System and method for providing a global real-time advanced correlation environment architecture
0 Assignments
0 Petitions
Accused Products
Abstract
A method and system are disclosed for efficiently correlating network events within a data processing system and then transmitting messages to various network entities in response to an occurrence of a particular network event. According to the present invention, a network mediation service receives raw message streams from one or more external networks and passes the streams in real-time to the event notification service. The event notification service then passes the message to the message parsing service for processing. After the message has been parsed by the message parsing service, it is passed back to the event notification service which passes the message along an event channel to the network management service. The message is also passed to the event correlation service for event correlation. A knowledge-based database of message classes that define how to interpret the message text are used by the event correlation service to match correlation rule conditions to the observed events. After event correlation service processes the parsed event, it is passed to the network management service for resolution.
58 Citations
50 Claims
-
1-33. -33. (canceled)
-
34. A method for correlating network event messages on a computer network comprising a message parsing service, an event correlation service, and a knowledge database coupled together via a plurality of interfaces, said method comprising:
-
receiving a raw event at said message parsing service;
parsing said raw event by said message parsing service;
transmitting said parsed event to said event correlation service;
utilizing data stored in said knowledge database to derive an event from said parsed event; and
transmitting said derived event to one of a plurality of operator workstations, regardless of a significance of said derived event. - View Dependent Claims (35, 46)
-
-
36. A method for correlating network event messages on a computer network comprising a network mediation service, a message parsing service, an event notification service, an event correlation service, and a knowledge database coupled together via a plurality of interfaces, said method comprising:
-
receiving a raw event at said network mediation service from an external computer network;
transmitting said raw event to said message parsing service;
parsing said raw event by said message parsing service;
transmitting said parsed event to said event correlation service;
utilizing data stored in said knowledge database to derive an event from said parsed event; and
transmitting said derived event to one of a plurality of operator workstations, regardless of a significance of said derived event. - View Dependent Claims (37, 38, 39, 40, 41, 42, 43, 44, 45)
-
-
47. A method for correlating network event messages on a computer network comprising a network mediation service, a message parsing service, an event notification service, and a network management service coupled together via a plurality of interfaces, said method comprising:
-
receiving a raw event at said network mediation service from an external computer network;
transmitting said raw event to said message parsing service;
parsing said raw event by said message parsing service; and
transmitting said parsed event to said network management service, regardless of a significance of said parsed event. - View Dependent Claims (48, 49, 50)
-
Specification