-
公开(公告)号:US11675816B1
公开(公告)日:2023-06-13
申请号:US17163258
申请日:2021-01-29
Applicant: Splunk Inc.
Inventor: Ramkumar Chandrasekharan , Tristan Antonio Fletcher , Ramprasad Siva Golla , Alpesh Sheth , Shailendra Suryawanshi , Xiang Zhou
CPC classification number: G06F16/285 , G06N20/00
Abstract: Systems and methods are described for using a streaming data processor to group notable events reflecting operation of a computing system into episodes of related events reflecting an incident on the computing system, such as to enable root cause analysis of the incident. Each notable event can be generated based on one or more events detected within raw machine data. The streaming data processor can ingest a data stream of notable events, and apply a clustering algorithm to the events to cluster those events into episodes. When the episodes satisfy an action rule, the streaming data processor can take an action appropriate to that rule, such as transmitting an alert or programmatically altering operation of the computing system. The streaming data processor can utilize feedback as to the grouping of events into episodes to modify the clustering algorithm and improve accuracy of clustering.