主权项 |
1. An event clustering system that generates reports, comprising:
an extraction engine in communication with an infrastructure, the extraction engine in operation receiving data from the infrastructure and produces events; an alert engine that receives the events and creates alerts mapped into a matrix, M; a sigalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine, the sigalizer engine determining one or more common steps from events and produces clusters relating to the alerts and or events; and a reporting engine configured to be coupled to the event clustering system. |