Cloud Black Box Subsystem Centralized Logging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud infrastructure, the decentralized and device-specific logging services make it difficult to obtain a centralized location for all information needed to find single issues and root causes, as different formats and levels of information complicate correlation, and the risk of logging service unavailability due to device failure exists.

Innovation Solution

A cloud black box subsystem that collects and stores information from heterogeneous devices using a common information transfer protocol, operating in both depository and retrieval modes, allowing for independent functionality even during device failures, and providing a centralized location for root-cause analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate device-specific logging services are used on different cloud devices, then each device can maintain its own logging format and operation independence, but centralized information collection becomes impossible and data correlation becomes difficult

Engineering Contradiction:
Improvedevice-specific logging flexibilityVSAvoidcentralized information availability
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces a centralized logging service that acts as an intermediary between heterogeneous cloud devices and the monitoring system. This service receives logs from various devices through standardized interfaces, normalizes them into a unified format, and stores them centrally. The intermediary enables centralized information collection while preserving device-specific logging capabilities through standardization protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The centralized logging service implements universal functionality by handling multiple device types (hosts, storage arrays, network switches) through a single unified interface. It performs multiple functions including log collection, normalization, storage, and correlation across different device types, eliminating the need for separate logging services for each device while maintaining adaptability to device-specific formats.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If logging services are integrated with monitored devices, then logging can be performed at the source, but the logging service becomes vulnerable to device failure and may not be available when needed

Engineering Contradiction:
Improvelogging efficiencyVSAvoidlogging service availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts the logging function from the monitored devices and places it in a separate, dedicated centralized logging service. This extraction ensures that logging operations are not dependent on the operational status of the monitored devices. Even when devices fail, the centralized logging service remains available to collect and store log data, ensuring logging reliability independent of device productivity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If different logging formats and information levels are used across devices, then each device can optimize its logging for its specific needs, but correlation and analysis of logs from multiple devices becomes difficult or impossible

Engineering Contradiction:
Improvedevice-optimized loggingVSAvoidlog correlation difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The centralized logging service applies parameter changes by transforming logs from various devices into a unified format with standardized fields, data types, and normalization rules. It adjusts information levels and structures to ensure consistency across different device types while preserving device-specific details through extended fields, enabling both device-optimized logging and easy correlation through parameter standardization.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If decentralized logging is implemented across multiple devices, then logging capacity is distributed, but no single location contains all information needed for root cause analysis

Engineering Contradiction:
Improvelogging distributionVSAvoidcomplete information availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges decentralized log data from multiple cloud devices into a single centralized repository. The centralized logging service collects logs from hosts, storage arrays, and network switches, combines them into a unified log store, and makes all information available at one location. This merging preserves the distributed logging capacity while ensuring complete information availability for root cause analysis through centralization.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9307015B1Cloud black box for cloud infrastructure
Publication Date: 2016.04.05 EMC IP HLDG CO LLC
  • US9307015B1 patent drawing
  • US9307015B1 patent drawing
  • US9307015B1 patent drawing

AI summary

A cloud black box (CBB) subsystem in a cloud computing infrastructure includes CBB storage and computer processing circuitry executing a CBB application having first and second operating modes. In a depository mode information messages are continually received from hardware computing devices during normal operation and device information from the messages is stored into the CBB storage. The information messages are generated by CBB agents executing on the hardware computing devices, which continually collect the device information and generate the information messages according to a common information transfer protocol. In a retrieval mode, device information in the CBB storage is provided to a requestor such as a data analysis application, which may be part of or external to the CBB subsystem. The CBB subsystem operates independently and remains available upon failure of hardware or software components in the cloud infrastructure, providing a centralized source of information for diagnosis or other analysis.