US2013227352A1PendingUtilityA1
Log monitoring
Est. expiryFeb 24, 2032(~5.6 yrs left)· nominal 20-yr term from priority
Inventors:Paramasivam KumarasamyAmey Vijaykumar KarandikarDurga Prasad ChedalavadaSuma SeshadriAnand Vibhor
G06F 11/1461G06F 11/3072G06F 11/3089G06F 11/3006G06F 11/3476G06F 11/1458
53
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A log monitoring system uses log monitoring rules to monitor log data generated by applications executing on a client computing device. By monitoring log data, the system detects that one or more triggering events have occurred on the client computing device. In response, the log monitoring system can perform one or more appropriate remedial actions. Additionally, in response to the detected event(s), the log monitoring system can extract a select subset of relevant data from the client and transmit the subset of data to a separate repository for storage and/or processing.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for monitoring log data associated with one or more applications executing on at least one client computing device in a networked data storage environment, the method comprising:
receiving a first set of log monitoring rules from a storage manager module, wherein the storage manager module directs storage operations between the client computing device and secondary storage, the log monitoring rules defining one or more triggering events associated with the client computing device; monitoring, at the client computing device, log data generated by at least one application executing on the client computing device, the log data including information related to events that occur on the client computing device and stored in a data store associated with the client computing device; in response to said monitoring, and based on the log monitoring rules, detecting whether a triggering event has occurred on the client computing device; in response to detecting that a triggering event has occurred on the client computing device, and based on the log monitoring rules, filtering data on the client computing device to extract a select subset of data for transmission to a collection repository that is separate from the client computing device and stores the select subset.
2 . The method of claim 1 , further comprising, in response to the detected triggering event, and based on the log monitoring rules, performing a remedial action associated with the client computing device.
3 . The method of claim 2 , wherein said performing a remedial action comprises performing at least one of not ng the storage manager module of the detected triggering event, limiting or preventing access to the at least one application, limiting or preventing access to the client computing device, limiting or preventing access to at least one file or folder stored on the client computing device, and notifying a user or administrator of the detected triggering event.
4 . The method of claim 2 , wherein the remedial action is initiated and performed by the client computing device without input from the storage manager module.
5 . The method of claim 1 , further comprising:
determining whether at least one additional client computing device is affected by the detected triggering event; and in response to determining that the additional client computing device is affected by the detected triggering event, performing a remedial action associated with the additional client computing device.
6 . The method of claim 1 , wherein the triggering events include one or more of an unauthorized access, an attempted unauthorized access, a request for unauthorized access, a predetermined number of failed login attempts, an unauthorized modification of one or more files, an application error, termination of employment of a user, or identification of a computer virus.
7 . The method of claim 1 , wherein there is at least one additional client computing device in the storage network, the storage manager distributes a second set of log monitoring rules to the additional client computing device, and the first set of log monitoring rules includes at least some rules which are the same as corresponding rules in the second set of log monitoring rules.
8 . The method of claim 1 , further comprising processing the data stored in the collection repository to audit system behavior, wherein said processing is performed by a computing device other than the client computing device.
9 . The method of claim 1 , wherein the client computing device and the collection repository communicate via a local area network (LAN), and the client computing device and the storage manager module communicate via a wide area network (WAN).
10 . The method of claim 1 , further comprising copying the data in the collection repository to secondary storage based on a storage policy.
11 . The method of claim 1 , further comprising, in response to the detected triggering event, instructing at least one additional client computing device to transmit a second select subset of data from the additional client computing device to a collection repository associated with the additional client computing device.
12 . A system configured to monitor log data in a data storage environment, the system comprising:
a data store comprising:
a first set of log monitoring rules received from a storage manager module, wherein the log monitoring rules define one or more triggering events associated with a client computing device in communication with the storage manager module, and
log data generated by at least one application executing on the client computing device, wherein the log data is generated by at least one application executing on the client computing device and includes information related to events that occur on the client computing device; and
a log monitoring module executing in one or more processors and configured to:
monitor the log data;
based on the log monitoring rules, detect whether a triggering event has occurred on the client computing device; and
upon detecting that a triggering event has occurred on the client computing device, and based on the log monitoring rules, filter data on the client computing device to extract a select subset of data for transmission to a collection repository that is separate from the client computing device and stores the select subset.
13 . The log monitoring system of claim 12 , wherein a remedial action associated with the client computing device is performed in response to the detected triggering event.
14 . The log monitoring system of claim 13 , wherein said remedial action comprises at least one of notifying the storage manager module of the detected triggering event, limiting or preventing access to the at least one application, limiting or preventing access to the client computing device, limiting or preventing access to at least one file or folder stored on the client computing device, and notifying a user or administrator of the detected triggering event.
15 . The log monitoring system of claim 13 , wherein the remedial action is initiated and performed by the client computing device without input from the storage manager module.
16 . The log monitoring system of claim 12 , wherein, if at least one additional client computing device is affected by the detected triggering event, a remedial action associated with the additional client computing device is performed.
17 . The log monitoring system of claim 12 , wherein the triggering events comprise at least one of an unauthorized access, an attempted unauthorized access, a request for unauthorized access, a predetermined number of failed login attempts, an unauthorized modification of one or more files, an application error, client computing device error, termination of employment of a user, or identification of a computer virus.
18 . The log monitoring system of claim 12 , further comprising at least a second client computing device, wherein the second client computing device comprises a data store containing a second set of log monitoring rules received from the storage manager module, wherein the first set of log monitoring rules includes at least some rules which are the same as corresponding rules in the second set of log monitoring rules.
19 . A method for monitoring data associated with one or more applications executing on at least one client computing device in a networked computing environment, the method comprising:
receiving log monitoring rules at least one client computing device of a plurality of client computing devices, the monitoring rules defining one or more triggering events associated with the client computing device; monitoring, at the client computing device, event data generated by at least one application executing on the client computing device, the event data recording information related to events that occur on the client computing device; in response to said monitoring and based on the monitoring rules, detecting whether a triggering event has occurred on the client computing device; in response to detecting that a triggering event has occurred on the client computing device, extracting a select subset of data from a set of data stored on the client computing device; and transmitting the select subset of data for storage in a collection repository that is separate from the client computing device.
20 . A system for monitoring log data generated by at least one application executing on a client computing device, the system comprising:
receiving means for receiving a first set of log monitoring rules from a storage manager module, wherein the storage manager module directs storage operations between the client computing device and secondary storage, the log monitoring rules defining one or more triggering events associated with the client computing device; monitoring means for monitoring log data generated by at least one application executing on the client computing device, the log data recording information related to events that occur on the client computing device and stored in a data store associated with the client computing device, wherein the monitoring means is further configured to:
detect whether a triggering event has occurred on the client computing device based on the log monitoring rules;
upon detecting that a triggering event has occurred on the client computing device, and based on the log monitoring rules, filter data on the client computing device to extract a select subset of data; and
transmit the select subset of data for storage in a collection repository that is separate from the client computing device.Join the waitlist — get patent alerts
Track US2013227352A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.