Hierarchical Log Data Structure for Root Cause Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Analyzing large volumes of monitoring data from computing systems is challenging due to the spread of skills and expertise required across different logs and components, making it difficult to identify error causes and perform predictive analysis efficiently.
Innovation Solution
A system that generates hierarchical data structures and timeline data structures from logs, using pre-processing and timeline plugins to dissect information into recognizable sets, associate metadata, and perform analysis, enabling collaborative execution and shared metadata across plugins.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If large volumes of monitoring data from multiple logs and components are analyzed manually, then comprehensive root cause analysis can be performed, but the analysis efficiency and productivity are significantly reduced due to the spread of skills and expertise across different logs
Solution Approach 1:
The patent segments the analysis process into distinct plugin modules, each responsible for specific analysis tasks on different log types. This allows specialized expertise to be encapsulated in individual plugins while enabling automated orchestration of the complete analysis workflow, thereby maintaining analysis accuracy while improving productivity.
Solution Approach 2:
The patent introduces a collaborative analysis system as an intermediary layer between raw log data and human analysts. This system automatically coordinates multiple plugins with different expertise areas, performing comprehensive root cause analysis without requiring manual coordination of specialized knowledge, thus resolving the contradiction between thorough analysis and analysis efficiency.
2Adaptability or versatility
If multiple plugins with different expertise are used to analyze different log types, then comprehensive analysis coverage is improved, but the system complexity and coordination difficulty increase
Solution Approach 1:
The patent creates a universal collaborative analysis system that can orchestrate multiple specialized plugins through a common interface and coordination mechanism. This universal framework enables the system to handle diverse log types and analysis tasks while maintaining manageable complexity through standardized processes.
Solution Approach 2:
The patent changes the organizational parameter from manual coordination of expertise to automated plugin-based processing. By transforming the analysis workflow into a parameterized plugin execution model, the system achieves comprehensive coverage through modular specialization while reducing coordination complexity through automated management.
3Productivity
If logs are analyzed in isolation without hierarchical organization, then simple analysis is faster, but the ability to perform predictive analysis and understand system-wide patterns is reduced
Solution Approach 1:
The patent implements a nested structure where individual log analyses are performed first, then results are aggregated into hierarchical patterns, and finally system-wide predictive analyses are conducted. This nested approach maintains the speed benefits of individual log analysis while progressively building up to comprehensive system-wide pattern recognition.
Solution Approach 2:
The patent adds a temporal and hierarchical dimension to log analysis by organizing analyses across multiple levels (individual logs, log groups, system-wide patterns) and time periods. This dimensional expansion enables predictive analysis while maintaining efficient processing through the hierarchical structure.
Data Source
AI summary
New data structures for analyzing a log are generated. A hierarchical data structure includes a plurality of hierarchical nodes. Each node is associated with data and metadata. Each node may also be associated with analysis data. Information (data, metadata, and/or analysis data) of an ancestor node is imputed to a descendant node; a descendant node inherits the information of an ancestor node. When determining analysis data for a particular hierarchical node, information from any ancestor node to the particular hierarchical node may be used; however, information from non-ancestor nodes is not necessarily used. A timeline data structure includes a reference to a hierarchical node within a hierarchical data structure and a reference to an event type. The timeline data structure is thereby associated with the information of the referenced hierarchical node and information of any ancestor nodes to the referenced hierarchical node.


