- Patent Title: System, method, and computer program for automatic parser creation
-
Application No.: US16890557Application Date: 2020-06-02
-
Publication No.: US11625366B1Publication Date: 2023-04-11
- Inventor: Barry Steiman , Sylvain Gil , Domingo Mihovilovic
- Applicant: Exabeam, Inc.
- Applicant Address: US CA Foster City
- Assignee: Exabeam, Inc.
- Current Assignee: Exabeam, Inc.
- Current Assignee Address: US CA Foster City
- Agency: Lessani Law Group, PC
- Main IPC: G06F16/21
- IPC: G06F16/21 ; H04L9/40 ; G06F11/34 ; G06N5/022 ; G06F21/55 ; G06F11/36 ; G06F21/57

Abstract:
The present disclosure describes a system, method, and computer program for automatically creating a parser for a log group. A parser-creation system groups logs that do not satisfy conditions for an existing parser, enables a user to select a log group for parser creation, and automatically creates a parser for the selected log group. In creating a parser, the system extracts values and keys value pairs from the log group and identifies the corresponding normalized output fields and regular expressions for the values and key-value pairs. To identify normalized fields corresponding to values and key-value pairs, the system compares the values and key-value pairs to one or more knowledgebases that include: (1) regular expressions from existing parsers, (2) regular expressions for value types associated with normalized fields, and (3) a list of keys in key-value pairs associated with normalized fields. As the system learns new token-to-normalized fields relationships, the system adds the relationships to its knowledgebase.
Information query