SYSTEMS AND METHODS FOR DISTRIBUTED RULE-BASED CORRELATION OF EVENTS
First Claim
Patent Images
1. A method for distributed correlation of events, the method comprising:
- receiving, at a computing device, a notification of a partial match of a distributed rule by an event of a first subset of events, wherein the notification comprises a set of properties of the event of the first subset of events;
evaluating the distributed rule using the set of properties of the event of the first subset of events and a set of properties of an event of a second subset of events;
determining a complete match of the rule based on the evaluation; and
generating a correlation event.
8 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods for distributed rule-based correlation of events are provided. A notification of a partial match of a distributed rule by an event of a first subset of events is received. The notification includes a set of properties of the event of the first subset of events. The distributed rule is evaluated using the set of properties of the event of the first subset of events and a set of properties of an event of a second subset of events. A complete match of the rule is determined based on the evaluation, and a correlation event is generated.
149 Citations
15 Claims
-
1. A method for distributed correlation of events, the method comprising:
-
receiving, at a computing device, a notification of a partial match of a distributed rule by an event of a first subset of events, wherein the notification comprises a set of properties of the event of the first subset of events; evaluating the distributed rule using the set of properties of the event of the first subset of events and a set of properties of an event of a second subset of events; determining a complete match of the rule based on the evaluation; and generating a correlation event. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A system for distributed correlation of events, the system comprising:
-
a first processor of a first computer system and configured to; receive events of a first subset of events; and generate a notification of a partial match of a distributed rule by an event of the first subset of events, wherein the notification comprises a set of properties of the event of the first subset of events; and a second processor of a second computer system and configured to; receive events of a second subset of events; receive the notification; evaluate the distributed rule using the set of properties of the event of the first subset of events and a set of properties of an event of the second subset of events; determine a complete match of the rule based on the evaluation; and generate a correlation event. - View Dependent Claims (10, 11, 12)
-
-
13. A non-transitory computer-readable medium storing a plurality of instructions to control a data processor to correlate events, the plurality of instructions comprising instructions that cause the data processor to:
-
receive a notification of a partial match of a distributed rule by an event of a first subset of events, wherein the notification comprises a set of properties of the event of the first subset of events; evaluate the distributed rule using the set of properties of the event of the first subset of events and a set of properties of an event of a second subset of events; determine a complete match of the rule based on the evaluation; and generate a correlation event. - View Dependent Claims (14, 15)
-
Specification