US 11,809,271 B1
System and method for identifying anomalies in data logs using context-based analysis
Dale Wang, Hayward, CA (US); Min Gong, Shanghai (CN); and Ashok Narayanan Potti, Bangalore (IN)
Assigned to Dell Products L.P., Round Rock, TX (US)
Filed by Dell Products L.P., Round Rock, TX (US)
Filed on Jan. 12, 2023, as Appl. No. 18/153,462.
Int. Cl. G06F 11/07 (2006.01); G06F 11/00 (2006.01)
CPC G06F 11/0793 (2013.01) [G06F 11/008 (2013.01); G06F 11/0709 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method for managing data processing systems based on indications of anomalous behaviors, comprising:
obtaining a new log for a data processing system of the data processing systems;
obtaining operational statistics for the data processing system based on the new log, the operational statistics indicating a level of intensity of a workload of the data processing system over a period of time;
identifying a state of the data processing system based on the operational statistics;
obtaining a trained inference model based on the state of the data processing system;
ingesting at least a portion of the new log to the trained inference model to obtain a classification for the new log, the classification indicating whether the portion of the new log comprises an anomalous log segment; and
in a first instance of the classification where the new log comprises the anomalous log segment:
executing a remediation action set to manage an impact of a potential undesired operation of the data processing system, the remediation action set being based on the anomalous log segment and comprising at least one action selected from a group consisting of: (i) disabling a function of the data processing system, (ii) transferring the workload to another data processing system of the data processing systems, and (iii) disabling a hardware component of the data processing system,
wherein obtaining the operational statistics comprises:
identifying a time period based on a first timestamp and a second timestamp from the new log; and
obtaining the operational statistics for the time period from an operational statistics log for the data processing system.