Invention Grant
- Patent Title: Identifying possible security threats using event group summaries
- Patent Title (中): 使用事件组摘要识别可能的安全威胁
-
Application No.: US15056999Application Date: 2016-02-29
-
Publication No.: US09596252B2Publication Date: 2017-03-14
- Inventor: John Coates , Lucas Murphey , David Hazekamp , James Hansen
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: Splunk Inc.
- Current Assignee: Splunk Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Wong & Rees LLP
- Agent Kirk D. Wong
- Main IPC: G06F11/00
- IPC: G06F11/00 ; H04L29/06 ; G06F21/55

Abstract:
A disclosed computer-implemented method includes receiving and indexing the raw data. Indexing includes dividing the raw data into time stamped searchable events that include information relating to computer or network security. Store the indexed data in an indexed data store and extract values from a field in the indexed data using a schema. Search the extracted field values for the security information. Determine a group of security events using the security information. Each security event includes a field value specified by a criteria. Present a graphical interface (GI) including a summary of the group of security events, other summaries of security events, and a remove element (associated with the summary). Receive input corresponding to an interaction of the remove element. Interacting with the remove element causes the summary to be removed from the GI. Update the GI to remove the summary from the GI.
Public/Granted literature
- US20160182546A1 Identifying Possible Security Threats Using Event Group Summaries Public/Granted day:2016-06-23
Information query