STORING LOG DATA EFFICIENTLY WHILE SUPPORTING QUERYING
    1.
    发明申请
    STORING LOG DATA EFFICIENTLY WHILE SUPPORTING QUERYING 有权
    在支持查询时有效地存储日志数据

    公开(公告)号:US20100011031A1

    公开(公告)日:2010-01-14

    申请号:US12554541

    申请日:2009-09-04

    IPC分类号: G06F17/30 G06F9/44

    摘要: A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a column-based data “chunk.” The manager receives and stores chunks. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. Each buffer is associated with a particular event field and includes values from that field from one or more events. The metadata includes, for each “field of interest,” a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk is generated for each buffer and includes the metadata structure and a compressed version of the buffer contents. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.

    摘要翻译: 记录系统包括事件接收器和存储管理器。 接收器接收日志数据,处理它,并输出基于列的数据“块”。 经理收到并存储块。 接收器包括存储事件的缓冲器和存储关于缓冲器的内容的元数据的元数据结构。 每个缓冲区与一个特定事件字段相关联,并包含一个或多个事件的该字段的值。 对于每个“感兴趣的领域”,元数据包括反映缓冲器中的所有事件的该字段的值的范围的最小值和最大值。 为每个缓冲区生成一个块,并包括元数据结构和缓冲区内容的压缩版本。 元数据结构在查询事件数据时用作搜索索引。 记录系统可以与安全信息/事件管理(SIEM)系统结合使用。

    Query pipeline
    2.
    发明授权
    Query pipeline 有权
    查询流水线

    公开(公告)号:US09009139B2

    公开(公告)日:2015-04-14

    申请号:US13699953

    申请日:2011-06-10

    IPC分类号: G06F17/30

    CPC分类号: G06F17/30563 G06F17/30442

    摘要: A query pipeline is created (514) from a query request. The query pipeline includes multiple query operations including multiple query operators. A first query operator and a second query operator perform first and second query operations on a database (526) and on data outside the database (534). A result from the first query operation in the query pipeline is fed to the second query operation in the query pipeline.

    摘要翻译: 从查询请求创建查询流水线(514)。 查询流水线包括多个查询操作,包括多个查询运算符。 第一查询运算符和第二查询运算符对数据库(526)和数据库外的数据(534)执行第一和第二查询操作。 查询流水线中的第一个查询操作的结果被馈送到查询流水线中的第二个查询操作。

    Storing log data efficiently while supporting querying
    4.
    发明授权
    Storing log data efficiently while supporting querying 有权
    有效地存储日志数据,同时支持查询

    公开(公告)号:US09166989B2

    公开(公告)日:2015-10-20

    申请号:US12554541

    申请日:2009-09-04

    摘要: A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a column-based data “chunk.” The manager receives and stores chunks. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. Each buffer is associated with a particular event field and includes values from that field from one or more events. The metadata includes, for each “field of interest,” a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk is generated for each buffer and includes the metadata structure and a compressed version of the buffer contents. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.

    摘要翻译: 记录系统包括事件接收器和存储管理器。 接收器接收日志数据,处理它,并输出基于列的数据“块”。管理器接收并存储块。 接收器包括存储事件的缓冲器和存储关于缓冲器的内容的元数据的元数据结构。 每个缓冲区与一个特定事件字段相关联,并包含一个或多个事件的该字段的值。 对于每个“感兴趣的领域”,元数据包括反映缓冲器中所有事件的该字段的值的范围的最小值和最大值。 为每个缓冲区生成一个块,并包括元数据结构和缓冲区内容的压缩版本。 元数据结构在查询事件数据时用作搜索索引。 记录系统可以与安全信息/事件管理(SIEM)系统结合使用。

    QUERY PIPELINE
    5.
    发明申请

    公开(公告)号:US20130073573A1

    公开(公告)日:2013-03-21

    申请号:US13699953

    申请日:2011-06-10

    IPC分类号: G06F17/30

    CPC分类号: G06F17/30563 G06F17/30442

    摘要: A query pipeline is created (514) from a query request. The query pipeline includes multiple query operations including multiple query operators. A first query operator and a second query operator perform first and second query operations on a database (526) and on data outside the database (534). A result from the first query operation in the query pipeline is fed to the second query operation in the query pipeline.

    摘要翻译: 从查询请求创建查询流水线(514)。 查询流水线包括多个查询操作,包括多个查询运算符。 第一查询运算符和第二查询运算符对数据库(526)和数据库外的数据(534)执行第一和第二查询操作。 查询流水线中的第一个查询操作的结果被馈送到查询流水线中的第二个查询操作。

    MULTIDIMENSION CLUSTERS FOR DATA PARTITIONING
    7.
    发明申请
    MULTIDIMENSION CLUSTERS FOR DATA PARTITIONING 审中-公开
    用于数据分区的多维集群

    公开(公告)号:US20140280075A1

    公开(公告)日:2014-09-18

    申请号:US14237192

    申请日:2012-08-24

    IPC分类号: G06F17/30

    摘要: A data storage system includes a partitioning module to partition data across multiple dimensions simultaneously. The partitioning may be based on a sizing parameter for each dimension. The partitioning module stores a cluster including the partitioned event data and metadata including attributes identifying the cluster.

    摘要翻译: 数据存储系统包括分区模块,用于同时跨多个维度划分数据。 分区可以基于每个维度的大小参数。 分区模块存储包括分区事件数据和元数据的集群,其中包括标识集群的属性。

    Distributed resource management in a portable computing device
    8.
    发明授权
    Distributed resource management in a portable computing device 有权
    便携式计算设备中的分布式资源管理

    公开(公告)号:US08631414B2

    公开(公告)日:2014-01-14

    申请号:US13225152

    申请日:2011-09-02

    IPC分类号: G06F9/46 G06F15/173

    摘要: In a portable computing device having a node-based resource architecture, a first or distributed node controlled by a first processor but corresponding to a second or native node controlled by a second processor is used to indirectly access a resource of the second node. In a resource graph defining the architecture each node represents an encapsulation of functionality of one or more resources, each edge represents a client request, and adjacent nodes represent resource dependencies. Resources defined by a first graph are controlled by the first processor but not the second processor, while resources defined by a second graph are controlled by the second processor but not the first processor. A client request on the first node may be received from a client under control of the first processor. Then, a client request may be issued on the second node in response to the client request on the first node.

    摘要翻译: 在具有基于节点的资源架构的便携式计算设备中,使用由第一处理器控制但对应于由第二处理器控制的第二或本地节点的第一或分布式节点来间接访问第二节点的资源。 在定义架构的资源图中,每个节点表示一个或多个资源的功能的封装,每个边缘表示客户端请求,相邻节点表示资源依赖关系。 由第一图形定义的资源由第一处理器控制,但不由第二处理器控制,而由第二图形所定义的资源由第二处理器控制,而不由第一处理器控制。 可以在第一处理器的控制下从客户端接收在第一节点上的客户端请求。 然后,响应于在第一节点上的客户端请求,可以在第二节点上发出客户端请求。

    DISTRIBUTED RESOURCE MANAGEMENT IN A PORTABLE COMPUTING DEVICE
    9.
    发明申请
    DISTRIBUTED RESOURCE MANAGEMENT IN A PORTABLE COMPUTING DEVICE 有权
    便携式计算设备中的分布式资源管理

    公开(公告)号:US20120227053A1

    公开(公告)日:2012-09-06

    申请号:US13225152

    申请日:2011-09-02

    IPC分类号: G06F9/50

    摘要: In a portable computing device having a node-based resource architecture, a first or distributed node controlled by a first processor but corresponding to a second or native node controlled by a second processor is used to indirectly access a resource of the second node. In a resource graph defining the architecture each node represents an encapsulation of functionality of one or more resources, each edge represents a client request, and adjacent nodes represent resource dependencies. Resources defined by a first graph are controlled by the first processor but not the second processor, while resources defined by a second graph are controlled by the second processor but not the first processor. A client request on the first node may be received from a client under control of the first processor. Then, a client request may be issued on the second node in response to the client request on the first node.

    摘要翻译: 在具有基于节点的资源架构的便携式计算设备中,使用由第一处理器控制但对应于由第二处理器控制的第二或本地节点的第一或分布式节点来间接访问第二节点的资源。 在定义架构的资源图中,每个节点表示一个或多个资源的功能的封装,每个边缘表示客户端请求,相邻节点表示资源依赖关系。 由第一图形定义的资源由第一处理器控制,但不由第二处理器控制,而由第二图形所定义的资源由第二处理器控制,而不由第一处理器控制。 可以在第一处理器的控制下从客户端接收在第一节点上的客户端请求。 然后,响应于在第一节点上的客户端请求,可以在第二节点上发出客户端请求。