Log event correlation analysis method and device capable of concurrent and interrupted analysis
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU LANKE TECH
- Publication Date
- 2011-08-17
- Estimated Expiration
- Not applicable · inactive patent
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to the technical field of event correlation analysis in the field of information security, in particular to a log event correlation analysis method and device for performing concurrent and intermittent analysis on multiple different logs. Background technique
[0002] In recent years, due to the rapid development of information technology, the scale of enterprise information technology infrastructure construction has continued to expand, and IT monitoring and operation and maintenance systems have also been widely used. Such systems are aimed at network equipment, hosts, operating systems, database systems and various application systems. The technical means of monitoring is mainly to collect various log data, and through effective analysis of these data, users or administrators can discover and avoid disasters in advance, and find the root cause of security incidents. The log here refers to certain operations of the system on som...