REAL-TIME STREAMING GRAPH QUERIES

    公开(公告)号:US20220374434A1

    公开(公告)日:2022-11-24

    申请号:US17325097

    申请日:2021-05-19

    申请人: CrowdStrike, Inc.

    IPC分类号: G06F16/2455 G06F16/901

    摘要: An event query host can include an event processor configured to process an event stream indicating events that occurred on a computing device. The event processor can add representations of events to an event graph. If an event added to the event graph is a trigger event associated with a query, the event processor can also add an instance of the query to a query queue. The query queue can be sorted based on scheduled execution times of query instances. At a scheduled execution time of a query instance in the query queue, a query manager of the event query host can execute the query instance and attempt to find a corresponding pattern of one or more events in the event graph.

    Real-time streaming graph queries

    公开(公告)号:US11836137B2

    公开(公告)日:2023-12-05

    申请号:US17325097

    申请日:2021-05-19

    申请人: CrowdStrike, Inc.

    IPC分类号: G06F16/2455 G06F16/901

    CPC分类号: G06F16/24568 G06F16/9024

    摘要: An event query host can include an event processor configured to process an event stream indicating events that occurred on a computing device. The event processor can add representations of events to an event graph. If an event added to the event graph is a trigger event associated with a query, the event processor can also add an instance of the query to a query queue. The query queue can be sorted based on scheduled execution times of query instances. At a scheduled execution time of a query instance in the query queue, a query manager of the event query host can execute the query instance and attempt to find a corresponding pattern of one or more events in the event graph.