Correlation-based multi-source problem diagnosis

    公开(公告)号:US11599404B2

    公开(公告)日:2023-03-07

    申请号:US17110438

    申请日:2020-12-03

    Abstract: According to an aspect, a method includes searching for a correlated log identifier in a correlation database based on detecting a metrics-based anomaly. The method also includes providing, in a problem diagnosis, related log information associated with the correlated log identifier based on locating one or more log entries including the correlated log identifier in a same time window as the metrics-based anomaly. The method further includes searching for a correlated metric in the correlation database based on detecting a log-based anomaly and providing, in the problem diagnosis, related metric information associated with the correlated metric based on locating one or more metrics records including the correlated metric in the same time window as the log-based anomaly.

    Event management in computer system

    公开(公告)号:US11762894B2

    公开(公告)日:2023-09-19

    申请号:US17456653

    申请日:2021-11-29

    CPC classification number: G06F16/35 G06F40/211 G06F40/30

    Abstract: Embodiments of the present invention relate to methods, systems, and computer program products for event management. In a method, a plurality of notes that are comprised in a plurality of event records are obtained in a computer system. A plurality of paragraphs that are comprised in the plurality of notes are classified into a plurality of content types based on a content analysis of the plurality of paragraphs. The plurality of notes are classified into a plurality of semantic types based on the plurality of content types and a syntactic parsing to the plurality of notes. A knowledge item is generated for managing an event in the computer system based on a group of notes in the plurality of notes that are classified into the plurality of semantic types. With these embodiments, knowledge items for managing events may be obtained in an easier and more effective way.

    EVENT MANAGEMENT IN COMPUTER SYSTEM
    6.
    发明公开

    公开(公告)号:US20230169104A1

    公开(公告)日:2023-06-01

    申请号:US17456653

    申请日:2021-11-29

    CPC classification number: G06F16/35 G06F40/30 G06F40/211

    Abstract: Embodiments of the present invention relate to methods, systems, and computer program products for event management. In a method, a plurality of notes that are comprised in a plurality of event records are obtained in a computer system. A plurality of paragraphs that are comprised in the plurality of notes are classified into a plurality of content types based on a content analysis of the plurality of paragraphs. The plurality of notes are classified into a plurality of semantic types based on the plurality of content types and a syntactic parsing to the plurality of notes. A knowledge item is generated for managing an event in the computer system based on a group of notes in the plurality of notes that are classified into the plurality of semantic types. With these embodiments, knowledge items for managing events may be obtained in an easier and more effective way.

    INTEGRATING DOCUMENTATION KNOWLEDGE WITH LOG MINING FOR SYSTEM DIAGNOSIS

    公开(公告)号:US20220180217A1

    公开(公告)日:2022-06-09

    申请号:US17110430

    申请日:2020-12-03

    Abstract: Aspects of the invention include computer systems, computer-implemented methods, and computer program products configured to integrate documentation knowledge with log mining data. A non-limiting example computer-implemented method includes determining a message-message relationship based on log message documentation and building a first subgraph based on the message-message relationship. The method further includes receiving a first message log entry having a message identifier and message field data. A second message log entry is correlated with the first message log entry based on at least one of the message identifier and the message field data. A second subgraph is built that includes the first message log entry and the second message log entry. The method includes building a graph that includes the first subgraph and the second subgraph.

    MESSAGE-BASED EVENT GROUPING FOR A COMPUTING OPERATION

    公开(公告)号:US20220179881A1

    公开(公告)日:2022-06-09

    申请号:US17110460

    申请日:2020-12-03

    Abstract: Aspects of the invention include determining whether a first log message written by an application during a first job is a message of interest based on a context of the first log message and a probability that the application writes the message for a same job as the first job. Calculating in response to determining that the first log message is a message of interest and by the processor, a correlation score based on intersecting tokens between the first log message and a second log message. Determining the first log message correlates to the second log message based on comparing the score to a threshold score. Modifying a system log of a mainframe to link the first log message to the second log message based on the correlation.

    GRAPH-BASED LOG SEQUENCE ANOMALY DETECTION AND PROBLEM DIAGNOSIS

    公开(公告)号:US20220179730A1

    公开(公告)日:2022-06-09

    申请号:US17110535

    申请日:2020-12-03

    Abstract: Techniques include generating a log sequence for new logs that have been received, searching a log sequence database for the log sequence having been generated, and determining that the log sequence is anomalous in response to not finding an identical log sequence in the log sequence database. In response to the log sequence not being found in the log sequence database, the log sequence is compared to a graph of historical log sequences to find a closest sequence path to one or more historical log sequences. An anomaly of the log sequence is diagnosed based on an occurrence at which the log sequence deviates from the closest sequence path of the one or more historical log sequences.

    Message-based problem diagnosis and root cause analysis

    公开(公告)号:US11243835B1

    公开(公告)日:2022-02-08

    申请号:US17110458

    申请日:2020-12-03

    Abstract: Aspects of the invention include constructing a knowledge graph by writing a plurality of data structures to connect correlated log messages in a system log. Detecting an anomalous log message based on the knowledge graph, wherein the anomalous log message is connected to a plurality of candidate root cause error log messages. Determining respective sequences from each of the plurality of candidate root cause error log messages to the anomalous log message. Calculating a deviation score for each respective sequence based on a deviation of an expected sequence for each candidate root cause error log message and the determined sequence. Determining a root cause log error message based on the calculated deviation scores.

Patent Agency Ranking