Patents by Inventor FAN JING MENG

FAN JING MENG has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20220180217
    Abstract: Aspects of the invention include computer systems, computer-implemented methods, and computer program products configured to integrate documentation knowledge with log mining data. A non-limiting example computer-implemented method includes determining a message-message relationship based on log message documentation and building a first subgraph based on the message-message relationship. The method further includes receiving a first message log entry having a message identifier and message field data. A second message log entry is correlated with the first message log entry based on at least one of the message identifier and the message field data. A second subgraph is built that includes the first message log entry and the second message log entry. The method includes building a graph that includes the first subgraph and the second subgraph.
    Type: Application
    Filed: December 3, 2020
    Publication date: June 9, 2022
    Inventors: Yuk L. Chan, Lei Yu, Jia Qi Li, Zhi Shuai Han, Tian Wu, Hong Min, FAN JING Meng
  • Publication number: 20220179866
    Abstract: Aspects of the invention include computer systems, computer-implemented methods, and computer program products configured to perform message correlation extraction for mainframe operation. A non-limiting example computer-implemented method includes receiving a first message log entry having a message identifier and message field data. The first message log entry is pre-processed to determine the message identifier and to tokenize the message field data. A second message log entry is identified based on at least one of the message identifier and the tokenized message field data. The method further includes determining that the second message log entry is correlated with the first message log entry and providing an output comprising the message correlation between the first message log entry and the second message log entry.
    Type: Application
    Filed: December 3, 2020
    Publication date: June 9, 2022
    Inventors: Yuk L. Chan, Jia Qi Li, LIN Yang, Tian Wu, Lei Yu, Hong Min, FAN JING Meng
  • Publication number: 20220179763
    Abstract: Techniques include collecting current logs from distributed sources, selecting a group of the current logs that are from a related source of the distributed sources, and generating a feature vector using the group of the current logs. A current status model is created for the feature vector using the group of the current logs. One or more anomalies are determined in the group of the current logs based on a difference between the current status model and a reference status model, the reference status model being based on history logs.
    Type: Application
    Filed: December 3, 2020
    Publication date: June 9, 2022
    Inventors: Yuk L. Chan, Lin Yang, Tian Wu, Jia Qi Li, Lei Yu, Hong Min, Fan Jing Meng
  • Publication number: 20220179730
    Abstract: Techniques include generating a log sequence for new logs that have been received, searching a log sequence database for the log sequence having been generated, and determining that the log sequence is anomalous in response to not finding an identical log sequence in the log sequence database. In response to the log sequence not being found in the log sequence database, the log sequence is compared to a graph of historical log sequences to find a closest sequence path to one or more historical log sequences. An anomaly of the log sequence is diagnosed based on an occurrence at which the log sequence deviates from the closest sequence path of the one or more historical log sequences.
    Type: Application
    Filed: December 3, 2020
    Publication date: June 9, 2022
    Inventors: Yuk L. Chan, Jia Qi Li, Zhi Shuai Han, Tian Wu, Lei Yu, Hong Min, FAN JING Meng
  • Publication number: 20220179764
    Abstract: According to an aspect a computer-implemented method includes identifying a plurality of metrics and log identifiers that describe similar information as a plurality of documentation-based correlation data. One or more metric pair correlations are identified. One or more log frequency correlations are identified by temporal correlation. A plurality of correlated metric-log pairs is identified. A correlation database is populated with the documentation-based correlation data, the one or more metric pair correlations, the one or more log frequency correlations, and the correlated metric-log pairs to support anomaly detection in one or more monitored computer systems.
    Type: Application
    Filed: December 3, 2020
    Publication date: June 9, 2022
    Inventors: Yuk L. Chan, Tian Wu, Lei Yu, Jia Qi Li, Zhi Shuai Han, Hong Min, Fan Jing Meng, Abhishek Dokania
  • Publication number: 20220122000
    Abstract: Described are techniques for using a dynamic ensemble model. The techniques including training a plurality of machine learning models on training data. The techniques further include identifying a similar subset of the training data that is similar to a dataset for evaluation. The techniques further include assembling a subset of models from the plurality of machine learning models based on performance of the subset of models on the similar subset of the training data. The techniques further include generating an output from the subset of models for the dataset for evaluation.
    Type: Application
    Filed: October 19, 2020
    Publication date: April 21, 2022
    Inventors: Jia Qi Li, Li Zhang, Jun Ying Lu, Fan Jing Meng, Shi Lei Zhang
  • Patent number: 11288291
    Abstract: A method and system for relation discovery from operation data includes classifying categories of extracted entities from operation data into three or more classes identified in a knowledge base. A log affiliation of the extracted entities is determined, and relations of the extracted entities are identified according to a log affiliation. The identified relations information of the extracted entities is associated with operation objects of the operation data.
    Type: Grant
    Filed: March 15, 2020
    Date of Patent: March 29, 2022
    Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Jia Qi Li, Fan Jing Meng, Jing Min Xu, Pei Ni Liu, Zi Xiao Zhu
  • Patent number: 11269714
    Abstract: Embodiments facilitating performance anomaly detection are described. A computer-implemented method comprises: detecting, by a device operatively coupled to one or more processing units, based on monitoring data of a plurality of performance metrics of a monitored device, at least one trend within the monitoring data of the respective performance metrics; removing, by the device, the at least one trend from the monitoring data of the respective performance metrics to generate modified data of the respective performance metrics; and detecting, by the device, a performance anomaly based on the modified data of the respective performance metrics and a behavior clustering model comprising at least one steady state.
    Type: Grant
    Filed: December 29, 2020
    Date of Patent: March 8, 2022
    Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Xiao Zhang, Fan Jing Meng, Lin Yang, Jing Min Xu
  • Patent number: 11270226
    Abstract: Systems and methods for ticket classification and response include labeling tickets with a ticket classifier that assigns a ticket label and an associated confidence score to each ticket. Tickets are clustered according to semantic similarity to form ticket clusters. A template associated with each ticket cluster is determined. Templates and the respective ticket clusters are clustered according to semantic similarity to form one or more ticket super-clusters. Tickets that have below-threshold confidence scores are labeled according to the one or more ticket super-clusters. The tickets are automatically responded to.
    Type: Grant
    Filed: October 1, 2018
    Date of Patent: March 8, 2022
    Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Fan Jing Meng, Lin Yang, Xiao Zhang, Shi Lei Zhang, Jing Min Xu, Naga A. Ayachitula, Zhuo Su
  • Patent number: 11243835
    Abstract: Aspects of the invention include constructing a knowledge graph by writing a plurality of data structures to connect correlated log messages in a system log. Detecting an anomalous log message based on the knowledge graph, wherein the anomalous log message is connected to a plurality of candidate root cause error log messages. Determining respective sequences from each of the plurality of candidate root cause error log messages to the anomalous log message. Calculating a deviation score for each respective sequence based on a deviation of an expected sequence for each candidate root cause error log message and the determined sequence. Determining a root cause log error message based on the calculated deviation scores.
    Type: Grant
    Filed: December 3, 2020
    Date of Patent: February 8, 2022
    Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Yuk L. Chan, Jia Qi Li, Lin Yang, Tian Wu, Lei Yu, Hong Min, Fan Jing Meng
  • Patent number: 11212162
    Abstract: Techniques for Bayesian-based event grouping are provided. One technique includes determining a group of alarm events from received alarm events; in response to the group of alarm events matching a group of historical alarm events, determining a first correlation, wherein the group of historical alarm events comprises correlated events associated with a same entity; and determining a root cause of the group of alarm events based on the first correlation.
    Type: Grant
    Filed: July 18, 2019
    Date of Patent: December 28, 2021
    Assignee: International Business Machines Corporation
    Inventors: Dian Qi, Fan Jing Meng, Jing Min Xu, Lin Yang
  • Patent number: 11190421
    Abstract: Embodiments of the present disclosure relate to a method for processing alerts. According to an embodiment of the present disclosure, a set of alerts matching a metric template are identified from received alerts during a period of time. A plurality of variable values are acquired from the set of alerts based on the metric template. The plurality of variable values are normalized according to a normalization rule of the metric template. A severity level for the set of alerts is determined based on the normalized variable values. In response to the severity level exceeding a certain threshold, an abstract alert including information related to the set of alerts is generated.
    Type: Grant
    Filed: March 1, 2021
    Date of Patent: November 30, 2021
    Assignee: International Business Machines Corporation
    Inventors: Pei Ni Liu, Zi Xiao Zhu, Tian Wu, Jia Qi Li, Fan Jing Meng, Ruo Yi Liu
  • Patent number: 11157267
    Abstract: A computer-implemented method includes receiving, by a processor, real time operation data related to an application, identifying components of the application based on the operation data, extracting relationships and interdependencies between the components, and generating a graph of the identified components, the relationships and the interdependencies. The method also includes determining one or more dynamic metrics of the identified components, the one or more dynamic metrics indicative of interactions between the components, extracting statistical information describing at least one of performance and resource consumption based on the operation data, incorporating the dynamic metrics into the graph, determining a behavior of at least one component based on a pattern of appearance of the at least one component in the graph, and generating a model of the application based on the identified components and the determined behaviors.
    Type: Grant
    Filed: September 9, 2020
    Date of Patent: October 26, 2021
    Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Jia Qi Li, Zhi Shuai Han, Fan Jing Meng, Amith Singhee, David Scott Wenk, Rahamim Katan, Saravanan Krishnan, Vini Kanvar
  • Publication number: 20210286828
    Abstract: A method and system for relation discovery from operation data includes classifying categories of extracted entities from operation data into three or more classes identified in a knowledge base. A log affiliation of the extracted entities is determined, and relations of the extracted entities are identified according to a log affiliation. The identified relations information of the extracted entities is associated with operation objects of the operation data.
    Type: Application
    Filed: March 15, 2020
    Publication date: September 16, 2021
    Inventors: Jia Qi Li, Fan Jing Meng, Jing Min Xu, Pei Ni Liu, Zi Xiao Zhu
  • Publication number: 20210286798
    Abstract: A computer-implemented method, system, and non-transitory machine readable medium for a graph-based analysis for an Information Technology (IT) operations includes generating a temporal graph by extracting one or more of operation objects, relations and attributes from operation data of workloads distributed across a plurality of levels of the IT operation within a predetermined time window. Anomalies are detected from the extracted operation data and annotating corresponding objects in the graph. A directional impact between corresponding objects on the temporal graph is determined, and the temporal graph is refined based on the determined directional impact. Accessible paths in the temporal graph indicating error propagation are searched, and potential causes for the detected anomalies in the temporal graph are identified. A list of the potential causes of the anomalies is generated, and a root cause ranked for each of the corresponding objects in the temporal graph.
    Type: Application
    Filed: March 15, 2020
    Publication date: September 16, 2021
    Inventors: Jia Qi Li, Fan Jing Meng, Pei Ni Liu, Zi Xiao Zhu, Matt Hogstrom, Dong Sheng Li
  • Publication number: 20210286819
    Abstract: A method and system for operation objects discovery from operation data includes performing pattern matching of operation data with patterns in a database. Fields in the operation data are identified as having matching patterns with the database as first potential objects. Data profiling is performed on unmatched fields of the operation data to generate data profiles. The data profiles are field classified and second potential objects are generated. The first potential objects and the second potential objects are de-duplicated, and operation objects are generated.
    Type: Application
    Filed: March 15, 2020
    Publication date: September 16, 2021
    Inventors: Jia Qi Li, Fan Jing Meng, Pei Ni Liu, Junmei Qu, Zi Xiao Zhu
  • Publication number: 20210286826
    Abstract: A system and method for attribute discovery for operation objects from operation data includes segmenting a name of each of a plurality of operation objects based on one or more special characters used in the name of each operation object. A similarity comparison of the operation objects is performed by extracting common subsequences from substrings in operation data in a same log as a target object, and a string similarity is computed of the extracted common subsequences. Numerical attributes are determined by calculating statistical metrics for fields in the log, and additional information of the operation objects is discovered based on the determined numerical attributes.
    Type: Application
    Filed: March 15, 2020
    Publication date: September 16, 2021
    Inventors: Jia Qi Li, Fan Jing Meng, Jing Min Xu, Zi Xiao Zhu
  • Patent number: 11055403
    Abstract: A method, system, and computer program product, include extracting information related to one or more processes of one or more applications running on a virtual machine from a memory of the virtual machine, building at least one first application signature based on the extracted information, and identifying the one or more applications running on the virtual machine by matching the at least one first application signature with one or more second application signatures previously stored.
    Type: Grant
    Filed: January 6, 2017
    Date of Patent: July 6, 2021
    Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Peng Fei Chen, Fan Jing Meng, Jing Min Xu, Lin Yang, Xiao Zhang
  • Patent number: 11029969
    Abstract: Determining a characteristic of a configuration file that is used to discover configuration files in a target machine, a computer identifies, using information associated with a configuration item of a machine, a candidate configuration file related to the configuration item of the machine, from among a plurality of files from the machine. The computer extracts a value of a feature of the candidate configuration file and aggregates the candidate configuration file with a second candidate configuration file related to the same configuration item identified from among a plurality of files from a second machine, based on the extracted value. The computer then determines a configuration file related to the configuration item from among the aggregated candidate configuration files based on a result of the aggregation, and determines a characteristic of the configuration file related to the configuration item.
    Type: Grant
    Filed: July 10, 2018
    Date of Patent: June 8, 2021
    Assignee: International Business Machines Corporation
    Inventors: Ajay A. Apte, Chang Sheng Li, Fan Jing Meng, Joseph P. Wigglesworth, Jing Min Xu, Bo Yang, Xue Jun Zhuo
  • Publication number: 20210117260
    Abstract: Embodiments facilitating performance anomaly detection are described. A computer-implemented method comprises: detecting, by a device operatively coupled to one or more processing units, based on monitoring data of a plurality of performance metrics of a monitored device, at least one trend within the monitoring data of the respective performance metrics; removing, by the device, the at least one trend from the monitoring data of the respective performance metrics to generate modified data of the respective performance metrics; and detecting, by the device, a performance anomaly based on the modified data of the respective performance metrics and a behavior clustering model comprising at least one steady state.
    Type: Application
    Filed: December 29, 2020
    Publication date: April 22, 2021
    Inventors: Xiao Zhang, Fan Jing Meng, Lin Yang, Jing Min Xu