发明申请
- 专利标题: STORING LOG DATA EFFICIENTLY WHILE SUPPORTING QUERYING
- 专利标题(中): 在支持查询时有效地存储日志数据
-
申请号: US12554541申请日: 2009-09-04
-
公开(公告)号: US20100011031A1公开(公告)日: 2010-01-14
- 发明人: Wei Huang , Yizheng Zhou , Bin Yu , Wenting Tang , Christian F. Beedgen
- 申请人: Wei Huang , Yizheng Zhou , Bin Yu , Wenting Tang , Christian F. Beedgen
- 申请人地址: US CA Cupertino
- 专利权人: ARCSIGHT, INC.
- 当前专利权人: ARCSIGHT, INC.
- 当前专利权人地址: US CA Cupertino
- 主分类号: G06F17/30
- IPC分类号: G06F17/30 ; G06F9/44
摘要:
A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a column-based data “chunk.” The manager receives and stores chunks. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. Each buffer is associated with a particular event field and includes values from that field from one or more events. The metadata includes, for each “field of interest,” a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk is generated for each buffer and includes the metadata structure and a compressed version of the buffer contents. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.
公开/授权文献
- US09166989B2 Storing log data efficiently while supporting querying 公开/授权日:2015-10-20
信息查询