Method and apparatus for monitoring events in a system
First Claim
Patent Images
1. A computer-implemented method of monitoring events in a computer system, the method comprising the steps of:
- (a) accessing a set of one or more filters;
(b) checking whether a new event in one or more event logs updated as a function of an operating system executing on the computer system satisfies the set of one or more filters;
(c) providing an indication if there is a new event which satisfies the set of one or more filters; and
(d) automatically repeating the checking step (b) and the providing step (c) at periodic intervals.
1 Assignment
0 Petitions
Accused Products
Abstract
An event log forwarder accesses a set of one or more filters and checks whether a new event in one or more event logs satisfies the set of one or more filters. The event log forwarder also provides an indication if there is a new event which satisfies the set of one or more filters. Additionally, the event log forwarder automatically repeats, at periodic intervals, checking whether a new event in one or more event logs satisfies the set of one or more filters and providing an indication if there is a new event which satisfied the set of one or more filters.
-
Citations
21 Claims
-
1. A computer-implemented method of monitoring events in a computer system, the method comprising the steps of:
-
(a) accessing a set of one or more filters; (b) checking whether a new event in one or more event logs updated as a function of an operating system executing on the computer system satisfies the set of one or more filters; (c) providing an indication if there is a new event which satisfies the set of one or more filters; and (d) automatically repeating the checking step (b) and the providing step (c) at periodic intervals. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A computer-implemented method of identifying events to be monitored in a computer system, the method comprising the steps of:
-
(a) receiving an indication of an event log updated as a function of an operating system executing on the computer system; (b) receiving an indication of an application; (c) receiving an indication of an event; and (d) storing the event log, the application, and the event as a filter in the system. - View Dependent Claims (9)
-
-
10. A computer-readable medium having stored thereon a plurality of instructions, the plurality of instructions including instructions which, when executed by a processor, result in:
-
(a) accessing a set of one or more filters; (b) checking whether a new event in one or more event logs updated as a function of an operating system executing on a computer system satisfies the set of one or more filters; (c) providing an indication if there is a new event which satisfies the set of one or more filters; and (d) automatically repeating the checking step (b) and the providing step (c) at periodic intervals. - View Dependent Claims (11, 12, 13, 14)
-
-
15. An apparatus comprising:
-
a storage device which stores a set of one or more filters; and a processor, coupled to the storage device, to access the set of one or more filters, to check whether a new event in one or more event logs updated as a function of the apparatus satisfies the set of one or more filters, to provide an indication if there is a new event which satisfies the set of one or more filters, and to automatically re-check the one or more event logs for the new event at periodic intervals. - View Dependent Claims (16, 17, 18)
-
-
19. An apparatus comprising:
-
means for accessing a set of one or more filters; means for checking whether a new event in one or more event logs updated as a normal function of the apparatus satisfies the set of one or more filters; means for providing an indication if there is a new event in the one or more event logs which satisfies the set of one or more filters; and means for automatically re-checking the one or more event logs for the new event at periodic intervals. - View Dependent Claims (20, 21)
-
Specification