发明名称 STORING LOG DATA EFFICIENTLY WHILE SUPPORTING QUERYING
摘要 A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a column-based data "chunk." The manager receives and stores chunks. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. Each buffer is associated with a particular event field and includes values from that field from one or more events. The metadata includes, for each "field of interest," a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk is generated for each buffer and includes the metadata structure and a compressed version of the buffer contents. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.
申请公布号 US2010011031(A1) 申请公布日期 2010.01.14
申请号 US20090554541 申请日期 2009.09.04
申请人 ARCSIGHT, INC. 发明人 HUANG WEI;ZHOU YIZHENG;YU BIN;TANG WENTING;BEEDGEN CHRISTIAN F.
分类号 G06F17/30;G06F9/44 主分类号 G06F17/30
代理机构 代理人
主权项
地址