Patent · US Active

Two-phase log anomaly aggregation framework

US12189506B1 · kind B1 · utility

0Cited by
1References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 15, 2022
Grant dateJan 7, 2025
Priority date
Expiry dateDec 15, 2042

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2201/835
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Systems and methods are described relating to aggregating log anomalies. In some examples, a plurality of log anomaly instances may be obtained, from a log anomaly detector, where individual instances are associated with a first log anomaly type and a first anomalous log event. Log anomaly instances associated with the first log anomaly type and the first anomalous log event may be combined into a first log anomaly class. The first log anomaly class may be combined with a second log anomaly class, including log anomaly instances associated with the first anomalous log event and a second log anomaly type, into a log anomaly group, which may correlate the occurrences of the first and second anomaly types to the same first anomalous log event over a period of time. An indication of the log anomaly group may then be output.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.