IP Library Granted Patent US 7,437,359
Granted Patent B2
US 7,437,359 · App. 11/398,863 · Granted Oct 14, 2008

Merging multiple log entries in accordance with merge properties and mapping properties

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,437,359
App. No.
11/398,863
Granted
Oct 14, 2008
Kind
B2
Abstract

A system and method for building merged events from log entries received from multiple devices. Multiple log events generally contribute to a single merged event. In the described embodiment, the mapping module receives log entries associated with specific merged events and maps them to fields in the merged event data structure in accordance with mapping properties. The described embodiments of the invention use regular expressions in the merge properties to describe values that are searched for in the received log entries. A described embodiment of the present invention gives the mapping module access to the event under construction. A new conditional operator, _oneOf, is introduced that selects the first token that is bound to a value out of a list of tokens.

Claims (38)

1. A method for merging multiple log entries received by a data processing system, comprising:

receiving a plurality of log entries;

for each received log entry:

determining if the log entry contains an ID common to any potential merged event in accordance with merge properties;

beginning a new merged event, if the log entry is a beginning log entry of a merged event in accordance with the merge properties; and

ending an existing merged event, if the log entry is an ending log entry of an existing merged event in accordance with the merge properties; and

mapping each log entry containing an ID common to an existing merged event to that merged event in accordance with mapping properties for the merged event.

2. The method of claim 1 , further comprising ending an existing merged event if a timeout as defined in the merge properties for that merged event occurs.

3. The method of claim 2 , further comprising identifying a log entry indicating a beginning of the merged event.

4. The method of claim 2 , further comprising identifying a log entry indicating an end of the merged event.

5. The method of claim 2 , further comprising identifying a log entry that neither implies a start nor an end of the merged event.

6. The method of claim 2 , further comprising an ability to consider the merged event as it exists so far when merging in a new entry's token.

7. The method of claim 6 , wherein the ability is used in a mapping operation.

8. The method of claim 1 , further comprising determining whether each received log entry is to be considered for merging in accordance with the merge properties.

9. The method of claim 1 , wherein mapping a log entry to a merged event further comprises determining a time of the merged event, the time being the time of a beginning log event for the merged event.

10. The method of claim 1 , wherein mapping a log entry to a merged event further comprises determining a time of the merged event, the time being the time of an ending log event for the merged event.

11. The method of claim 1 , wherein mapping a log entry to a merged event further comprises mapping an event ID in accordance with the mapping properties.

12. The method of claim 1 , wherein mapping a log entry to a merged event further comprises mapping an event name in accordance with the mapping properties.

13. The method of claim 1 , wherein mapping a log entry to a merged event further comprises mapping a name parsed from the log entry, the mapping performed in accordance with a oneOf function in the mapping properties.

14. The method of claim 1 , wherein mapping a log entry to a merged event further comprises mapping a device action in accordance with the mapping properties.

15. The method of claim 1 , wherein the received log entries contain log entries corresponding to more than one merged event mixed together.

16. The method of claim 1 , wherein one received log entry is used to build more than one merged event.

17. The method of claim 1 , wherein an ID comprises multiple fields in the log entry, the multiple fields acting to identify log entries that contribute to a merged event.

18. A system for merging multiple log entries received by a data processing system, comprising:

a module for receiving a plurality of log entries;

a parser for parsing the log entries into tokens;

a grouper that, for each received log entry:

determines if the log entry contains an ID common to any potential merged event in accordance with merge properties;

begins a new merged event, if the log entry is a beginning log entry of a merged event in accordance with the merge properties; and

ends an existing merged event, if the log entry is an ending log entry of an existing merged event in accordance with the merge properties; and

a mapper that maps each log entry containing an ID common to an existing merged event to that merged event in accordance with mapping properties for the merged event.

19. A computer program product comprising instructions stored on a computer readable medium for causing a computer to perform a method, comprising:

receiving a plurality of log entries;

for each received log entry:

determining if the log entry contains an ID common to any potential merged event in accordance with merge properties;

beginning a new merged event, if the log entry is a beginning log entry of a merged event in accordance with the merge properties; and

ending an existing merged event, if the log entry is an ending log entry of an existing merged event in accordance with the merge properties; and

mapping each log entry containing an ID common to an existing merged event to that merged event in accordance with mapping properties for the merged event.

Assignments (11)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
CERTIFICATE OF CONVERSION Recorded Nov 16, 2012
From: ARCSIGHT, INC.
To: ARCSIGHT, LLC.
Reel/Frame 029308/0908 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: ARCSIGHT, LLC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029308/0929 →
MERGER Recorded Dec 23, 2010
From: PRIAM ACQUISITION CORPORATION
To: ARCSIGHT, INC.
Reel/Frame 025525/0172 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2006
From: AGUILAR-MACIAS, HECTOR; MANTRY, GIRISH
To: ARCSIGHT, INC.
Reel/Frame 017743/0938 →