Patent attributes
As an embodiment of the present invention, a network monitoring apparatus includes a combination rule storage section where a combination rule is registered; and the combination rule includes a combination of a plurality of failure event information to be monitored, and new event information to which the combination of the plurality of failure event information is to be changed. In this state, the network monitoring apparatus collects a plurality of failure event information from network apparatuses; extracts, from the plurality of failure event information collected, a combination of a plurality of failure event information detected to occur within a unit time; and collates the combination of the plurality of failure event information extracted with the combination of the plurality of failure event information defined to be monitored in the combination rule. Then, when the combination of the plurality of failure event information extracted matches in content and occurrence sequence with the combination of the plurality of failure event information defined to be monitored in the combination rule, the network monitoring apparatus adds the new event information included in the combination rule to the combination of the plurality of failure event information extracted, or alternatively, replaces the combination of the plurality of failure event information extracted with the new event information.