Patents Assigned to LogLogic, Inc.
  • Patent number: 8386498
    Abstract: Messages (e.g., log messages or any form of record oriented data) are analyzed for identifiable value patterns. When a pattern is located the value is replaced by a name or “token” for the pattern, resulting in a “message description” for the message. When analysis is finished and token/value replacements are complete the message description can be stored as a reference to the message.
    Type: Grant
    Filed: August 5, 2009
    Date of Patent: February 26, 2013
    Assignee: LogLogic, Inc.
    Inventor: Sanford Whitehouse
  • Patent number: 8380752
    Abstract: Event data (e.g., log messages) are represented as sets of attribute/value pairs. An index maps each attribute/value pair or attribute/value tuple to a pointer that points to event data which contains the attribute/value pair or attribute/value tuple. An attribute co-occurrence map or matrix can be generated that includes attribute names that co-occur together. Queries and custom reports can be generated by projecting event data into one or more attributes or attribute/value pairs, and then determining statistics on other attributes using a combination of the inverted index, the attribute co-occurrence map or matrix, operations on sets and/or math and statistical functions.
    Type: Grant
    Filed: April 11, 2011
    Date of Patent: February 19, 2013
    Assignee: LogLogic, Inc.
    Inventors: Sherif Botros, Jian L. Zhen, Minjun Liu, Boris Galitsky
  • Patent number: 8306967
    Abstract: To retrieve a sequence of associated events in log data, a request expression is parsed to retrieve types of dependencies between events which are searched, and the constraints (e.g., keywords) which characterize each event. Based on the parsing results, query components can be formed, expressing the constraints for individual events and interrelations (e.g., time spans) between events. A resultant span query comprising the query components can then be run against an index of events, which encodes a mutual location of associated events in storage.
    Type: Grant
    Filed: October 2, 2007
    Date of Patent: November 6, 2012
    Assignee: LogLogic, Inc.
    Inventors: Boris Galitsky, Sherif Botros
  • Patent number: 8234256
    Abstract: A system and method is disclosed which enables network administrators and the like to quickly analyze the data produced by log-producing devices such as network firewalls and routers. Unlike systems of the prior art, the system disclosed herein automatically parses and summarizes log data before inserting it into one or more databases. This greatly reduces the volume of data stored in the database and permits database queries to be run and reports generated while many types of attempted breaches of network security are still in progress. Database maintenance may also be accomplished automatically by the system to delete or archive old log data.
    Type: Grant
    Filed: November 18, 2004
    Date of Patent: July 31, 2012
    Assignee: LogLogic, Inc.
    Inventors: Jason Michael DeStefano, Thomas Hunt Schabo Grabowski
  • Patent number: 7925678
    Abstract: Event data (e.g., log messages) are represented as sets of attribute/value pairs. An index maps each attribute/value pair or attribute/value tuple to a pointer that points to event data which contains the attribute/value pair or attribute/value tuple. An attribute co-occurrence map or matrix can be generated that includes attribute names that co-occur together. Queries and custom reports can be generated by projecting event data into one or more attributes or attribute/value pairs, and then determining statistics on other attributes using a combination of the inverted index, the attribute co-occurrence map or matrix, operations on sets and/or math and statistical functions.
    Type: Grant
    Filed: January 12, 2007
    Date of Patent: April 12, 2011
    Assignee: LogLogic, Inc.
    Inventors: Sherif Botros, Jian L. Zhen, Minjun Liu, Boris Galitsky
  • Patent number: 7599939
    Abstract: A system and method is disclosed for collecting, storing and reporting raw log data from log-producing devices such as firewalls and routers. The log-producing devices may be both local and remote—i.e., linked to a raw log server via a LAN and/or a WAN. A log data analyzer at a remote location gathers log data from devices at that remote location into time-defined sets and then sends those sets over a WAN (which may be the Internet) to a raw log server using a first protocol. Local log-producing devices may send their log data to the log data analyzer via a LAN using a second protocol. The log data analyzer forwards the raw log data local devices to an appropriate log data analyzer for parsing, summarizing and storage in one or more databases. The raw log server combines local and remote sets of raw log data for a given time period and stores them in a storage area of raw log data.
    Type: Grant
    Filed: July 23, 2004
    Date of Patent: October 6, 2009
    Assignee: LogLogic, Inc.
    Inventors: Jason Michael DeStefano, Ralph D. Jenson