METHOD FOR MONITORING ABNORMAL BEHAVIOR IN A COMPUTER SYSTEM
First Claim
1. A method for monitoring a computer system in which a manager computer and a plurality of agent computers are connected over a network, comprising the steps of:
- sending information on types of log to be collected from said manager computer to said plurality of agent computers;
collecting said types of log on said plurality of agent computers; and
sending said collected log from said plurality of agent computers to said manager computer.
0 Assignments
0 Petitions
Accused Products
Abstract
The present invention relates to a method for monitoring a computer system in which one manager computer is connected to a plurality of agent computers over a network. The manager computer sends information on the types of log to be collected to the plurality of agent computers. In response, the plurality of agent computers collect the specified types of log. Then, the plurality of agent computers send the collected logs to the manager computer. Thus, the plurality of agent computers are able to collect the types of log specified by the manager computer.
-
Citations
7 Claims
-
1. A method for monitoring a computer system in which a manager computer and a plurality of agent computers are connected over a network, comprising the steps of:
-
sending information on types of log to be collected from said manager computer to said plurality of agent computers;
collecting said types of log on said plurality of agent computers; and
sending said collected log from said plurality of agent computers to said manager computer. - View Dependent Claims (2, 3, 4)
-
-
5. A method for monitoring a computer system in which a manager computer and a plurality of agent computers are connected over a network, comprising the steps of:
-
in response to an error occurring on one of said plurality of agent computers, supposing a first cause of said error on said manager computer;
sending a request from said manager computer to said plurality of agent computers, said request requesting to collect a log to prove said supposed first cause;
collecting the log to prove said supposed first cause on each of said plurality of agent computers;
sending said collected log from each of said plurality of agent computers to said manager computer;
supposing a second cause of the first cause on said manager computer; and
sending the request from said manager computer to said plurality of agent computers, said request requesting to collect the log to prove said supposed second cause. - View Dependent Claims (6)
-
-
7. A method for monitoring a computer system in which a manager computer and (n+1) agent computers are connected over a network, comprising the steps of:
-
dividing a log collected on said manager computer into n pieces of log information;
on said manager computer, generating appendage information to be added to the n pieces of log information;
distributing said n pieces of information and said appendage information among said (n+1) agent computers; and
on said (n+1) agent computers, encrypting and memorizing said distributed log information and said appendage information.
-
Specification