Event and alert analysis in a distributed processing system
First Claim
1. An apparatus for event and alert analysis in a distributed processing system, the distributed processing system including a local event analyzer embedded in an alert analyzer, the apparatus comprising a computer processor and a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that when executed by the computer processor cause the apparatus to carry out the steps of:
- receiving, by the local event analyzer embedded in the alert analyzer, events from an event queue;
creating, based on the received events and local event analysis rules specific to the alert analyzer, by the local event analyzer, a temporary alert for the alert analyzer, wherein the temporary alert is an alert that is visible to one or more specific alert analyzers including the alert analyzer;
receiving, by the alert analyzer, alerts created by a plurality of event analyzers, wherein each event analyzer of the plurality of event analyzers is configured to create the alerts by processing the events from the event queue according to each event analyzer'"'"'s own event analysis rules; and
analyzing, by the alert analyzer, based on alert analysis rules, the temporary alert and the alerts created by the plurality of event analyzers.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods, apparatuses, and computer program products for event and alert analysis are provided. Embodiments include a local event analyzer embedded in an alert analyzer receiving events from an event queue. Embodiments also include the local event analyzer creating, based on the received events and local event analysis rules specific to the alert analyzer, a temporary alert for the alert analyzer. Embodiments also include the alert analyzer analyzing the temporary alert based on alert analysis rules.
240 Citations
15 Claims
-
1. An apparatus for event and alert analysis in a distributed processing system, the distributed processing system including a local event analyzer embedded in an alert analyzer, the apparatus comprising a computer processor and a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that when executed by the computer processor cause the apparatus to carry out the steps of:
-
receiving, by the local event analyzer embedded in the alert analyzer, events from an event queue; creating, based on the received events and local event analysis rules specific to the alert analyzer, by the local event analyzer, a temporary alert for the alert analyzer, wherein the temporary alert is an alert that is visible to one or more specific alert analyzers including the alert analyzer; receiving, by the alert analyzer, alerts created by a plurality of event analyzers, wherein each event analyzer of the plurality of event analyzers is configured to create the alerts by processing the events from the event queue according to each event analyzer'"'"'s own event analysis rules; and analyzing, by the alert analyzer, based on alert analysis rules, the temporary alert and the alerts created by the plurality of event analyzers. - View Dependent Claims (2, 3, 4, 5, 6, 15)
-
-
7. A computer program product for event and alert analysis in a distributed processing system, the distributed processing system including a local event analyzer embedded in an alert analyzer, the computer program product disposed upon a computer readable medium, the computer readable medium is not a signal, the computer program product comprising computer program instructions that when executed by a computer cause the computer to carry out the steps of:
-
receiving, by the local event analyzer embedded in the alert analyzer, events from an event queue; creating, based on the received events and local event analysis rules specific to the alert analyzer, by the local event analyzer, a temporary alert for the alert analyzer, wherein the temporary alert is an alert that is visible to one or more specific alert analyzers including the alert analyzer; receiving, by the alert analyzer, alerts created by a plurality of event analyzers, wherein each event analyzer of the plurality of event analyzers is configured to create the alerts by processing the events from the event queue according to each event analyzer'"'"'s own event analysis rules; and analyzing, by the alert analyzer, based on alert analysis rules, the temporary alert and the alerts created by the plurality of event analyzers. - View Dependent Claims (8, 9, 10, 11, 12, 13, 14)
-
Specification