Flexible event data content management for relevant event and alert analysis within a distributed processing system
First Claim
1. A method of flexible event data content management for relevant event and alert analysis within a distributed processing system, the method comprising:
- analyzing, by an interface connector, custom data within a raw event to determine a location to store the custom data, the custom data in a first data format;
storing, by the interface connector, extended data within the raw event in a common event data format, the extended data indicating the location of the custom data;
receiving, by an event analyzer, the event; and
determining whether there are custom customer rules that need the custom data; and
if there are such custom customer rules, retrieving the custom data based on the extended data from the event, including;
determining if the custom data is stored in the extended data; and
if the custom data is stored within the extended data, extracting the custom data from the extended data within the event; and
applying the custom customer rules to the extended data;
if there are no such custom customer rules, applying the base rules to a base portion of the event.
1 Assignment
0 Petitions
Accused Products
Abstract
Flexible event data content management for relevant event and alert analysis within a distributed processing system includes receiving, by an interface connector, a raw event from a component of the distributed processing system; analyzing custom data within the raw event to determine a location to store the custom data, the custom data in a first data format; storing extended data within the raw event in a common event data format, the extended data indicating the location of the custom data; receiving, by an event analyzer, the event; and determining whether there are custom customer rules that need the custom data; and if there are such custom customer rules, retrieving the custom data based on the extended data from the event; and applying the custom customer rules to the extended data; if there are no such custom customer rules, applying the base rules to a base portion of the event.
-
Citations
15 Claims
-
1. A method of flexible event data content management for relevant event and alert analysis within a distributed processing system, the method comprising:
-
analyzing, by an interface connector, custom data within a raw event to determine a location to store the custom data, the custom data in a first data format; storing, by the interface connector, extended data within the raw event in a common event data format, the extended data indicating the location of the custom data; receiving, by an event analyzer, the event; and determining whether there are custom customer rules that need the custom data; and if there are such custom customer rules, retrieving the custom data based on the extended data from the event, including; determining if the custom data is stored in the extended data; and if the custom data is stored within the extended data, extracting the custom data from the extended data within the event; and applying the custom customer rules to the extended data; if there are no such custom customer rules, applying the base rules to a base portion of the event. - View Dependent Claims (2, 3, 4, 5)
-
-
6. A system for flexible event data content management for relevant event and alert analysis within a distributed processing system, the system comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions capable, when executed by the computer processor, of causing the system to carry out the steps of:
-
analyzing, by an interface connector, custom data within a raw event to determine a location to store the custom data, the custom data in a first data format; storing, by the interface connector, extended data within the raw event in a common event data format, the extended data indicating the location of the custom data; receiving, by an event analyzer, the event; and determining whether there are custom customer rules that need the custom data; and if there are such custom customer rules, retrieving the custom data based on the extended data from the event, including; determining if the custom data is stored in the extended data; and if the custom data is stored within the extended data, extracting the custom data from the extended data within the event; and applying the custom customer rules to the extended data; if there are no such custom customer rules, applying the base rules to a base portion of the event. - View Dependent Claims (7, 8, 9, 10)
-
-
11. A computer program product for restarting event and alert analysis in a distributed processing system, the computer program product disposed upon a computer readable storage medium, wherein the computer readable storage medium is not a signal and the computer program product comprises computer program instructions for:
-
analyzing, by an interface connector, custom data within a raw event to determine a location to store the custom data, the custom data in a first data format; storing, by the interface connector, extended data within the raw event in a common event data format, the extended data indicating the location of the custom data; receiving, by an event analyzer, the event; and determining whether there are custom customer rules that need the custom data; and if there are such custom customer rules, retrieving the custom data based on the extended data from the event, including; determining if the custom data is stored in the extended data; and if the custom data is stored within the extended data, extracting the custom data from the extended data within the event; and applying the custom customer rules to the extended data; if there are no such custom customer rules, applying the base rules to a base portion of the event. - View Dependent Claims (12, 13, 14, 15)
-
Specification