发明名称 SYSLOG PARSER
摘要 A computerized method performed in a computer operatively connected to storage. Parsing rules are determined for parsing logs output as text and/or symbols from multiple devices in a computer network. The logs are stored in the storage. Multiple log samples are sampled from the logs. The log samples are input into an application running on the computer. The log samples are each sectioned into multiple sections which include variable information separated by static structural text. Each of the log samples is processed by: comparing the sections to a list of regular expressions. The list is maintained in the storage, and upon matching a matched section of the sections to a matched regular expression from the list of the regular expressions, the matched section is tagged with a tag associated with the matched regular expression. The tag associated to the matched regular expression is stored and combined with any unmatched sections and with the static structural text to create a log pattern. The log pattern is stored in a table only if the log pattern is distinct from all log patterns previously stored in the table.
申请公布号 US2009119307(A1) 申请公布日期 2009.05.07
申请号 US20070875955 申请日期 2007.10.22
申请人 CHECK POINT SOFTWARE TECHNOLOGIES LTD. 发明人 BRAUN URI;ZASLAVSKY YURI;TEITZ YOSEF
分类号 G06F17/30 主分类号 G06F17/30
代理机构 代理人
主权项
地址