摘要 |
FIELD: information technology. ^ SUBSTANCE: method involves: accumulation of events describing the behaviour of the computer system, dividing events into groups based on their type and analysing events in order to determine reasons for unusual behaviour and/or problem in the operation of the system, wherein events are analysed by performing the following operations: events from each group are clustered into a set of clusters, wherein similarity between events is calculated by applying a similarity metric; clusters which describe abnormal behaviour or problem of operation of the system are determined, wherein the following rule is used: if an event in a cluster contains information indicating that the system function returned an incorrect value, then that cluster is considered a cluster which describes abnormal behaviour or problem in the operation of the system; reasons for abnormal behaviour or problems in operation of the system are determined, wherein stable components of events in each cluster are determined. ^ EFFECT: faster operation owing to automatic analysis of monitoring data. ^ 3 cl, 4 dwg |