The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 20, 2015

Filed:

Sep. 04, 2009
Applicants:

Wei Huang, Fremont, CA (US);

Yizheng Zhou, Cupertino, CA (US);

Bin Yu, San Ramon, CA (US);

Wenting Tang, Sunnyvale, CA (US);

Christian F. Beedgen, Cupertino, CA (US);

Inventors:

Wei Huang, Fremont, CA (US);

Yizheng Zhou, Cupertino, CA (US);

Bin Yu, San Ramon, CA (US);

Wenting Tang, Sunnyvale, CA (US);

Christian F. Beedgen, Cupertino, CA (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 7/00 (2006.01); G06F 17/00 (2006.01); H04L 29/06 (2006.01); G06F 21/55 (2013.01); G06F 11/34 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1408 (2013.01); G06F 21/552 (2013.01); G06F 11/3476 (2013.01); G06F 2201/86 (2013.01);
Abstract

A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a column-based data 'chunk.' The manager receives and stores chunks. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. Each buffer is associated with a particular event field and includes values from that field from one or more events. The metadata includes, for each 'field of interest,' a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk is generated for each buffer and includes the metadata structure and a compressed version of the buffer contents. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.


Find Patent Forward Citations

Loading…