System and method for analysis and management of logs and events
First Claim
1. A log record analyzing system for monitoring log records from external computerized systems, the external computerized systems using respectively initially undefined grammar types for log records, said log record analyzing system comprising:
- a processor, the processor being hardware and configured with;
a pattern repository configured to store a plurality of pattern object records, each of said stored pattern object records being of a respectively different log record grammar type, thereby to provide within said system a plurality of defined grammar types, incoming log records being matchable with said pattern records to find a matching structure, thereby to parse said incoming log records of undefined grammar type according to respectively matched structures, said matching thereby defining grammar types for parsing of said incoming log records; and
a parsing engine associated with said electronic pattern repository, comprising;
a raw log data input for receiving raw log data from said computerized system, said raw log data being of said undefined grammar type,a matching unit associated with said input for matching between said raw log data input and successive ones of said pattern object records to find one of said pattern object records having a structure most closely matching said raw log data irrespective of said matching being an exact match, selecting said pattern object record having said most closely matching structure and parsing said raw log data of undefined grammar type using said selected pattern object record and said matching structure to produce a parsed structured version of said raw log data of initially undefined grammar type; and
an output for outputting said parsed structured version of said raw log data of initially undefined grammar type, said parsed structured version thereby being rendered suitable for said monitoring, said closest matching being to ensure that said parsed structured version is provided and said monitoring enabled even when no exactly matching pattern object record is found, the system further comprising an automatic parsed data builder configured to identify the grammar of said raw log data input, said automatic parsed data builder being configured to output a pattern object according to said identified grammar, storing said pattern object in said pattern repository.
1 Assignment
0 Petitions
Accused Products
Abstract
A log record analyzing system for monitoring log records from at least one computerized system. The log record analyzing system comprises a pattern repository that stores a plurality of pattern object records of different grammar types and a parsing engine which is adapted to receive a raw log data input. The parsing engine facilitates the matching between the raw log data input and at least one of the pattern object records. The parsing engine outputs parsed data according to the matching.
-
Citations
18 Claims
-
1. A log record analyzing system for monitoring log records from external computerized systems, the external computerized systems using respectively initially undefined grammar types for log records, said log record analyzing system comprising:
-
a processor, the processor being hardware and configured with; a pattern repository configured to store a plurality of pattern object records, each of said stored pattern object records being of a respectively different log record grammar type, thereby to provide within said system a plurality of defined grammar types, incoming log records being matchable with said pattern records to find a matching structure, thereby to parse said incoming log records of undefined grammar type according to respectively matched structures, said matching thereby defining grammar types for parsing of said incoming log records; and a parsing engine associated with said electronic pattern repository, comprising; a raw log data input for receiving raw log data from said computerized system, said raw log data being of said undefined grammar type, a matching unit associated with said input for matching between said raw log data input and successive ones of said pattern object records to find one of said pattern object records having a structure most closely matching said raw log data irrespective of said matching being an exact match, selecting said pattern object record having said most closely matching structure and parsing said raw log data of undefined grammar type using said selected pattern object record and said matching structure to produce a parsed structured version of said raw log data of initially undefined grammar type; and an output for outputting said parsed structured version of said raw log data of initially undefined grammar type, said parsed structured version thereby being rendered suitable for said monitoring, said closest matching being to ensure that said parsed structured version is provided and said monitoring enabled even when no exactly matching pattern object record is found, the system further comprising an automatic parsed data builder configured to identify the grammar of said raw log data input, said automatic parsed data builder being configured to output a pattern object according to said identified grammar, storing said pattern object in said pattern repository. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18)
-
Specification