Method and apparatus for processing log data produced by a network is
described. In one example, entries in the log data are filtered using a
plurality of filters to select first entries from the entries. The first
entries are filtered using a plurality of false positive filters
associated with the plurality of filters to select second entries from
the first entries. Unique IP addresses are identified in the second
entries. The entries in the log data are then filtered using the unique
IP addresses to select third set entries. The third entries are analyzed
to detect one or more patterns.