Risto Vaarandi, Bernhards Blumbergs, E. Çalışkan
{"title":"简单事件相关器——创建可伸缩配置的最佳实践","authors":"Risto Vaarandi, Bernhards Blumbergs, E. Çalışkan","doi":"10.1109/COGSIMA.2015.7108181","DOIUrl":null,"url":null,"abstract":"During the past two decades, event correlation has emerged as a prominent monitoring technique, and is essential for achieving better situational awareness. Since its introduction in 2001 by one of the authors of this paper, Simple Event Correlator (SEC) has become a widely used open source event correlation tool. During the last decade, a number of papers have been published that describe the use of SEC in various environments. However, recent SEC versions have introduced a number of novel features not discussed in existing works. This paper fills this gap and provides an up-to-date coverage of best practices for creating scalable SEC configurations.","PeriodicalId":373467,"journal":{"name":"2015 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-03-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":"{\"title\":\"Simple event correlator - Best practices for creating scalable configurations\",\"authors\":\"Risto Vaarandi, Bernhards Blumbergs, E. Çalışkan\",\"doi\":\"10.1109/COGSIMA.2015.7108181\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"During the past two decades, event correlation has emerged as a prominent monitoring technique, and is essential for achieving better situational awareness. Since its introduction in 2001 by one of the authors of this paper, Simple Event Correlator (SEC) has become a widely used open source event correlation tool. During the last decade, a number of papers have been published that describe the use of SEC in various environments. However, recent SEC versions have introduced a number of novel features not discussed in existing works. This paper fills this gap and provides an up-to-date coverage of best practices for creating scalable SEC configurations.\",\"PeriodicalId\":373467,\"journal\":{\"name\":\"2015 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision\",\"volume\":\"15 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-03-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"12\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2015 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/COGSIMA.2015.7108181\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COGSIMA.2015.7108181","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Simple event correlator - Best practices for creating scalable configurations
During the past two decades, event correlation has emerged as a prominent monitoring technique, and is essential for achieving better situational awareness. Since its introduction in 2001 by one of the authors of this paper, Simple Event Correlator (SEC) has become a widely used open source event correlation tool. During the last decade, a number of papers have been published that describe the use of SEC in various environments. However, recent SEC versions have introduced a number of novel features not discussed in existing works. This paper fills this gap and provides an up-to-date coverage of best practices for creating scalable SEC configurations.