Patents Assigned to LogLogic, Inc.
-
Patent number: 8386498Abstract: Messages (e.g., log messages or any form of record oriented data) are analyzed for identifiable value patterns. When a pattern is located the value is replaced by a name or “token” for the pattern, resulting in a “message description” for the message. When analysis is finished and token/value replacements are complete the message description can be stored as a reference to the message.Type: GrantFiled: August 5, 2009Date of Patent: February 26, 2013Assignee: LogLogic, Inc.Inventor: Sanford Whitehouse
-
Patent number: 8380752Abstract: Event data (e.g., log messages) are represented as sets of attribute/value pairs. An index maps each attribute/value pair or attribute/value tuple to a pointer that points to event data which contains the attribute/value pair or attribute/value tuple. An attribute co-occurrence map or matrix can be generated that includes attribute names that co-occur together. Queries and custom reports can be generated by projecting event data into one or more attributes or attribute/value pairs, and then determining statistics on other attributes using a combination of the inverted index, the attribute co-occurrence map or matrix, operations on sets and/or math and statistical functions.Type: GrantFiled: April 11, 2011Date of Patent: February 19, 2013Assignee: LogLogic, Inc.Inventors: Sherif Botros, Jian L. Zhen, Minjun Liu, Boris Galitsky
-
Patent number: 8306967Abstract: To retrieve a sequence of associated events in log data, a request expression is parsed to retrieve types of dependencies between events which are searched, and the constraints (e.g., keywords) which characterize each event. Based on the parsing results, query components can be formed, expressing the constraints for individual events and interrelations (e.g., time spans) between events. A resultant span query comprising the query components can then be run against an index of events, which encodes a mutual location of associated events in storage.Type: GrantFiled: October 2, 2007Date of Patent: November 6, 2012Assignee: LogLogic, Inc.Inventors: Boris Galitsky, Sherif Botros
-
Patent number: 8234256Abstract: A system and method is disclosed which enables network administrators and the like to quickly analyze the data produced by log-producing devices such as network firewalls and routers. Unlike systems of the prior art, the system disclosed herein automatically parses and summarizes log data before inserting it into one or more databases. This greatly reduces the volume of data stored in the database and permits database queries to be run and reports generated while many types of attempted breaches of network security are still in progress. Database maintenance may also be accomplished automatically by the system to delete or archive old log data.Type: GrantFiled: November 18, 2004Date of Patent: July 31, 2012Assignee: LogLogic, Inc.Inventors: Jason Michael DeStefano, Thomas Hunt Schabo Grabowski
-
Patent number: 7925678Abstract: Event data (e.g., log messages) are represented as sets of attribute/value pairs. An index maps each attribute/value pair or attribute/value tuple to a pointer that points to event data which contains the attribute/value pair or attribute/value tuple. An attribute co-occurrence map or matrix can be generated that includes attribute names that co-occur together. Queries and custom reports can be generated by projecting event data into one or more attributes or attribute/value pairs, and then determining statistics on other attributes using a combination of the inverted index, the attribute co-occurrence map or matrix, operations on sets and/or math and statistical functions.Type: GrantFiled: January 12, 2007Date of Patent: April 12, 2011Assignee: LogLogic, Inc.Inventors: Sherif Botros, Jian L. Zhen, Minjun Liu, Boris Galitsky
-
Patent number: 7599939Abstract: A system and method is disclosed for collecting, storing and reporting raw log data from log-producing devices such as firewalls and routers. The log-producing devices may be both local and remote—i.e., linked to a raw log server via a LAN and/or a WAN. A log data analyzer at a remote location gathers log data from devices at that remote location into time-defined sets and then sends those sets over a WAN (which may be the Internet) to a raw log server using a first protocol. Local log-producing devices may send their log data to the log data analyzer via a LAN using a second protocol. The log data analyzer forwards the raw log data local devices to an appropriate log data analyzer for parsing, summarizing and storage in one or more databases. The raw log server combines local and remote sets of raw log data for a given time period and stores them in a storage area of raw log data.Type: GrantFiled: July 23, 2004Date of Patent: October 6, 2009Assignee: LogLogic, Inc.Inventors: Jason Michael DeStefano, Ralph D. Jenson