×

System and method for analysis and management of logs and events

  • US 7,895,167 B2
  • Filed: 02/16/2006
  • Issued: 02/22/2011
  • Est. Priority Date: 02/16/2005
  • Status: Active Grant
First Claim
Patent Images

1. A log record analyzing system for monitoring log records from external computerized systems, the external computerized systems using respectively initially undefined grammar types for log records, said log record analyzing system comprising:

  • a processor, the processor being hardware and configured with;

    a pattern repository configured to store a plurality of pattern object records, each of said stored pattern object records being of a respectively different log record grammar type, thereby to provide within said system a plurality of defined grammar types, incoming log records being matchable with said pattern records to find a matching structure, thereby to parse said incoming log records of undefined grammar type according to respectively matched structures, said matching thereby defining grammar types for parsing of said incoming log records; and

    a parsing engine associated with said electronic pattern repository, comprising;

    a raw log data input for receiving raw log data from said computerized system, said raw log data being of said undefined grammar type,a matching unit associated with said input for matching between said raw log data input and successive ones of said pattern object records to find one of said pattern object records having a structure most closely matching said raw log data irrespective of said matching being an exact match, selecting said pattern object record having said most closely matching structure and parsing said raw log data of undefined grammar type using said selected pattern object record and said matching structure to produce a parsed structured version of said raw log data of initially undefined grammar type; and

    an output for outputting said parsed structured version of said raw log data of initially undefined grammar type, said parsed structured version thereby being rendered suitable for said monitoring, said closest matching being to ensure that said parsed structured version is provided and said monitoring enabled even when no exactly matching pattern object record is found, the system further comprising an automatic parsed data builder configured to identify the grammar of said raw log data input, said automatic parsed data builder being configured to output a pattern object according to said identified grammar, storing said pattern object in said pattern repository.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×