Invention Grant
- Patent Title: Reparsing unsuccessfully parsed event data in a security information and event management system
-
Application No.: US15235177Application Date: 2016-08-12
-
Publication No.: US10069853B2Publication Date: 2018-09-04
- Inventor: Rory F. Bray , Michael S. Hume , Christopher A. LeMesurier , Jamie A. R. Wheaton
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Francis Lammes; Stephen J. Walder, Jr.; Jeffrey S. LaBaw
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A mechanism is provided for reparsing unsuccessfully parsed event data. Responsive to determining that one or more unsuccessfully parsed event data items exist for a log source, each unsuccessfully parsed event data item of the one or more unsuccessfully parsed event data items is reparsing using an updated device support module associated with the log source. Responsive to the device support module successfully reparsing the unsuccessfully parsed event data item thereby forming a successfully parsed event data item, the successfully parsed event data item is added to a historical record of events associated with the log source. Responsive to the device support module failing to successfully reparse the unsuccessfully parsed event data item, the unsuccessfully parsed event data item is retained in an unsuccessfully parsed event data item data structure.
Public/Granted literature
- US20180048664A1 Reparsing Unsuccessfully Parsed Event Data in a Security Information and Event Management System Public/Granted day:2018-02-15
Information query