Method and computer system for correlating network event messages
First Claim
1. A method for correlating network event messages on a computer network comprising a message parsing service, an event correlation service, and a knowledge database coupled together via a plurality of interfaces, said method comprising:
- receiving a raw event at said message parsing service;
parsing said raw event by said message parsing service;
transmitting said parsed event to said event correlation service;
utilizing data stored in said knowledge database to derive an event from said parsed event; and
transmitting said derived event to one of a plurality of operator workstations, regardless of a significance of said derived event,wherein at least one of transmitting said parsed event and transmitting said derived event comprises transmitting a respective event via an event channel that accepts incoming events from a plurality of suppliers and that forwards the events to respective consumers that are registered to receive the events.
0 Assignments
0 Petitions
Accused Products
Abstract
A method and system are disclosed for efficiently correlating network events within a data processing system and then transmitting messages to various network entities in response to an occurrence of a particular network event. According to the present invention, a network mediation service receives raw message streams from one or more external networks and passes the streams in real-time to the event notification service. The event notification service then passes the message to the message parsing service for processing. After the message has been parsed by the message parsing service, it is passed back to the event notification service which passes the message along an event channel to the network management service. The message is also passed to the event correlation service for event correlation. A knowledge-based database of message classes that define how to interpret the message text are used by the event correlation service to match correlation rule conditions to the observed events. After event correlation service processes the parsed event, it is passed to the network management service for resolution.
57 Citations
17 Claims
-
1. A method for correlating network event messages on a computer network comprising a message parsing service, an event correlation service, and a knowledge database coupled together via a plurality of interfaces, said method comprising:
-
receiving a raw event at said message parsing service; parsing said raw event by said message parsing service; transmitting said parsed event to said event correlation service; utilizing data stored in said knowledge database to derive an event from said parsed event; and transmitting said derived event to one of a plurality of operator workstations, regardless of a significance of said derived event, wherein at least one of transmitting said parsed event and transmitting said derived event comprises transmitting a respective event via an event channel that accepts incoming events from a plurality of suppliers and that forwards the events to respective consumers that are registered to receive the events. - View Dependent Claims (2, 13)
-
-
3. A method for correlating network event messages on a computer network comprising a network mediation service, a message parsing service, an event notification service, an event correlation service, and a knowledge database coupled together via a plurality of interfaces, said method comprising:
-
receiving a raw event at said network mediation service from an external computer network; transmitting said raw event to said message parsing service;
parsing said raw event by said message parsing service;transmitting said parsed event to said event correlation service; utilizing data stored in said knowledge database to derive an event from said parsed event; and transmitting said derived event to one of a plurality of operator workstations, regardless of a significance of said derived event, wherein at least one of transmitting said raw event, transmitting said parsed event and transmitting said derived event comprises transmitting a respective event via an event channel that accepts incoming events from a plurality of suppliers and that forwards the events to respective consumers that are registered to receive the events. - View Dependent Claims (4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
14. A method for correlating network event messages on a computer network comprising a network mediation service, a message parsing service, an event notification service, and a network management service coupled together via a plurality of interfaces, said method comprising:
-
receiving a raw event at said network mediation service from an external computer network; transmitting said raw event to said message parsing service;
parsing said raw event by said message parsing service; andtransmitting said parsed event to said network management service, regardless of a significance of said parsed event, wherein at least one of transmitting said raw event and transmitting said parsed event comprises transmitting a respective event via an event channel that accepts incoming events from a plurality of suppliers and that forwards the events to respective consumers that are registered to receive the events. - View Dependent Claims (15, 16, 17)
-
Specification