IP Library Granted Patent US 9,098,804
Granted Patent B1
US 9,098,804 · App. 13/727,855 · Granted Aug 4, 2015

Using data aggregation to manage a memory for an event-based analysis engine

Inventors: Aharon Blitzer (Shoham, IL); Aviram Katz (Kiryat Onno, IL); Amit Lieberman (Raanana, IL); Amihai Hadar (Herzelia, IL); Senya Touretski (Ramat Gan, IL); Meytal Ashkenazy (Netanya, IL); Radai Rosenblatt (Petah Tikva, IL)
Assignee: EMC International Company
G06N5/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,098,804
App. No.
13/727,855
Granted
Aug 4, 2015
Kind
B1
Abstract

In one aspect, a method includes receiving an original rule configured to be used by an event based analysis engine. The original rule requires data to be collected over a period of time. The method also includes determining if the period of time is greater than a time period threshold; determining if the original rule includes an aggregate function; generating an aggregation rule that aggregates the data to be collected by the original rule if the original rule includes an aggregate function and if the period of time is greater than the time period threshold and aggregating data according to the aggregation rule.

Claims (36)

1. A method comprising:

receiving an original rule configured to be used by an event based analysis engine, the original rule requiring data to be collected over a period of time;

determining if the period of time is greater than a time period threshold;

determining if the original rule includes an aggregate function;

generating an aggregation rule that aggregates the data to be collected by the original rule if the original rule includes an aggregate function and if the period of time is greater than the time period threshold;

aggregating data according to the aggregation rule; and

determining if a size of data to be collected over the period of time is greater than a size threshold comprises evaluating metadata of events associated with the original rule,

wherein generating the aggregation rule comprises generating an aggregation rule that aggregates the data to be collected by the original rule if the original rule includes an aggregate function, if the period of time is greater than the time period threshold and if the size of the data to be collected over the period of time is greater than a size threshold.

2. The method of claim 1 wherein aggregating the data according to the aggregation rule comprises aggregating data previously collected.

3. The method of claim 2 wherein aggregating the data previously collected according to the aggregation rule comprises aggregating data previously collected if the aggregation rule is activated.

4. The method of claim 1 wherein aggregating the data according to the aggregation rule comprises aggregating data based on an aggregation level.

5. An apparatus, comprising:

electronic hardware circuitry configured to:

receive an original rule configured to be used by an event based analysis engine, the original rule requiring data to be collected over a period of time;

determine if the period of time is greater than a time period threshold;

determine if the original rule includes an aggregate function;

generate an aggregation rule that aggregates the data to be collected by the original rule if the original rule includes an aggregate function and if the period of time is greater than the time period threshold;

aggregate data according to the aggregation rule; and

determine if a size of data to be collected over the period of time is greater than a size threshold comprises evaluating metadata of events associated with the original rule,

wherein the circuitry configured to generate the aggregation rule comprises circuitry configured to generate an aggregation rule that aggregates the data to be collected by the original rule if the original rule includes an aggregate function, if the period of time is greater than the time period threshold and if the size of the data to be collected over the period of time is greater than a size threshold.

6. The apparatus of claim 5 wherein the circuitry comprises at least one of a processor, a memory, a programmable logic device and a logic gate.

7. The apparatus of claim 5 wherein the circuitry configured to aggregate the data according to the aggregation rule comprises circuitry configured to aggregate data previously collected.

8. The apparatus of claim 7 wherein the circuitry configured to aggregate the data previously collected according to the aggregation rule comprises circuitry configured to aggregate data previously collected if the aggregation rule is activated.

9. The apparatus of claim 5 wherein the circuitry configured to aggregate the data according to the aggregation rule comprises circuitry configured to aggregate data based on an aggregation level.

10. An article comprising:

a non-transitory computer-readable medium that stores computer-executable instructions, the instructions causing a machine to:

receive an original rule configured to be used by an event based analysis engine, the original rule requiring data to be collected over a period of time;

determine if the period of time is greater than a time period threshold;

determine if the original rule includes an aggregate function;

generate an aggregation rule that aggregates the data to be collected by the original rule if the original rule includes an aggregate function and if the period of time is greater than the time period threshold;

aggregate data according to the aggregation rule; and

determine if a size of data to be collected over the period of time is greater than a size threshold comprises evaluating metadata of events associated with the original rule,

wherein the instructions causing the machine to generate the aggregation rule comprises instructions causing the machine to generate an aggregation rule that aggregates the data to be collected by the original rule if the original rule includes an aggregate function, if the period of time is greater than the time period threshold and if the size of the data to be collected over the period of time is greater than a size threshold.

11. The article of claim 10 wherein the instructions causing a machine to aggregate the data according to the aggregation rule comprises instructions causing a machine to aggregate data previously collected.

12. The article of claim 11 wherein the instructions causing a machine to aggregate the data previously collected according to the aggregation rule comprises instructions causing a machine to aggregate data previously collected if the aggregation rule is activated.

13. The article of claim 10 wherein the instructions causing a machine to aggregate the data according to the aggregation rule comprises instructions causing a machine to aggregate data based on an aggregation level.

Assignments (5)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2015
From: BLITZER, AHARON; LIEBERMAN, AMIT; HADAR, AMIHAI; TOURETSKI, SENYA; ASHKENAZY, MEYTAL; ROSENBLATT, RADAI
To: EMC INTERNATIONAL COMPANY
Reel/Frame 035325/0988 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2013
From: KATZ, AVIRAM
To: EMC INTERNATIONAL COMPANY
Reel/Frame 030149/0067 →