An embodiment includes a computer system for detecting and monitoring
network intrusion events from log data received from network service
devices in a computer network. An embodiment may include an event parser
in communication with multiple network service devices. The event parser
may parse information to create corresponding event objects concerning
intrusion events. The system may include an event manager in
communication with the event parser. The event manager may be configured
to evaluate the event objects according to at least one predetermined
threshold condition. The system may include an event broadcaster in
communication with the event manager for receiving event objects
designated by the event manager for broadcast. The event broadcaster may
be able to transmit the event objects in real time. The system may also
include means for alerting the user that a network intrusion event has
occurred.