System and method for enhancing event correlation with exploitation of external data
First Claim
1. A computer-implemented method comprising:
- receiving an event over a computer network;
identifying a correlation rule that corresponds to the event;
retrieving external data based upon the identified correlation rule;
determining whether to monitor the event based upon the external data; and
monitoring the event in response to the determination.
1 Assignment
0 Petitions
Accused Products
Abstract
A system and method for enhancing event correlation with exploitation of external data is presented. A correlation engine receives events and selects a correlation rule that corresponds to the events. The correlation rule includes an event selection, a trigger condition, and a correlation conclusion. The correlation engine uses the event selection to access external data and select events based upon the external data. In turn, the correlation engine monitors the selected events and checks whether they meet the correlation rule'"'"'s trigger condition. When the events meet the correlation rule'"'"'s trigger condition, the correlation engine performs an action based upon the correlation rule'"'"'s correlation condition.
-
Citations
20 Claims
-
1. A computer-implemented method comprising:
-
receiving an event over a computer network;
identifying a correlation rule that corresponds to the event;
retrieving external data based upon the identified correlation rule;
determining whether to monitor the event based upon the external data; and
monitoring the event in response to the determination. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A computer program product comprising:
a computer operable medium having computer readable code, the computer readable code effective to;
receive an event over a computer network;
identify a correlation rule that corresponds to the event;
retrieve external data based upon the identified correlation rule;
determine whether to monitor the event based upon the external data; and
monitor the event in response to the determination. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
15. An information handling system comprising:
-
one or more processors;
a memory accessible by the processors;
one or more nonvolatile storage devices accessible by the processors; and
an event correlation tool effective to;
receive an event over a computer network;
identify a correlation rule that corresponds to the event, the correlation rule included in one of the nonvolatile storage devices;
retrieve external data from one of the nonvolatile storage devices based upon the identified correlation rule;
determine whether to monitor the event based upon the external data; and
monitor the event in response to the determination. - View Dependent Claims (16, 17, 18, 19, 20)
-
Specification