System and method for tracking and filtering alerts in an enterprise and generating alert indications for analysis
First Claim
Patent Images
1. A method of producing at least one alert indication based on a number of events derived from an enterprise comprising:
- providing a plurality of enterprise device outputs, at least a portion of the outputs having different formats, each output containing an event relating to an enterprise device;
translating each output into a common format event, adding knowledge to the common format event using knowledge base table files to generate a knowledge-containing common format event; and
applying one or more rules from a set of rules to the knowledge-containing common format event to generate the alert indication.
3 Assignments
0 Petitions
Accused Products
Abstract
A system and method for declaring alert indications that occur in an enterprise comprising translating a number of device outputs into a common format event using a number of translation files, and generating a number of knowledge-containing common format events based on matches between the common format events and knowledge base tables. A set of rules determines whether the knowledge base common format events rise to an alert indication for further automated correlation and analysis.
-
Citations
22 Claims
-
1. A method of producing at least one alert indication based on a number of events derived from an enterprise comprising:
-
providing a plurality of enterprise device outputs, at least a portion of the outputs having different formats, each output containing an event relating to an enterprise device;
translating each output into a common format event, adding knowledge to the common format event using knowledge base table files to generate a knowledge-containing common format event; and
applying one or more rules from a set of rules to the knowledge-containing common format event to generate the alert indication. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 21, 22)
-
-
15. A system for producing at least one alert indication based on a number of events derived from an enterprise comprising:
-
a plurality of enterprise devices, each device capable of producing an output;
a number of translation files, the translation files allowing the output to be translated into a common format event;
a number of knowledge base table files, matching of the common format event with one or more of the knowledge base table files adding knowledge from the matched file to generate a knowledge-containing common format event;
a number of rule files, the rule files governing generation of the alert indication. - View Dependent Claims (16, 17, 18, 19, 20)
-
Specification