Invention Grant
US08079081B1 Systems and methods for automated log event normalization using three-staged regular expressions
有权
使用三阶正则表达式的自动日志事件规范化的系统和方法
- Patent Title: Systems and methods for automated log event normalization using three-staged regular expressions
- Patent Title (中): 使用三阶正则表达式的自动日志事件规范化的系统和方法
-
Application No.: US12163733Application Date: 2008-06-27
-
Publication No.: US08079081B1Publication Date: 2011-12-13
- Inventor: Anton Lavrik , Pavel Trakhtman , Paul Fisher , Eugene Golovinsky
- Applicant: Anton Lavrik , Pavel Trakhtman , Paul Fisher , Eugene Golovinsky
- Applicant Address: US TX Houston
- Assignee: Alert Logic, Inc.
- Current Assignee: Alert Logic, Inc.
- Current Assignee Address: US TX Houston
- Agency: Sprinkle IP Law Group
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Methods and systems for normalizing log messages. Some methods include obtaining a freeform log message from one of many disparate programs. The methods can include determining which program originated the message and, based on that, determining a signature which matches the message. Using the signature, a parsing expression may be determined with which to extract information from a portion of the message. The time from obtaining the message to extracting the information can be about the same for all messages and can be about 1/40,000th of a second. In some embodiments, a generic signature of the message may be output. A version of the message may be reconstructed based on the generic signature and information. When more than one message signatures matches the reconstructed message, one of the matching signatures can be adjusted. The parsing expression can be the first of an ordered list of expressions which successfully evaluates the log message.
Information query