×

System and method for tracking and filtering alerts in an enterprise and generating alert indications for analysis

  • US 7,171,689 B2
  • Filed: 02/25/2002
  • Issued: 01/30/2007
  • Est. Priority Date: 02/25/2002
  • Status: Active Grant
First Claim
Patent Images

1. A method of producing at least one alert indication based on a number of events derived from an enterprise comprising:

  • providing a plurality of enterprise device outputs, at least a portion of the outputs having different formats, each output containing an event relating to an enterprise device;

    translating each output into a common format event comprising;

    matching data values in the device output with a signature specification for each enterprise device, the signature specification containing;

    a number of signatures;

    a first location identifier for each signature; and

    a first key;

    wherein the signature is a listing of names found in the device output, the first location identifier determines the method used to locate the name in the device output, and the first key determines where to locate the name in the device output;

    identifying a message type from a plurality message types for each enterprise device based on the device output as part of the translated common format event;

    adding knowledge to the common format event using knowledge base table files to generate a knowledge-containing common format event;

    applying one or more rules from a set of rules to the knowledge-containing common format event to generate the alert indication; and

    generating the alert indication, wherein the alert indication includes at least a text message describing the event contained in the output of the enterprise device.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×