首页> 外国专利> To support the computer network security technology to store efficiently log data while supporting queries

To support the computer network security technology to store efficiently log data while supporting queries

机译:支持计算机网络安全技术以在支持查询的同时有效地存储日志数据

摘要

A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a data “chunk.” The manager receives data chunks and stores them so that they can be queried. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. The metadata includes a unique identifier associated with the receiver, the number of events in the buffers, and, for each “field of interest,” a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk includes the metadata structure and a compressed version of the contents of the buffers. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.
机译:日志记录系统包括事件接收器和存储管理器。接收器接收日志数据,对其进行处理,并输出数据“块”。管理器接收数据块并将其存储,以便可以查询它们。接收器包括用于存储事件的缓冲区和用于存储有关缓冲区内容的元数据的元数据结构。元数据包括与接收器相关联的唯一标识符,缓冲器中的事件数,并且对于每个“关注领域”,包括:反映缓冲区中所有事件的该字段的值范围的最小值和最大值。块包括元数据结构和缓冲区内容的压缩版本。查询事件数据时,元数据结构充当搜索索引。日志记录系统可以与安全信息/事件管理(SIEM)系统结合使用。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号