System and method for parsing, summarizing and reporting log data
First Claim
1. A data processing system comprising:
- a local area network;
a log-producing device connected to the local area network; and
, a log data analyzer connected to the local area network which receives raw log data from the log-producing device over the local area network, parses the raw log data, summarizes the parsed log data, inserts the summarized log data into a database, and generates reports from the summarized log data in response to database queries.
15 Assignments
0 Petitions
Accused Products
Abstract
A system and method is disclosed which enables network administrators and the like to quickly analyze the data produced by log-producing devices such as network firewalls and routers. Unlike systems of the prior art, the system disclosed herein automatically parses and summarizes log data before inserting it into one or more databases. This greatly reduces the volume of data stored in the database and permits database queries to be run and reports generated while many types of attempted breaches of network security are still in progress. Database maintenance may also be accomplished automatically by the system to delete or archive old log data.
127 Citations
40 Claims
-
1. A data processing system comprising:
-
a local area network;
a log-producing device connected to the local area network; and
,a log data analyzer connected to the local area network which receives raw log data from the log-producing device over the local area network, parses the raw log data, summarizes the parsed log data, inserts the summarized log data into a database, and generates reports from the summarized log data in response to database queries. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A method of processing log data from a log-producing device connected to a local area network comprising:
-
receiving raw log data from the log-producing device over the local area network;
parsing the raw log data;
summarizing the parsed log data;
inserting the summarized log data into a database; and
,generating reports from the summarized log data in response to database queries. - View Dependent Claims (15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26)
-
-
27. An apparatus for processing log data from a log-producing device connected to a local area network comprising:
-
a processor; and
,a medium storing instructions for causing the processor to receive raw log data from the log-producing device over the local area network;
parse the raw log data;
summarize the parsed log data;
insert the summarized log data into a database; and
,generate reports from the summarized log data in response to database queries. - View Dependent Claims (28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40)
-
Specification