发明名称 Systems and methods for automated log event normalization using three-staged regular expressions
摘要 Methods and systems for normalizing log messages. Some methods include obtaining a freeform log message from one of many disparate programs. The methods can include determining which program originated the message and, based on that, determining a signature which matches the message. Using the signature, a parsing expression may be determined with which to extract information from a portion of the message. The time from obtaining the message to extracting the information can be about the same for all messages and can be about 1/40,000th of a second. In some embodiments, a generic signature of the message may be output. A version of the message may be reconstructed based on the generic signature and information. When more than one message signatures matches the reconstructed message, one of the matching signatures can be adjusted. The parsing expression can be the first of an ordered list of expressions which successfully evaluates the log message.
申请公布号 US8079081(B1) 申请公布日期 2011.12.13
申请号 US20080163733 申请日期 2008.06.27
申请人 LAVRIK ANTON;TRAKHTMAN PAVEL;FISHER PAUL;GOLOVINSKY EUGENE;ALERT LOGIC, INC. 发明人 LAVRIK ANTON;TRAKHTMAN PAVEL;FISHER PAUL;GOLOVINSKY EUGENE
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址