Log Analytics System Using ML Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional log analytics tools face challenges in efficiently collecting and analyzing log records from large-scale computing systems due to their inability to scale with numerous hosts and applications, requiring manual configuration and lacking efficient classification of unknown log types.

Innovation Solution

A machine learning-based classification system that automates log grouping using a cloud-based or SaaS architecture, allowing for scalable log collection and analysis by associating log rules with targets and sources, reducing redundant processing, and enabling efficient classification of log types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional log analytics tools are used to collect and analyze log records from large-scale computing systems, then basic log collection functionality is provided, but the system cannot efficiently scale when posed with massive systems involving large numbers of computing systems and applications

Engineering Contradiction:
Improvelog analysis efficiencyVSAvoidsystem scalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system segments log collection and analysis by introducing log sources and log rules as independent configurable entities. Each log source represents a specific application or system component, and each log rule defines collection criteria. This segmentation allows the system to scale by adding individual log sources and rules without reconfiguring the entire system, enabling efficient handling of massive systems with numerous computing systems and applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements a universal log collection framework where a single log analytics platform can collect, normalize, and analyze logs from multiple diverse sources (different computing systems, applications, and log formats) through a common architecture. The normalization capability allows the system to handle various log formats universally, providing multi-functional log analysis across heterogeneous systems without requiring source-specific configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If conventional per-host configuration approach is used for log collection, then individual host log analysis is possible, but extensive manual configuration activities are required each time a new host is added or log collection activities need to be performed

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidconfiguration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary configuration by pre-defining log sources and log rules that can be reused across multiple hosts. Instead of configuring each host individually, administrators can create log sources and rules in advance, then apply them to multiple hosts simultaneously. This preliminary setup eliminates repetitive manual configuration activities when adding new hosts, significantly reducing configuration time and effort.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables copying of log source and log rule configurations across multiple hosts. Once a log source or rule is defined for one host, it can be replicated to other hosts with similar log collection requirements. This copying mechanism eliminates the need to manually recreate configurations for each new host, making the system easy to operate and scale.

Inventive Principle:
Principle #26Copying

3Loss of energy

If on-premise conventional solutions are used for log analytics, then local log processing is performed, but resource sharing and analysis component utilization are inadequate, causing significant redundant processing and resource usage

Engineering Contradiction:
Improveresource usage efficiencyVSAvoidsystem architecture
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The system merges log collection, normalization, and analysis capabilities into a centralized cloud-based platform that serves multiple hosts and applications. Instead of each host running separate log analysis components, the system consolidates these functions in a shared infrastructure. This merging eliminates redundant processing across multiple systems and optimizes resource utilization while maintaining a manageable system architecture through web-based interfaces and standardized protocols.

Inventive Principle:
Principle #5Merging (Combining)

4Measurement precision

If manual processes are used to classify log file types, then accurate classification can be achieved, but the process is highly manual and time-consuming

Engineering Contradiction:
Improveclassification accuracyVSAvoidclassification speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements automated log type classification that performs itself without manual intervention. The log analytics platform automatically detects log file types by analyzing log content patterns, formats, and characteristics. This self-service classification mechanism maintains high accuracy by using sophisticated pattern recognition while dramatically improving productivity by eliminating manual classification tasks, enabling the system to handle large volumes of logs efficiently.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240311386A1Method And System For Implementing Machine Learning Classifications
Publication Date: 2024.09.19 ORACLE INT CORP
  • US20240311386A1 patent drawing
  • US20240311386A1 patent drawing
  • US20240311386A1 patent drawing

AI summary

Disclosed is a system, method, and computer program product for implementing a log analytics method and system that can configure, collect, and analyze log records in an efficient manner. Machine learning-based classification can be performed to classify logs. This approach is used to group logs automatically using a machine learning infrastructure.