Method for transforming and consolidating fields in log records from logs generated on different operating systems
First Claim
Patent Images
1. A computer-implemented method of translating an event record of an event log into a reconstituted event record, the method comprising acts of:
- rendering data contained in the event record into at least one data set;
transforming, on a computer having at least one transformation engine, the at least one data set into at least one transformed data set using the at least one transformation engine including;
a security level transformation engine,a user account transformation engine,a keyword/opcode transformation engine,a category/description transformation engine, andan event identifier transformation engine; and
generating the reconstituted event record from the at least one transformed data set, the reconstituted event record comprising the data contained in the event record in a format that is common to a pre-MICROSOFT WINDOWS®
VISTA operating system event log and a MICROSOFT WINDOWS®
VISTA operating system event log, such that the reconstituted event record can be managed on a computer executing any version of the MICROSOFT WINDOWS®
operating system prior to and including the MICROSOFT WINDOWS®
VISTA operating system;
wherein the category/description transformation engine is operable to query, based on information in the at least one data set, a system registry to locate a message file containing a category message corresponding to a task number associated with the event record; and
wherein the category/description transformation engine is further operable to locate the message file by sequentially applying a series of offset numbers to an event identifier in the event record.
6 Assignments
0 Petitions
Accused Products
Abstract
An event log translator for reading and translating, when necessary, the event log records from two distinct event log file formats (e.g. EVT and EVTX formats). Moreover, it is a system for consolidating the log records contained in either of the above formats into a common set of fields, which can be displayed to the user of a computer, exported into different formats (e.g. text files, database tables, etc) or consumed by an event log management system.
46 Citations
10 Claims
-
1. A computer-implemented method of translating an event record of an event log into a reconstituted event record, the method comprising acts of:
-
rendering data contained in the event record into at least one data set; transforming, on a computer having at least one transformation engine, the at least one data set into at least one transformed data set using the at least one transformation engine including; a security level transformation engine, a user account transformation engine, a keyword/opcode transformation engine, a category/description transformation engine, and an event identifier transformation engine; and generating the reconstituted event record from the at least one transformed data set, the reconstituted event record comprising the data contained in the event record in a format that is common to a pre-MICROSOFT WINDOWS®
VISTA operating system event log and a MICROSOFT WINDOWS®
VISTA operating system event log, such that the reconstituted event record can be managed on a computer executing any version of the MICROSOFT WINDOWS®
operating system prior to and including the MICROSOFT WINDOWS®
VISTA operating system;wherein the category/description transformation engine is operable to query, based on information in the at least one data set, a system registry to locate a message file containing a category message corresponding to a task number associated with the event record; and wherein the category/description transformation engine is further operable to locate the message file by sequentially applying a series of offset numbers to an event identifier in the event record. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
Specification