Invention Application
- Patent Title: MERGING MULTI-LINE LOG ENTRIES
- Patent Title (中): 合并多行日志输入
-
Application No.: PCT/US2007/065886Application Date: 2007-04-03
-
Publication No.: WO2007118096A2Publication Date: 2007-10-18
- Inventor: AGUILAR-MACIAS, Hector , MANTRY, Girish
- Applicant: ARCSIGHT, INC. , AGUILAR-MACIAS, Hector , MANTRY, Girish
- Applicant Address: 5 Results Way Cupertino, CA 95014 US
- Assignee: ARCSIGHT, INC.,AGUILAR-MACIAS, Hector,MANTRY, Girish
- Current Assignee: ARCSIGHT, INC.,AGUILAR-MACIAS, Hector,MANTRY, Girish
- Current Assignee Address: 5 Results Way Cupertino, CA 95014 US
- Agency: TRUESDALE, Sabra-Anne et al.
- Priority: US11/398,863 20060405
- Main IPC: G06F11/00
- IPC: G06F11/00
Abstract:
A system and method for building merged events from log entries received from multiple devices. Multiple log events generally contribute to a single merged event. In the described embodiment, the mapping module receives log entries associated with specific merged events and maps them to fields in the merged event data structure in accordance with mapping properties. The described embodiments of the invention use regular expressions in the merge properties to describe values that are searched for in the received log entries. A described embodiment of the present invention gives the mapping module access to the event under construction. A new conditional operator, _oneOf, is introduced that selects the first token that is bound to a value out of a list of tokens.
Information query