Continuous query language (CQL) debugger in complex event processing (CEP)
US-9329975-B2 · May 3, 2016 · US
US10205642B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10205642-B2 |
| Application number | US-201514951010-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 24, 2015 |
| Priority date | Mar 11, 2013 |
| Publication date | Feb 12, 2019 |
| Grant date | Feb 12, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A system and method for management of network monitoring information includes a non-transient memory and one or more processors coupled to the non-transient memory and configured to read instructions from the non-transient memory to cause the information handling system to perform operations, The operations include collecting real-time network monitoring information from one or more network switching units, storing the collected real-time network monitoring information in a data storage system using a first column family, periodically aggregating the collected real-time network monitoring information to generate corresponding history information, storing the aggregated history information in the data storage system using a second column family different from the first column family, retrieving information from the data storage system based on one or more first queries, the stored real-time network monitoring information, and the stored aggregated history information, and providing the retrieved information for use during network monitoring.
Opening claim text (preview).
What is claimed is: 1. An information handling system comprising: a non-transient memory; and one or more processors coupled to the non-transient memory and configured to read instructions from the non-transient memory to cause the information handling system to perform operations comprising: collecting real-time network monitoring information from one or more network switching units; storing the collected real-time network monitoring information in a data storage system using a first column family; periodically aggregating the collected real-time network monitoring information to generate corresponding history information; storing the aggregated history information in the data storage system using a second column family different from the first column family; receiving a network monitoring query; retrieving, in response to receiving the network monitoring query, information from the data storage system based on the network monitoring query, the stored real-time network monitoring information, and the stored aggregated history information; providing the retrieved information as a response to the network monitoring query; periodically deleting portions of the stored real-time network monitoring information older than a first time-to-live value; and periodically deleting portions of the stored aggregated history information that is older than a second time-to live value longer than the first time-to-live value. 2. The information handling system of claim 1 , wherein the data storage system stores the stored real-time information and the stored aggregated history information using a NoSQL schema. 3. The information handling system of claim 1 , wherein the data storage system is a distributed data storage system. 4. The information handling system of claim 1 , wherein the real-time network monitoring information is sFlow information. 5. The information handling system of claim 1 , wherein the operations further comprise: periodically processing one or more commonly used static queries; and storing results of the one or more commonly used static queries in the data storage system. 6. The information handling system of claim 5 , wherein retrieving the information from the data storage system is further based on the stored results of the one or more commonly used static queries. 7. A method of managing network monitoring information, the method comprising: collecting, using a network monitoring system comprising a non-transient memory and one or more processors executing instructions stored in the non-transient memory, real-time network monitoring information from one or more network switching units; storing the collected real-time network monitoring information in a data storage system using a first column family; periodically aggregating, by the network monitoring system, the collected real-time network monitoring information to generate corresponding history information; storing the aggregated history information in the data storage system using a second column family different from the first column family; receiving a network monitoring query; retrieving, in response to receiving the network monitoring query, information from the data storage system based on the network monitoring query, the stored real-time network monitoring information, and the stored aggregated history information; providing the retrieved information as a response to the network monitoring query; periodically deleting portions of the stored real-time network monitoring information older than a first time-to-live value; and periodically deleting portions of the stored aggregated history information that is older than a second time-to live value longer than the first time-to-live value. 8. The method of claim 7 , wherein the data storage system stores the stored real-time information and the stored aggregated history information using a NoSQL schema. 9. The method of claim 7 , wherein the data storage system is a distributed data storage system. 10. The method of claim 7 , wherein the real-time network monitoring information is sFlow information. 11. The method of claim 7 , further comprising: periodically executing one or more commonly used static queries; and storing results of the one or more commonly used static queries in the data storage system. 12. The method of claim 11 , wherein retrieving the information from the data storage system is further based on the stored results of the one or more commonly used static queries. 13. A non-transient computer-readable media having stored thereon machine-readable instructions executable to cause an information handling system to perform operations comprising: collecting real-time network monitoring information from one or more network switching units; storing the collected real-time network monitoring information in a data storage system using a first column family; periodically aggregating the collected real-time network monitoring information to generate corresponding history information; storing the aggregated history information in the data storage system using a second column family different from the first column family; receiving a network monitoring query; retrieving, in response to receiving the network monitoring query, information from the data storage system based on the network monitoring query, the stored real-time network monitoring information, and the stored aggregated history information; providing the retrieved information as a response to the network monitoring query; periodically deleting portions of the stored real-time network monitoring information older than a first time-to-live value; and periodically deleting portions of the stored aggregated history information that is older than a second time-to live value longer than the first time-to-live value. 14. The non-transient computer-readable media of claim 13 , wherein the data storage system stores the stored real-time information and the stored aggregated history information using a NoSQL schema. 15. The non-transient computer-readable media of claim 13 , wherein the data storage system is a distributed data storage system. 16. The non-transient computer-readable media of claim 13 , wherein the real-time network monitoring information is sFlow information. 17. The non-transient computer-readable media of claim 13 , wherein the operations further comprise: periodically processing one or more commonly used static queries; and storing results of the one or more commonly used static queries in the data storage system; and retrieving the information from the data storage system is further based on the stored results of the one or more commonly used static queries.
by sampling · CPC title
Physics · mapped topic
Physics · mapped topic
using software, i.e. software packages (network security related monitoring H04L63/1408) · CPC title
Physics · mapped topic
Related publications grouped by family.
Answers are generated from the same data shown on this page.