×

Method, apparatus and computer program for analysing events in a computer system

  • US 9,727,393 B2
  • Filed: 11/14/2014
  • Issued: 08/08/2017
  • Est. Priority Date: 05/16/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method for analysing events in a computer system, the method comprising:

  • receiving an event;

    splitting the event into a meta part and a content part, the meta part comprising non-content of the event including at least one of;

    non-letter/number character, colon (;

    ), semicolon (;

    ), space ( ) comma (,), tab ( ), and a cryptographic hash;

    comparing the meta part by matching the meta part with meta parts from previous events for determining that the meta part is new, and wherein when the meta part is determined new;

    storing the meta part and the content part;

    whereinwhen the meta part is determined not new, comparing the content part by matching with previous content parts with the same meta part for determining that the content part is new,comparing the content part with other content parts with the same meta part as said content part,determining existence of at least one parameter of said content part being different from a number of corresponding parameters of said other content parts, and when a difference is determined for the at least one parameter determine a parameter variation between content parts which are otherwise the same,labelling the at least one parameter of said content part as a dynamic parameter,determining that said content part is new when said content part has at least one new parameter different from said at least one dynamic parameter, andwhen the content part is determined new, storing the content part, thereby enabling analysing events in a computer system and presenting events as new.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×