Log Management System for Heterogeneous Network Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of managing and analyzing log data across diverse network technologies and platforms, with varying log formats and systems, makes comprehensive review and monitoring impractical, leading to difficulties in extracting useful information and ensuring security, compliance, and operational analysis.

Innovation Solution

A system and method for processing and managing log messages, involving log processing rules, metadata classification, and data management settings to selectively process and distribute logs across platforms, using protocols like Syslog, SNMP, and proprietary formats, allowing for customizable filtering, archiving, and alerting mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If log files from multiple devices and platforms are collected and reviewed comprehensively, then security monitoring and compliance analysis are improved, but system complexity and difficulty of management increase significantly

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex task of log management by creating distinct functional modules: log collection agents on individual devices, a central log management server, and specialized analysis tools. Each component handles specific aspects of log processing, reducing the complexity burden on any single system element while maintaining comprehensive security monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a central log management server as an intermediary between diverse log sources and analysis tools. This mediator standardizes log formats, centralizes storage, and provides unified access controls, thereby improving security monitoring without proportionally increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If log data from diverse platforms with varying formats is collected, then comprehensive audit and compliance analysis is enabled, but data processing and standardization become increasingly difficult

Engineering Contradiction:
Improvecompliance analysis capabilityVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a universal log format and standardized data structure that can accommodate logs from multiple platforms and devices. The log management server provides multi-functional capabilities including format conversion, normalization, and standardized storage, enabling comprehensive compliance analysis without requiring separate processing systems for each log source.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms diverse log formats into a standardized parameter structure with consistent fields for timestamps, source identification, event types, and security-relevant data. This parameter standardization enables uniform processing and analysis across all log sources while preserving the essential information needed for compliance audits.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If real-time log processing and analysis is implemented across large networks, then security event detection is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity event detectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary filtering and classification of log events at the collection agents and management server before detailed analysis. By pre-processing logs to identify and prioritize security-relevant events, the system reduces the computational burden on analysis tools and accelerates detection of critical security incidents.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies selective processing where only log events meeting specific criteria (e.g., security-related keywords, anomaly patterns) undergo intensive analysis. This partial action approach focuses computational resources on high-priority events, improving security detection efficiency without proportionally increasing processing time for all logs.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10122575B2Log collection, structuring and processing
Publication Date: 2018.11.06 LOGRHYTHM INC
  • US10122575B2 patent drawing
  • US10122575B2 patent drawing
  • US10122575B2 patent drawing

AI summary

Tools for use in obtaining useful information from processed log messages generated by a variety of network platforms (e.g., Windows servers, Linux servers, UNIX servers, databases, workstations, etc.). The log messages may be processed by one or more processing platforms or “log managers” using any appropriate rule base to identify “events” (i.e., log messages of somewhat heightened importance), and one or more “event managers” may analyze the events to determine whether alarms should be generated therefrom. The tools may be accessed via any appropriate user interface of a console that is in communication with the various log managers, event managers, etc., to perform numerous tasks in relation to logs, events and alarms.