Method for processing log data from local and remote log-producing devices
First Claim
1. A method for processing log data from a plurality of log-producing devices comprising:
- receiving in a raw log server raw log data from a local log-producing device;
collecting the raw log data from a local log-producing device into time-defined sets;
storing a set of raw log data in a first temporary data buffer;
receiving a set of raw log data via a wide area network from a remote log data analyzer;
storing the set of raw log data from the remote log data analyzer in a second temporary data buffer;
combining the raw log data from the first and second temporary data buffers to form a combined data set; and
, storing the combined data set.
3 Assignments
0 Petitions
Accused Products
Abstract
A system and method is disclosed for collecting, storing and reporting raw log data from log-producing devices such as firewalls and routers. The log-producing devices may be both local and remote—i.e., linked to a raw log server via a LAN and/or a WAN. A log data analyzer at a remote location gathers log data from devices at that remote location into time-defined sets and then sends those sets over a WAN (which may be the Internet) to a raw log server using a first protocol. Local log-producing devices may send their log data to the log data analyzer via a LAN using a second protocol. The log data analyzer forwards the raw log data local devices to an appropriate log data analyzer for parsing, summarizing and storage in one or more databases. The raw log server combines local and remote sets of raw log data for a given time period and stores them in a storage area of raw log data. A central management station is used to query the various databases in the system and to merge database reports into a single report for display.
-
Citations
20 Claims
-
1. A method for processing log data from a plurality of log-producing devices comprising:
-
receiving in a raw log server raw log data from a local log-producing device;
collecting the raw log data from a local log-producing device into time-defined sets;
storing a set of raw log data in a first temporary data buffer;
receiving a set of raw log data via a wide area network from a remote log data analyzer;
storing the set of raw log data from the remote log data analyzer in a second temporary data buffer;
combining the raw log data from the first and second temporary data buffers to form a combined data set; and
,storing the combined data set. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A data processing system for processing log data from a plurality of log-producing devices comprising a raw log server which:
-
receives raw log data from a local log-producing device;
collects the raw log data from a local log-producing device into time-defined sets;
stores a set of raw log data in a first temporary data buffer;
receives a set of raw log data via a wide area network from a remote log data analyzer;
stores the set of raw log data from the remote log data analyzer in a second temporary data buffer;
combines the raw log data from the first and second temporary data buffers to form a combined data set; and
,stores the combined data set. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification