发明名称 Storing log data efficiently while supporting querying to assist in computer network security
摘要 <p>A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a data "chunk." The manager receives data chunks and stores them so that they can be queried. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. The metadata includes a unique identifier associated with the receiver, the number of events in the buffers, and, for each "field of interest," a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk includes the metadata structure and a compressed version of the contents of the buffers. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.</p>
申请公布号 AU2007339801(A1) 申请公布日期 2008.07.10
申请号 AU20070339801 申请日期 2007.12.28
申请人 ARCSIGHT, INC. 发明人 WEI HUANG;CHRISTIAN F. BEEDGEN;WENTING TANG
分类号 G06F12/00;G06F17/30 主分类号 G06F12/00
代理机构 代理人
主权项
地址