US2021342411A1PendingUtilityA1

Event stream processing

Assignee: ENT SERVICES DEV CORP LPPriority: Aug 4, 2014Filed: Jul 15, 2021Published: Nov 4, 2021
Est. expiryAug 4, 2034(~8 yrs left)· nominal 20-yr term from priority
G06F 16/9535G06F 16/24568G06F 16/2477G06Q 10/06G06F 16/24565G06F 21/00
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An example system receives a plurality of event streams. A separate stream rule is applied to each individual event stream to produce a filtered output event stream. The system also applies a correlation rule to the filtered output event streams to produce correlated event results.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising:
 a plurality of event stream filter engines to receive a plurality of event streams, each event stream filter engine to receive a separate event stream, apply a filter rule specified for that particular event stream filter, and generate a filtered output event stream;   a correlation engine to receive the filtered output event streams from the event stream filter engines and apply a correlation rule to the filtered output event streams to produce correlated event results; and   a historical processing engine to receive the correlated event results, and apply a historical rule to the correlated event results to produce historical filtered results.   
     
     
         2 . The system of  claim 1  further comprising a time window engine to apply a time window-based rule to the historical filtered results. 
     
     
         3 . The system of  claim 2  further comprising a rule engine to:
 receive a complex event rule; and 
 decompose the complex event rule to generate:
 the filter rules for the event stream filter engines; 
 a correlation rule; 
 the historical rule; and 
 the time window-based rule. 
 
 
     
     
         4 . The system of  claim 3  wherein the rule engine distributes the filter rules to the event stream filter engines, the correlation rule to the correlation engine, the historical rule to the historical processing engine, and the time window-based rule to the time window engine. 
     
     
         5 . The system of  claim 1  wherein:
 each filter rule, when applied by the corresponding event stream filter engine, causes a subset of the event stream received by that event stream filter engine to be output by the event stream filter engine as the filtered output event stream; and 
 the correlation rule is to specify a relationship between separate filtered output event streams that the correlation engine is to detect. 
 
     
     
         6 . The system of  claim 1  wherein the historical rule indicates a processing operation to be performed by the historical processing engine on the correlated event results based on data previously mapped to at least one of the event streams and previously stored in non-volatile storage. 
     
     
         7 . The system of  claim 1  wherein the correlation engine does not receive nor operate on the event streams received by the event stream filter engines. 
     
     
         8 . A non-transitory storage device containing machine instructions that, when executed by a processing resource, cause the processing resource to:
 receive a plurality of event streams, each event stream including a plurality of records;   apply a separate stream rule to each individual event stream to produce a plurality of filtered output event streams;   after applying a separate stream rule to each individual event stream, apply a correlation rule to correlate the filtered output event streams to produce correlated event results;   after correlating the filtered event streams, apply a historical rule to the correlated event results to produce historical filtered results; and   after applying the historical rule, apply a time window-based rule to the historical filtered results.   
     
     
         9 . The non-transitory storage device of  claim 8  wherein the time window-based rule implements a user-programmable period of time and also implements a user-programmable rule that specifies certain historical filtered results that must be true during the user-programmable period of time. 
     
     
         10 . The non-transitory storage device of  claim 8  wherein the machine instructions, when executed, further cause the processing resource to:
 receive a complex event rule from a user; and 
 decompose the complex event rule to generate:
 the stream rules; 
 the correlation rule; 
 the historical rule; and 
 the time window-based rule. 
 
 
     
     
         11 . The non-transitory storage device of  claim 10  wherein, when the machine instructions, when executed, cause the processing resource to apply the historical rule, the machine instructions cause the processing resource to perform an operation on the correlated event results based on data previously mapped to at least one of the event streams and previously stored in non-volatile storage. 
     
     
         12 . A method, comprising:
 receiving a plurality of event streams;   applying a separate stream rule to each individual event stream to produce a filtered output event stream from each such event stream;   after applying a separate stream rule to each individual event stream, correlating the filtered output event streams to produce correlated event results; and   after correlating the filtered event streams, applying a time window-based rule to produce time window results.   
     
     
         13 . The method of  claim 12  further comprising, after correlating the filtered output event streams but before applying the time window-based rule, applying a historical rule to the correlated event results to produce historical filtered results and wherein applying the time window-based rule comprises applying the time window-based rule to the historical filtered results. 
     
     
         14 . The method of  claim 13  further comprising:
 receiving a complex event rule; and 
 decomposing the complex event rule to generate:
 the separate stream rules for the event streams; 
 a correlation rule to be applied to the filtered event streams while correlating the filtered event streams; 
 the historical rule; and 
 the time window-based rule. 
 
 
     
     
         15 . The method of  claim 12 :
 wherein each event stream includes a plurality of records;   wherein applying the separate stream rules to each such event stream comprises causing a subset of the records of each event stream to be the filtered output event stream for that event stream; and   wherein correlating the filtered event streams includes applying a correlation rule that specifies a relationship between separate filtered output event streams.

Join the waitlist — get patent alerts

Track US2021342411A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.