IP Library › Granted Patent US 9,940,373
Granted Patent B2
US 9,940,373 · App. 15/689,232 · Granted Apr 10, 2018

Method and system for implementing an operating system hook in a log analytics system

Inventors: Jerry Paul Russell (Seattle, WA); Haobo He (Shenzhen, CN); Greg Ma (Shanghai, CN); Xin Xu (Westford, MA)
Assignee: Oracle International Corporation
G06F17/30554G06F3/04842G06F9/44505G06F9/542G06F11/00G06F17/30073G06F17/30091G06F17/30321G06F17/30368G06F17/30477G06F17/30707G06F17/30914G06N99/005H04L41/5074H04L41/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,940,373
App. No.
15/689,232
Granted
Apr 10, 2018
Kind
B2
Abstract

Disclosed is a system, method, and computer program product for implementing a log analytics method and system that can configure, collect, and analyze log records in an efficient manner. An improved approach is provided for identifying log files that have undergone a change in status that would require retrieve of its log data, by including a module directly into the operating system that allows the log collection component to be reactively notified of any changes to pertinent log files.

Claims (39)

1. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, cause performance of operations comprising:

identifying a target subset of OS calls from a plurality of OS calls;

intercepting a plurality of invocations of one or more OS calls in the target subset of OS calls;

identifying a plurality of log file changes corresponding respectively to the plurality of invocations;

identifying a plurality of events corresponding to the plurality log file changes;

filtering the plurality of events, based on one or more event filtering criteria, to obtain a subset of events corresponding to a subset from the plurality of log file changes; and

writing the subset of events to an event list.

2. The medium of claim 1 , the operations further comprising:

refraining from intercepting invocations of one or more other OS calls, from the plurality of OS calls, that are not in the target subset from the plurality of OS calls.

3. The medium of claim 1 , wherein intercepting the plurality of invocations of the one or more OS calls is performed by a module loaded in the OS.

4. The medium of claim 3 , wherein filtering the plurality of events corresponding to the plurality of log file changes is performed by the module loaded in the OS.

5. The medium of claim 3 , wherein writing the subset of events to the event list is performed by the module loaded in the OS.

6. The medium of claim 1 , the operations further comprising:

for each particular invocation in the plurality of invocations, forwarding the particular invocation to the OS for execution after intercepting the particular invocation.

7. The medium of claim 1 , wherein intercepting the plurality of invocations comprises replacing one or more memory addresses associated with the one or more OS calls.

8. The medium of claim 1 , the operations further comprising:

monitoring, by a log analytics agent, the event list for changes.

9. The medium of claim 1 , wherein the one or more event filtering criteria comprise one or more file location criteria.

10. The medium of claim 1 , the operations further comprising:

determining whether a particular invocation in the plurality of invocations was successful, wherein writing an event to the event list, for the particular invocation, is performed only if the particular invocation was successful.

11. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, cause performance of operations comprising:

identifying a target subset of OS calls from a plurality of OS calls;

intercepting a plurality of invocations of one or more OS calls in the target subset of OS calls;

identifying a plurality of log file changes corresponding respectively to the plurality of invocations;

writing, to an event list, a plurality of events corresponding to the plurality of log file changes; and

filtering the event list, based on one or more event filtering criteria, to obtain a filtered event list comprising events corresponding to a subset of the plurality of log file changes.

12. The medium of claim 11 , the operations further comprising:

refraining from intercepting invocations of one or more other OS calls, from the plurality of OS calls, that are not in the target subset of the plurality of OS calls.

13. The medium of claim 11 , wherein intercepting the plurality of invocations of the one or more OS calls is performed by a module loaded in the OS.

14. The medium of claim 13 , wherein filtering the event list is performed by the module loaded in the OS.

15. The medium of claim 13 , wherein writing the plurality of events to the event list is performed by the module loaded in the OS.

16. The medium of claim 11 , the operations further comprising:

for each particular invocation in the plurality of invocations, forwarding the particular invocation to the OS for execution after intercepting the particular invocation.

17. The medium of claim 11 , wherein intercepting the plurality of invocations comprises replacing one or more memory addresses associated with the one or more OS calls.

18. The medium of claim 11 , the operations further comprising:

monitoring, by a log analytics agent, the filtered event list for changes.

19. The medium of claim 11 , wherein the one or more event filtering criteria comprise one or more file location criteria.

20. The medium of claim 11 , the operations further comprising:

determining whether a particular invocation in the plurality of invocations was successful, wherein writing an event to the event list, for the particular invocation, is performed only if the particular invocation was successful.

Continuity (3)
Continuation 15089049 · Apr 1, 2016
Provisional Application 62142987 · Apr 3, 2015
Related Publication 20180004824A1 · Jan 4, 2018