-
公开(公告)号:WO2012031259A1
公开(公告)日:2012-03-08
申请号:PCT/US2011/050421
申请日:2011-09-02
Applicant: LOGLOGIC, INC. , HARNETT, Tim , BHAMIDIPATY, Achyutram , TEWARI, Abinas , MANLEY, Stephen , MORGAN, Stephen , NICKLIN, Peter , ROY, Jena-Francois
Inventor: HARNETT, Tim , BHAMIDIPATY, Achyutram , TEWARI, Abinas , MANLEY, Stephen , MORGAN, Stephen , NICKLIN, Peter , ROY, Jena-Francois
IPC: G06F17/30
CPC classification number: G06F17/30666 , G06F17/30557 , G06F17/30637
Abstract: Methods, program products, and systems implementing dynamic parsing rules are disclosed. Log data from a variety of log producers can be parsed using parsing rules to generate information about an information system. The parsing rules can include system parsing rules and custom parsing rules. A state machine can be used to detect conflicts between various parsing rules. A central server can distribute the system parsing rules and custom parsing rules to one or more remote servers for distributed processing. In a hierarchical parsing system, a first tier parser can be used to identify types of sources generating the log data. Log data from each type of log source can be sent to a second tier parser that corresponds to the type of log source.
Abstract translation: 公开了实现动态解析规则的方法,程序产品和系统。 可以使用解析规则解析来自各种日志生成器的日志数据,以生成有关信息系统的信息。 解析规则可以包括系统解析规则和自定义解析规则。 状态机可用于检测各种解析规则之间的冲突。 中央服务器可以将系统解析规则和自定义解析规则分发到一个或多个远程服务器进行分布式处理。 在分层解析系统中,第一层解析器可用于识别生成日志数据的源的类型。 可以将来自每种日志源的日志数据发送到与日志源类型对应的第二层解析器。