The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 12, 2015

Filed:

Dec. 28, 2007
Applicants:

Wei Huang, Fremont, CA (US);

Wenting Tang, Sunnyvale, CA (US);

Christian F. Beedgen, Cupertino, CA (US);

Inventors:

Wei Huang, Fremont, CA (US);

Wenting Tang, Sunnyvale, CA (US);

Christian F. Beedgen, Cupertino, CA (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 7/00 (2006.01); G06F 17/00 (2006.01); H04L 12/24 (2006.01); G06F 11/34 (2006.01); G06F 17/30 (2006.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
H04L 41/0686 (2013.01); G06F 11/3476 (2013.01); G06F 17/30312 (2013.01); G06F 21/552 (2013.01); H04L 41/069 (2013.01); G06F 2201/835 (2013.01); G06F 2201/86 (2013.01); Y10S 707/99953 (2013.01);
Abstract

A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a data 'chunk.' The manager receives data chunks and stores them so that they can be queried. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. The metadata includes a unique identifier associated with the receiver, the number of events in the buffers, and, for each 'field of interest,' a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk includes the metadata structure and a compressed version of the contents of the buffers. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.


Find Patent Forward Citations

Loading…