首页> 外国专利> Anomaly event detection using frequent patterns

Anomaly event detection using frequent patterns

机译:异常事件检测使用频繁模式

摘要

A method is disclosed. The method includes: receiving, at a computing device, an event log including a plurality of events, where the plurality of events are derived from machine data generated by components of an information technology environment; determining a first score associated with a first granularity level by comparing a first event from the event log with a first plurality of frequent patterns generated for the first granularity level; determining a second score associated with a second granularity level by comparing the first event with a second plurality of frequent patterns generated for the second granularity level; determining an aggregate score for the first event based on the first score and the second score; comparing the aggregate score for the first event with an anomaly score threshold; and issuing an alert identifying the first event as an anomaly based on the aggregate score exceeding the anomaly score threshold.
机译:公开了一种方法。该方法包括:在计算设备处接收包括多个事件的事件日志,其中多个事件源自由信息技术环境的组件生成的机器数据;通过将来自事件日志的第一事件与第一个粒度水平产生的第一多个频繁模式进行比较,确定与第一粒度水平相关联的第一分数;通过将第一事件与第二粒度水平产生的第二多个频繁模式进行比较,确定与第二粒度水平相关联的第二分数;基于第一个分数和第二分的第一个事件确定总分数;将第一个事件的总分与异常分数阈值进行比较;并根据超过异常评分阈值的总分发布将第一个事件的警报标识为异常。

著录项

  • 公开/公告号US11055405B1

    专利类型

  • 公开/公告日2021-07-06

    原文格式PDF

  • 申请/专利权人 SPLUNK INC.;

    申请/专利号US201916399734

  • 发明设计人 ZHUXUAN JIN;GEORGE APOSTOLOPOULOS;

    申请日2019-04-30

  • 分类号G06F21/55;G06F16/245;G06F21/56;H04L29/06;

  • 国家 US

  • 入库时间 2022-08-24 19:44:06

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号