×

Systems and methods for correlating log messages into actionable security incidents and managing human responses

  • US 8,156,553 B1
  • Filed: 07/11/2008
  • Issued: 04/10/2012
  • Est. Priority Date: 07/11/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method of managing incidents comprising:

  • at a computer having at least one processor, comparing a plurality of parsed log messages to one another, wherein the plurality of parsed log messages are free form log messages, wherein parsing occurs substantially in real time;

    if two or more of the plurality of parsed log messages correlate, generating one or more correlation messages and comparing the one or more correlation messages to a plurality of incident descriptions;

    determining from the one or more correlation messages whether to create an incident case corresponding to the one or more correlation messages;

    associating one or more workflow steps with the incident case; and

    outputting the incident case with the workflow steps.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×