GENERATING EVENTS FROM HOST BASED LOGGING FOR CONSUMPTION BY A NETWORK LOGGING HOST
First Claim
Patent Images
1. A network traffic analysis system including a network based logging host, the system comprising:
- a processing system; and
a memory device coupled to the processing system and including instructions stored thereon that, in response to execution by the processing system, are operable to perform operations including;
collecting, using a log transport module, one or more messages including one or more host event logs from the one or more remote hosts, respectively; and
inputting the collected messages into an event parser, the event parser to generate normalized events consumable by the network logging host from the collected messages, the event parser configured to;
classify each message based on one of a plurality of predetermined event types;
apply a rule of a plurality of predetermined rules to each event based on the classified event types to select content from the message; and
extract the selected content and generate an event based on the extracted content and the corresponding rule; and
exposing the generated events to one or more consumer modules of the network logging host.
2 Assignments
0 Petitions
Accused Products
Abstract
In an example, a network traffic analysis system including a network based logging host may include a transport module, an event parser, and one or more consumer modules. The transport module may collect one or more messages including one or more event logs from one or more remote hosts, respectively. The event parser may generate normalized events consumable by the network logging host from the collected messages. The consumer modules may host process metadata of the event out to file for analysis. Other embodiments may be disclosed and/or claimed.
-
Citations
20 Claims
-
1. A network traffic analysis system including a network based logging host, the system comprising:
-
a processing system; and a memory device coupled to the processing system and including instructions stored thereon that, in response to execution by the processing system, are operable to perform operations including; collecting, using a log transport module, one or more messages including one or more host event logs from the one or more remote hosts, respectively; and inputting the collected messages into an event parser, the event parser to generate normalized events consumable by the network logging host from the collected messages, the event parser configured to; classify each message based on one of a plurality of predetermined event types; apply a rule of a plurality of predetermined rules to each event based on the classified event types to select content from the message; and extract the selected content and generate an event based on the extracted content and the corresponding rule; and exposing the generated events to one or more consumer modules of the network logging host. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A network traffic analysis system including a network based logging platform, the network traffic analysis system comprising:
-
a transport module configured to collect one or more messages over a network, the one or more messages including one or more host event logs from the one or more remote hosts, respectively; wherein the network based logging platform comprises one or more processors, and the network traffic analysis system further comprises; a script configured to establish a communication link with the one or more processors; the script configured to receive data from the transport module in a predetermined format, the data based on the one or more host event logs; the script configured to extract key values from the received data and assign the key values to variables; the script configured to construct one or more events using the variables and provide the one or more events over the communication link. - View Dependent Claims (8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A method, comprising:
-
collecting, at a network traffic analysis system including a first network based logging host and over a network, one or more messages including one or more host event logs from the one or more second hosts, respectively; establishing a communication link with the first network based logging host; generating object notation data from data of the one or more messages; extracting key values from the object notation data and assign the key values to variables; constructing one or more events using the variables; and transmitting the one or more events over the communication link. - View Dependent Claims (17, 18, 19, 20)
-
Specification