×

Streaming and sampling in real-time log analysis

  • US 8,850,263 B1
  • Filed: 09/14/2012
  • Issued: 09/30/2014
  • Est. Priority Date: 09/14/2012
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method of providing real-time log analysis comprising:

  • hashing, by one or more monitored hosts, a value in log messages comprising log files on the one or more monitored hosts;

    tagging, by the one or more monitored hosts, each of the log messages with the hashed value;

    extracting, by the one or more monitored hosts, representative samples of log data from the log files, each of the representative samples of log data comprising at least a portion of a log message extracted from the log files based on the tagged hashed value;

    streaming, by the one or more monitored hosts, the representative samples of log data to a plurality of log processors;

    processing, by the plurality of log processors, the representative samples of log data;

    determining, by the plurality of log processors, a data completeness of the representative samples of log data processed, the data completeness comprising an indication of a proportion of total log data represented by the representative samples of log data;

    merging and collating, by a data accumulation computer, the representative samples of log data;

    generating, by the data accumulation computer, an estimated metric value from the merged and collated representative samples of log data based on the data completeness; and

    publishing, by the data accumulation computer, the estimated metric value to consumers.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×