×

Correlation engine with support for time-based rules

  • US 8,176,527 B1
  • Filed: 12/02/2002
  • Issued: 05/08/2012
  • Est. Priority Date: 12/02/2002
  • Status: Expired due to Fees
First Claim
Patent Images

1. A computer-implemented method, comprising:

  • receiving, by a computer processor, a plurality of base events, wherein a base event originated in an event log entry that was generated by a network component, and wherein the base event includes a time attribute that indicates when the network component generated the event log entry;

    identifying a first rule that indicates a threshold number of base events and a first time period;

    determining how many base events include a time attribute that falls within the first time period;

    determining whether the threshold number of base events exceeds the number of base events that include a time attribute that falls within the first time period;

    when the threshold number of base events does not exceed the number of base events whose time attributes fall within the first time period, generating a first stage meta-event;

    identifying a second rule that indicates a threshold number of first stage meta-events and a second time period;

    when the threshold number of first stage meta-events does not exceed a number of first stage meta-events whose time attributes fall within the second time period, generating a second stage meta-event;

    detecting additional second stage meta-events;

    determining an amount of time that has passed since a most-recent second stage meta-event was detected; and

    when a threshold time period does not exceed the amount of time that has passed since the most-recent second stage meta-event was detected, generating a third stage meta-event.

View all claims
  • 11 Assignments
Timeline View
Assignment View
    ×
    ×