-
公开(公告)号:US20110214020A1
公开(公告)日:2011-09-01
申请号:US12714842
申请日:2010-03-01
申请人: Ziv Caspi , Ron E. Dar Ziv , Yifat Orlin , Alexander Sloutsky , Itai Frenkel
发明人: Ziv Caspi , Ron E. Dar Ziv , Yifat Orlin , Alexander Sloutsky , Itai Frenkel
IPC分类号: G06F11/07
CPC分类号: G06F11/079 , G06F11/0709 , G06F11/0715 , H04L41/064 , H04L41/0686
摘要: Correlating activity events to identify a root cause of a process failure. Activity event data is received from a process executing on a computing device. The activity event data corresponds to a plurality of activity events. Each of the activity events has a correlation identifier, a resolution status, and an occurrence time value associated therewith. Each of the activity events are assigned to one of a plurality of event groups based on the correlation identifier of the activity event. Thereafter, at least one of the event groups is determined to have an activity event with a resolution status indicating failure of the process. One of the activity events within the determined event group is selected as a root cause activity event based on the occurrence time values. In some embodiments, the root cause activity event is identified to a user of the computing device.
摘要翻译: 关联活动事件以识别过程失败的根本原因。 从在计算设备上执行的进程接收活动事件数据。 活动事件数据对应于多个活动事件。 每个活动事件具有相关标识符,分辨率状态和与其相关联的发生时间值。 基于活动事件的相关标识符,将活动事件分配给多个事件组中的一个。 此后,确定事件组中的至少一个具有活动事件,其中解决状态指示过程失败。 基于发生时间值,将所确定的事件组中的活动事件之一选择为根本原因活动事件。 在一些实施例中,根本原因活动事件被识别给计算设备的用户。
-
公开(公告)号:US08060782B2
公开(公告)日:2011-11-15
申请号:US12714842
申请日:2010-03-01
申请人: Ziv Caspi , Ron E. Dar Ziv , Yifat Orlin , Alexander Sloutsky , Itai Frenkel
发明人: Ziv Caspi , Ron E. Dar Ziv , Yifat Orlin , Alexander Sloutsky , Itai Frenkel
IPC分类号: G06F11/00
CPC分类号: G06F11/079 , G06F11/0709 , G06F11/0715 , H04L41/064 , H04L41/0686
摘要: Correlating activity events to identify a root cause of a process failure. Activity event data is received from a process executing on a computing device. The activity event data corresponds to a plurality of activity events. Each of the activity events has a correlation identifier, a resolution status, and an occurrence time value associated therewith. Each of the activity events are assigned to one of a plurality of event groups based on the correlation identifier of the activity event. Thereafter, at least one of the event groups is determined to have an activity event with a resolution status indicating failure of the process. One of the activity events within the determined event group is selected as a root cause activity event based on the occurrence time values. In some embodiments, the root cause activity event is identified to a user of the computing device.
摘要翻译: 关联活动事件以识别过程失败的根本原因。 从在计算设备上执行的进程接收活动事件数据。 活动事件数据对应于多个活动事件。 每个活动事件具有相关标识符,分辨率状态和与其相关联的发生时间值。 基于活动事件的相关标识符,将活动事件分配给多个事件组中的一个。 此后,确定事件组中的至少一个具有活动事件,其中解决状态指示过程失败。 基于发生时间值,将所确定的事件组中的活动事件之一选择为根本原因活动事件。 在一些实施例中,根本原因活动事件被识别给计算设备的用户。
-
公开(公告)号:US08353020B2
公开(公告)日:2013-01-08
申请号:US11453778
申请日:2006-06-14
IPC分类号: H04L29/06
CPC分类号: H04L63/0227
摘要: A generic master-slave mechanism enables a single processor of a cluster of firewall processors to define the behavior of the other processors in the cluster for a specific logical connection. The cluster of firewall processors utilizes virtual adapters representing physical adapters on other processors in the firewall cluster. This virtualization allows each cluster member to act as though it is a standalone machine that owns all local IP addresses of the entire cluster. When traffic is received by a firewall processor, the firewall processor determines if there is a master associated with the logical connection for the traffic. If so, the traffic is routed to the master. If no master is associated, in an example configuration, the receiving firewall processor becomes the master. A message traffic logical connection has a single master. A master remains the master of a logical connection until the connection is terminated.
摘要翻译: 通用主从机制使得防火墙处理器群集的单个处理器可以定义集群中其他处理器的特定逻辑连接的行为。 防火墙处理器集群利用虚拟适配器代表防火墙集群中其他处理器上的物理适配器。 这种虚拟化允许每个集群成员就像是拥有整个集群的所有本地IP地址的独立机器一样。 当防火墙处理器接收到流量时,防火墙处理器确定是否存在与流量的逻辑连接相关联的主机。 如果是,则流量被路由到主服务器。 如果没有与主机相关联,则在示例配置中,接收防火墙处理器成为主设备。 消息流量逻辑连接具有单个主服务器。 在连接终止之前,主器件保持逻辑连接的主器件。
-
公开(公告)号:US07603333B2
公开(公告)日:2009-10-13
申请号:US11454042
申请日:2006-06-14
IPC分类号: G06N5/02 , G06F15/173
CPC分类号: G06N5/025
摘要: The evaluation of a policy can be delayed until all rules criteria needed for evaluation are available. Also, new types of rules criteria can be registered without requiring changes to a rules engine. A policy manager allows rules to be evaluated and decisions made at different stages of the request handling. The policy manager facilitates interaction with the rules engine until all criteria are evaluated. The policy manager also allows modules developed by third parties to provide notification when criteria can be decided and thus complete evaluation.
摘要翻译: 可以推迟对政策的评估,直到评估所需的所有规则标准可用。 此外,可以注册新类型的规则标准,而不需要更改规则引擎。 策略管理器允许对请求处理的不同阶段进行评估和决策。 策略管理器促进与规则引擎的交互,直到评估所有标准。 政策经理还允许第三方开发的模块在可以决定标准的情况下提供通知,从而完成评估。
-
公开(公告)号:US20070294754A1
公开(公告)日:2007-12-20
申请号:US11453778
申请日:2006-06-14
IPC分类号: G06F15/16
CPC分类号: H04L63/0227
摘要: A generic master-slave mechanism enables a single processor of a cluster of firewall processors to define the behavior of the other processors in the cluster for a specific logical connection. The cluster of firewall processors utilizes virtual adapters representing physical adapters on other processors in the firewall cluster. This virtualization allows each cluster member to act as though it is a standalone machine that owns all local IP addresses of the entire cluster. When traffic is received by a firewall processor, the firewall processor determines if there is a master associated with the logical connection for the traffic. If so, the traffic is routed to the master. If no master is associated, in an example configuration, the receiving firewall processor becomes the master. A message traffic logical connection has a single master. A master remains the master of a logical connection until the connection is terminated.
摘要翻译: 通用主从机制使得防火墙处理器群集的单个处理器可以定义集群中其他处理器的特定逻辑连接的行为。 防火墙处理器集群利用虚拟适配器代表防火墙集群中其他处理器上的物理适配器。 这种虚拟化允许每个集群成员就像是拥有整个集群的所有本地IP地址的独立机器一样。 当防火墙处理器接收到流量时,防火墙处理器确定是否存在与流量的逻辑连接相关联的主机。 如果是,则流量被路由到主服务器。 如果没有与主机相关联,则在示例配置中,接收防火墙处理器成为主设备。 消息流量逻辑连接具有单个主服务器。 在连接终止之前,主器件保持逻辑连接的主器件。
-
公开(公告)号:US20070294198A1
公开(公告)日:2007-12-20
申请号:US11454042
申请日:2006-06-14
IPC分类号: G06N5/02
CPC分类号: G06N5/025
摘要: The evaluation of a policy can be delayed until all rules criteria needed for evaluation are available. Also, new types of rules criteria can be registered without requiring changes to a rules engine. A policy manager allows rules to be evaluated and decisions made at different stages of the request handling. The policy manager facilitates interaction with the rules engine until all criteria are evaluated. The policy manager also allows modules developed by third parties to provide notification when criteria can be decided and thus complete evaluation.
摘要翻译: 可以推迟对政策的评估,直到评估所需的所有规则标准可用。 此外,可以注册新类型的规则标准,而不需要更改规则引擎。 策略管理器允许对请求处理的不同阶段进行评估和决策。 策略管理器促进与规则引擎的交互,直到评估所有标准。 政策经理还允许第三方开发的模块在可以决定标准的情况下提供通知,从而完成评估。
-
-
-
-
-