CPC G06F 16/285 (2019.01) [G06N 20/00 (2019.01)] | 20 Claims |
1. A computer-implemented method comprising:
obtaining a data stream containing a set of events, each event representing machine data generated based on operation of a computing system;
passing individual events of the data stream through a streaming data processor configured to group events from the data stream into episodes, each episode corresponds to a subset of events grouped together according to similarities between events of the subset, wherein passing individual events of the data stream through the streaming data processor comprises:
comparing attributes of an individual event to aggregate attributes of an existing episode, the aggregate attributes representing an aggregation of attributes of events within the existing episode;
determining whether attributes of the individual event are within a threshold similarity level to the aggregate attributes; and
responsive to determining that the attributes of the individual event are not within the threshold similarity level, generating an additional episode including the individual event; and
outputting the events grouped into episodes as a record of operation of the computing system.
|