Abstract: Analyzing log data, such as security log data and event data, is disclosed. Log data is received. Portions of the log data are clustered into clusters of similar data portions. A signature for each cluster is generated. Comparison of subsequent log data with the signature indicates whether the subsequent log data belongs in the cluster.
Type:
Grant
Filed:
June 5, 2012
Date of Patent:
February 16, 2016
Assignee:
Sumo Logic
Inventors:
Kumar Saurabh, Christian Friedrich Beedgen, Bruno Kurtic
Abstract: The automatic selection and usage of a parser is disclosed. Raw data is received from a first remote device. At least a portion of the raw data is evaluated using a plurality of rules. A confidence measure is determined for at least some of the rules. An indication that the raw data pertains to a source is provided as output when the confidence measure exceeds a threshold.
Type:
Grant
Filed:
June 30, 2011
Date of Patent:
September 15, 2015
Assignee:
Sumo Logic
Inventors:
Kumar Saurabh, Christian Friedrich Beedgen, Bruno Kurtic
Abstract: Data collection and transmission is disclosed. A server is configured to receive, from a remote device, a message including raw information, and to parse at least a portion of the received raw information. The raw information is received by the system from an information reporting module interface of the remote device. The information reporting module of the remote device is configured to receive information from at least one separately installed information reporting module. A client device includes an information reporting module interface and a server interface. The client device is configured to receive configuration information from a remote server.
Type:
Grant
Filed:
June 30, 2011
Date of Patent:
March 17, 2015
Assignee:
Sumo Logic
Inventors:
Christian Friedrich Beedgen, Kumar Saurabh, Bruno Kurtic
Abstract: Automatically generating a parser is disclosed. Raw data is received from a first remote device. A determination that the raw data does not, within a predefined confidence measure, conform to any rules included in a set of rules is made. A clustering function is performed on the raw data. At least one parser rule is generated based on the clustering.
Type:
Grant
Filed:
June 30, 2011
Date of Patent:
January 6, 2015
Assignee:
Sumo Logic
Inventors:
Kumar Saurabh, Christian Friedrich Beedgen, Bruno Kurtic
Abstract: Obfuscating data is disclosed. A processor identifies structured information in log data. The structured information is transformed in a manner that preserves the structure to form transformed raw data. The transformed raw data is sent to a remote analysis engine. The remote analysis engine receives a query and responds to the query by providing as results at least a portion of the transformed raw data. A processor is configured to de-transform the transformed raw data.
Type:
Grant
Filed:
June 30, 2011
Date of Patent:
October 14, 2014
Assignee:
Sumo Logic
Inventors:
Bruno Kurtic, Stefan Christoph Zier, Christian Friedrich Beedgen, Kumar Saurabh