5/047 G06N20/00

    Abstract: Systems and methods are disclosed for detecting periodic event behaviors from machine generated logging by: capturing heterogeneous log messages, each log message including a time stamp and text content with one or more fields; recognizing log formats from log messages; transforming the text content into a set of time series data, one time series for each log format; during a training phase, analyzing the set of time series data and building a category model for each periodic event type in heterogeneous logs; and during live operation, applying the category model to a stream of time series data from live heterogeneous log messages and generating a flag on a time series data point violating the category model and generating an alarm report for the corresponding log message.

    Automatic Discovery of Message Ordering Invariants in Heterogeneous Logs
    14.
    发明申请
    Automatic Discovery of Message Ordering Invariants in Heterogeneous Logs 审中-公开
    在异构日志中自动发现消息排序不变量

    公开(公告)号:US20160086097A1

    公开(公告)日:2016-03-24

    申请号:US14846093

    申请日:2015-09-04

    CPC classification number: G06N99/005

    Abstract: A method and system are provided. The method includes performing, by a logs-to-time-series converter, a logs-to-time-series conversion by transforming a plurality of heterogeneous logs into a set of time series. Each of the heterogeneous logs includes a time stamp and text portion with one or more fields. The method further includes performing, by a time-series-to-sequential-pattern converter, a time-series-to-sequential-pattern conversion by mining invariant relationships between the set of time series, and discovering sequential message patterns and association rules in the plurality of heterogeneous logs using the invariant relationships. The method also includes executing, by a processor, a set of log management applications, based on the sequential message patterns and the association rules.

    Abstract translation: 提供了一种方法和系统。 该方法包括:通过日志到时间序列转换器,通过将多个异构日志转换为一组时间序列来进行日志到时间序列转换。 每个异类日志包括具有一个或多个字段的时间戳和文本部分。 该方法还包括通过时间序列到顺序模式转换器,通过在时间序列集合之间挖掘不变关系,并且发现顺序消息模式和关联规则来执行时间序列到顺序模式转换 使用不变关系的多个异类日志。 该方法还包括基于顺序消息模式和关联规则由处理器执行一组日志管理应用程序。

    HETEROGENEOUS LOG ANALYSIS
    15.
    发明申请
    HETEROGENEOUS LOG ANALYSIS 审中-公开
    异质日志分析

    公开(公告)号:US20150094959A1

    公开(公告)日:2015-04-02

    申请号:US14503549

    申请日:2014-10-01

    CPC classification number: G01V99/005

    Abstract: A method and system are provided for heterogeneous log analysis. The method includes performing hierarchical log clustering on heterogeneous logs to generate a log cluster hierarchy for the heterogeneous logs. The method further includes performing, by a log pattern recognizer device having a processor, log pattern recognition on the log cluster hierarchy to generate log pattern representations. The method also includes performing log field analysis on the log pattern representations to generate log field statistics. The method additionally includes performing log indexing on the log pattern representations to generate log indexes.

    Abstract translation: 提供了一种用于异构对数分析的方法和系统。 该方法包括在异构日志上执行分层日志聚类,以生成异类日志的日志群集层次结构。 该方法还包括通过具有处理器的日志模式识别器装置执行日志簇层级上的日志模式识别以产生日志模式表示。 该方法还包括对日志模式表示执行日志字段分析以生成日志字段统计。 该方法还包括对日志模式表示执行日志索引以生成日志索引。

    ANOMALY DETECTION IN STREAMING NETWORKS
    19.
    发明申请

    公开(公告)号:US20180336436A1

    公开(公告)日:2018-11-22

    申请号:US15981087

    申请日:2018-05-16

    Abstract: A computer-implemented method, system, and computer program product are provided for anomaly detection system in streaming networks. The method includes receiving, by a processor, a plurality of vertices and edges from a streaming graph. The method also includes generating, by the processor, graph codes for the plurality of vertices and edges. The method additionally includes determining, by the processor, edge codes in real-time responsive to the graph codes. The method further includes identifying, by the processor, an anomaly based on a distance between edge codes and all current cluster centers. The method also includes controlling an operation of a processor-based machine to change a state of the processor-based machine, responsive to the anomaly.

Patent Agency Ranking