×

Method and apparatus for alert prioritization on high value end points

  • US 8,438,268 B2
  • Filed: 04/23/2008
  • Issued: 05/07/2013
  • Est. Priority Date: 04/23/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method of prioritizing alerts on end points, comprising:

  • receiving at an aggregator agent that monitors a plurality of end point agents, a signal indicating an out of band operating tolerance from an end point asset;

    in response to receiving the signal, gathering at the aggregator agent, information associated with a local environment where the end point asset is located, at least by retrieving data available on a computer running the aggregator agent and by querying one or more other end points agents respectively associated with one or more other end point assets, wherein the aggregator agent, the end point asset and the other end point assets are co-located in the local environment;

    determining locally at the aggregator agent a priority of said signal based on a rules engine local to the aggregator agent and at least based on the gathered information;

    transmitting said priority of said signal and information associated with said signal to a remote host computer for appropriate handling;

    wherein the step of determining locally at the aggregator agent a priority further includes downgrading priority of said signal and writing to a local log information associated with the downgraded priority of said signal without immediately sending the priority of said signal to the remote host computer; and

    wherein the step of determining locally at the aggregator agent a priority of said signal further includes re-polling for data from the plurality of end point agents and reassessing said priority based on the repolled data.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×