Event source management using a metadata-driven framework
First Claim
1. A collector system including at least one collector connected to one or more network devices, comprising:
- collecting means for collecting event data from the one or more network devices;
filtering means for filtering the event data based on one or more preconfigured filters;
parsing means for parsing the filtered event data to a normalized form;
transmitting means for transmitting the normalized event data to a central manager for reporting.
9 Assignments
0 Petitions
Accused Products
Abstract
A system and method that relates to managing multiple network device connections and/or collectors for collecting event source data from one or more network devices, filtering event source data, continuously monitoring connection status to the one or more network devices, controlling raw data collection from the one or more network devices, parsing event source data into normalized data structures, and/or managing collector configurations, among other things. Event sources may be network devices (physical or logical) across a network, including but not limited to, firewalls, routers, biometric devices, mainframes, databases and/or applications. A network device may be a source from which a collector may receive and/or request event data.
-
Citations
30 Claims
-
1. A collector system including at least one collector connected to one or more network devices, comprising:
-
collecting means for collecting event data from the one or more network devices; filtering means for filtering the event data based on one or more preconfigured filters; parsing means for parsing the filtered event data to a normalized form; transmitting means for transmitting the normalized event data to a central manager for reporting. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A collector framework system including at least one collector for collecting event data from one or more network devices, the system comprising:
-
a collector manager for storing a collector script; configuring means for configuring a collector based on the collector script; a proxy manager for determining one or more network devices to connect to the collector based on the collector script, wherein the collector collects event data from the one or more network devices; and receiving means for receiving the collected event data from the collector manager. - View Dependent Claims (13, 14, 15)
-
-
16. A method for collecting data using at least one collector connected to one or more network devices, comprising:
-
collecting event data from the one or more network devices; filtering the event data based on one or more preconfigured filters; parsing the filtered event data to a normalized form; and transmitting the normalized event data to a central manager for reporting. - View Dependent Claims (17, 18, 19, 20, 21, 22, 23, 24, 25, 26)
-
-
27. A computer based method including at least one collector for collecting event data from one or more network devices, comprising the step of:
-
configuring a collector process based on the collector script; determining one or more network devices to connect to the collector based on the collector script, wherein the collector process collects event data from the one or more network devices; and receiving the collected event data from a collector manager. - View Dependent Claims (28, 29, 30)
-
Specification