Two-phase log anomaly aggregation framework
US12189506B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Dec 15, 2022 |
| Grant date | Jan 7, 2025 |
| Priority date | — |
| Expiry date | Dec 15, 2042 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F2201/835
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
Systems and methods are described relating to aggregating log anomalies. In some examples, a plurality of log anomaly instances may be obtained, from a log anomaly detector, where individual instances are associated with a first log anomaly type and a first anomalous log event. Log anomaly instances associated with the first log anomaly type and the first anomalous log event may be combined into a first log anomaly class. The first log anomaly class may be combined with a second log anomaly class, including log anomaly instances associated with the first anomalous log event and a second log anomaly type, into a log anomaly group, which may correlate the occurrences of the first and second anomaly types to the same first anomalous log event over a period of time. An indication of the log anomaly group may then be output.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.