首页> 外国专利> Fingerprinting event logs for system management troubleshooting

Fingerprinting event logs for system management troubleshooting

机译:指纹事件日志用于系统管理故障排除

摘要

A technique for automatically detecting and correcting configuration errors in a computing system. In a learning process, recurring event sequences, including e.g., registry access events, are identified from event logs, and corresponding rules are developed. In a detecting phase, the rules are applied to detected event sequences to identify violations and to recover from failures. Event sequences across multiple hosts can be analyzed. The recurring event sequences are identified efficiently by flattening a hierarchical sequence of the events such as is obtained from the Sequitur algorithm. A trie is generated from the recurring event sequences and edges of nodes of the trie are marked as rule edges or non-rule edges. A rule is formed from a set of nodes connected by rule edges. The rules can be updated as additional event sequences are analyzed. False positive suppression policies include a violation-consistency policy and an expected event disappearance policy.
机译:一种用于自动检测和纠正计算系统中的配置错误的技术。在学习过程中,从事件日志中识别重复的事件序列,包括例如注册表访问事件,并制定相应的规则。在检测阶段,将规则应用于检测到的事件序列,以识别违规并从故障中恢复。可以分析多个主机上的事件序列。通过展平诸如从Sequitur算法获得的事件的分层序列,可以有效地识别重复发生的事件序列。根据重复的事件序列生成特里树,并将该特里树节点的边缘标记为规则边缘或非规则边缘。规则是由一组由规则边缘连接的节点组成的。可以在分析其他事件序列时更新规则。误报抑制策略包括违规一致性策略和预期事件消失策略。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号