IP Library Granted Patent US 8,234,256
Granted Patent B2
US 8,234,256 · App. 10/992,230 · Granted Jul 31, 2012

System and method for parsing, summarizing and reporting log data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,234,256
App. No.
10/992,230
Granted
Jul 31, 2012
Kind
B2
Abstract

A system and method is disclosed which enables network administrators and the like to quickly analyze the data produced by log-producing devices such as network firewalls and routers. Unlike systems of the prior art, the system disclosed herein automatically parses and summarizes log data before inserting it into one or more databases. This greatly reduces the volume of data stored in the database and permits database queries to be run and reports generated while many types of attempted breaches of network security are still in progress. Database maintenance may also be accomplished automatically by the system to delete or archive old log data.

Claims (64)

1. A method performed by a data processing system, comprising:

receiving raw log data from one or more log producing devices;

generating database statements from data fields extracted from the raw log data;

creating a first database table for storing the database statements, including designating a lifetime of the first database table such that when the lifetime of the first database table expires, a replacement first database table is created;

at an interval that corresponds to the lifetime, summarizing the database statements stored in the first database table into a data chunk that includes summary database statements, including:

identifying database statements stored in the first database table that share at least one common data field; and

combining the identified database statements into the summary database statements; and

storing, on a storage device, the summarized database statements as log files of the one or more log producing devices.

2. The method of claim 1 , comprising:

determining a data source of the raw log data; and

comparing the data source with a list of acceptable data sources before generating the one or more database statements.

3. The method of claim 1 , wherein generating the one or more database statements comprises:

searching the raw log data for a predetermined keyword to identify a message type; and

extracting the data field from the raw log data according to the message type.

4. The method of claim 1 , wherein the at least one common data field includes a data field of a source Internet protocol (IP) address, a destination IP address or a destination port number.

5. The method of claim 1 , wherein the summarized database statements as log files comprises:

storing the data chunk in a second database table that is associated with a first time period; and

periodically aggregating data chunks in the second database table to a third database table that is associated with a second time period that is longer than the first time period, including generating data that have coarser granularity than data in the data chunk.

6. The method of claim 5 , wherein:

the first database table includes a database table stored in memory, and

each of the second and third database tables includes at least one of an accept table or a deny table stored on disk.

7. Computer instructions stored on a non-transitory medium, the computer instructions configured to cause a data processing system to perform operations comprising:

receiving raw log data from one or more log producing devices;

generating database statements from data fields extracted from the raw log data;

creating a first database table for storing the database statements, including designating a lifetime of the first database table such that when the lifetime of the first database table expires, a replacement first database table is created;

at an interval that corresponds to the lifetime, summarizing the database statements stored in the first database table into a data chunk that includes summary database statements, including:

identifying database statements stored in the first database table that share at least one common data field; and

combining the identified database statements into the summary database statements; and

storing, on a storage device, the summarized database statements as log files of the one or more log producing devices.

8. The computer instructions of claim 7 , the operations comprising:

determining a data source of the raw log data; and

comparing the data source with a list of acceptable data sources before generating the one or more database statements.

9. The computer instructions of claim 7 , wherein generating the one or more database statements comprises:

searching the raw log data for a predetermined keyword to identify a message type; and

extracting the data field from the raw log data according to the message type.

10. The computer instructions of claim 7 , wherein the at least one common data field includes a data field of a source Internet protocol (IP) address, a destination IP address or a destination port number.

11. The computer instructions of claim 7 , wherein the summarized database statements as log files comprises:

storing the data chunk in a second database table that is associated with a first time period; and

periodically aggregating data chunks in the second database table to a third database table that is associated with a second time period that is longer than the first time period, including generating data that have coarser granularity than data in the data chunk.

12. The computer instructions of claim 11 , wherein:

the first database table includes a database table stored in memory, and

each of the second and third database tables includes at least one of an accept table or a deny table stored on disk.

13. A system, comprising:

one or more security servers connected to one or more log producing devices through a local area network, the one or more security servers configured to perform operations comprising:

receiving raw log data from the one or more log producing devices;

generating database statements from data fields extracted from the raw log data;

creating a first database table for storing the database statements, including designating a lifetime of the first database table such that when the lifetime of the first database table expires, a replacement first database table is created;

at an interval that corresponds to the lifetime, summarizing the database statements stored in the first database table into a data chunk that includes summary database statements, including:

identifying database statements stored in the first database table that share at least one common data field; and

combining the identified database statements into the summary database statements; and

storing, on a storage device, the summarized database statements as log files of the one or more log producing devices.

14. The system of claim 13 , the operations comprising:

determining a data source of the raw log data; and

comparing the data source with a list of acceptable data sources before generating the one or more database statements.

15. The system of claim 13 , wherein generating the one or more database statements comprises:

searching the raw log data for a predetermined keyword to identify a message type; and

extracting the data field from the raw log data according to the message type.

16. The system of claim 13 , wherein the at least one common data field includes a data field of a source Internet protocol (IP) address, a destination IP address or a destination port number.

17. The system of claim 13 , wherein the summarized database statements as log files comprises:

storing the data chunk in a second database table that is associated with a first time period; and

periodically aggregating data chunks in the second database table to a third database table that is associated with a second time period that is longer than the first time period, including generating data that have coarser granularity than data in the data chunk.

18. The system of claim 17 , wherein:

the first database table includes a database table stored in memory, and

each of the second and third database tables includes at least one of an accept table or a deny table stored on disk.

Assignments (15)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
CHANGE OF NAME Recorded Feb 7, 2023
From: TIBCO SOFTWARE INC.
To: CLOUD SOFTWARE GROUP, INC.
Reel/Frame 062714/0634 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
RELEASE REEL 052115 / FRAME 0318 Recorded Oct 3, 2022
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: TIBCO SOFTWARE INC.
Reel/Frame 061588/0511 →
RELEASE (REEL 034536 / FRAME 0438) Recorded Sep 30, 2022
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 061574/0963 →
RELEASE (REEL 054275 / FRAME 0975) Recorded May 7, 2021
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 056176/0398 →
SECURITY AGREEMENT Recorded Nov 2, 2020
From: TIBCO SOFTWARE INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 054275/0975 →
SECURITY AGREEMENT Recorded Mar 6, 2020
From: TIBCO SOFTWARE INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 052115/0318 →
SECURITY INTEREST Recorded Dec 5, 2014
From: TIBCO SOFTWARE INC.; TIBCO KABIRA LLC; NETRICS.COM LLC
To: JPMORGAN CHASE BANK., N.A., AS COLLATERAL AGENT
Reel/Frame 034536/0438 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2013
From: LOGLOGIC, INC.
To: TIBCO SOFTWARE INC.
Reel/Frame 030560/0473 →