×

Method for transforming and consolidating fields in log records from logs generated on different operating systems

  • US 8,086,650 B1
  • Filed: 11/02/2007
  • Issued: 12/27/2011
  • Est. Priority Date: 06/15/2007
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method of translating an event record of an event log into a reconstituted event record, the method comprising acts of:

  • rendering data contained in the event record into at least one data set;

    transforming, on a computer having at least one transformation engine, the at least one data set into at least one transformed data set using the at least one transformation engine including;

    a security level transformation engine,a user account transformation engine,a keyword/opcode transformation engine,a category/description transformation engine, andan event identifier transformation engine; and

    generating the reconstituted event record from the at least one transformed data set, the reconstituted event record comprising the data contained in the event record in a format that is common to a pre-MICROSOFT WINDOWS®

    VISTA operating system event log and a MICROSOFT WINDOWS®

    VISTA operating system event log, such that the reconstituted event record can be managed on a computer executing any version of the MICROSOFT WINDOWS®

    operating system prior to and including the MICROSOFT WINDOWS®

    VISTA operating system;

    wherein the category/description transformation engine is operable to query, based on information in the at least one data set, a system registry to locate a message file containing a category message corresponding to a task number associated with the event record; and

    wherein the category/description transformation engine is further operable to locate the message file by sequentially applying a series of offset numbers to an event identifier in the event record.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×