Network event capture and retention system
First Claim
1. A data processing system comprising:
- a first local area network;
a first log-producing device connected to the first local area network;
a raw log server connected to the first local area network and in data communication with the first log-producing device over the first local area network;
a first log data analyzer connected to the first local area network and in data communication with the raw log server over the first local area network;
a second local area network in data communication with the first local area network;
a second log-producing device connected to the second local area network; and
, a second log data analyzer connected to the second local area network and in data communication with the second log-producing device over the second local area network and in data communication with the raw log server via the first and second local area networks.
23 Assignments
0 Petitions
Accused Products
Abstract
Methods and apparatus are provided to monitor and analyze activity occurring on a networked computer system. In some embodiments, a method is provided for capturing, in a data structure, at least a portion of a notification describing a network event provided by a node on a computer network, identifying a data element (e.g., an IP address of the node) within the notification, and updating an index and/or summary based on the data element. The data structure may be stored in a file system maintained on a site, and sites may exchange information related to the notification data stored on each. In some embodiments, a query which is issued to a site may be processed using data transferred from other sites, and/or may be split into one or more additional queries which may be transmitted for processing to other sites.
43 Citations
14 Claims
-
1. A data processing system comprising:
- a first local area network;
a first log-producing device connected to the first local area network;
a raw log server connected to the first local area network and in data communication with the first log-producing device over the first local area network;
a first log data analyzer connected to the first local area network and in data communication with the raw log server over the first local area network;
a second local area network in data communication with the first local area network;
a second log-producing device connected to the second local area network; and
, a second log data analyzer connected to the second local area network and in data communication with the second log-producing device over the second local area network and in data communication with the raw log server via the first and second local area networks. - View Dependent Claims (2, 3, 4, 5, 6, 7)
- a first local area network;
-
8. A method for processing log data comprising:
- generating raw log data in a first log-producing device connected to a first local area network;
storing raw log data in a raw log server connected to the first local area network and in data communication with the first log-producing device over the first local area network;
sending the raw log data generated by the first log-producing device to a first log data analyzer connected to the first local area network and in data communication with the raw log server over the first local area network;
generating log data in a second log-producing device connected to a second local area network; and
, sending the log data generated by the second log-producing device from a second log data analyzer connected to the second local area network and in data communication with the second log-producing device over the second local area network and in data communication with the raw log server via the first and second local area networks to the raw log server. - View Dependent Claims (9, 10, 11, 12, 13, 14)
- generating raw log data in a first log-producing device connected to a first local area network;
Specification