Correlating forensic and non-forensic data in an information technology environment

    公开(公告)号:US11743285B2

    公开(公告)日:2023-08-29

    申请号:US16528397

    申请日:2019-07-31

    Applicant: Splunk Inc.

    Inventor: Brian Luger

    Abstract: Techniques and mechanisms are disclosed enabling efficient collection of forensic data from client devices, also referred to herein as endpoint devices, of a networked computer system. Embodiments described herein further enable correlating forensic data with other types of non-forensic data from other data sources. A network security application described herein further enables generating various dashboards, visualizations, and other interfaces for managing forensic data collection, and displaying information related to collected forensic data and information related to identified correlations between items of forensic data and other items of non-forensic data.

    Queries based on selected subsets of textual representations of events

    公开(公告)号:US11741086B2

    公开(公告)日:2023-08-29

    申请号:US17121935

    申请日:2020-12-15

    Applicant: SPLUNK Inc.

    CPC classification number: G06F16/2428 G06F3/0482 G06F3/04842 G06F3/04847

    Abstract: A search interface is displayed in a table format that includes one or more columns, each column including data items of an event attribute, the data items being of a set of events, and a plurality of rows forming cells with the one or more columns, each cell displaying a textual representation of at least one of the data items of the event attribute of a corresponding column. Based on a user selecting a portion of the textual representation in a corresponding cell, a list of options is displayed that corresponds to the selected portion of the textual representation. Furthermore, one or more commands are added to a search query that corresponds to the set of events, the one or more commands being based on at least an option that is selected from the list of options and the selected portion of the textual representation in the corresponding cell.

    Secure update of dashboard properties

    公开(公告)号:US11736452B1

    公开(公告)日:2023-08-22

    申请号:US17246536

    申请日:2021-04-30

    Applicant: SPLUNK INC.

    CPC classification number: H04L63/0428 H04L63/0272 H04L63/0869

    Abstract: In various embodiments, a computer-implemented method comprises determining that a first property associated with a dashboard is modified at a first device, determining that the dashboard is accessible at a second device, where the first device and the second device are coupled via a trusted tunnel bridge, and in a real-time response to determining that the first property was modified, transmitting, to the second device via the trusted tunnel bridge, an update that causes the second device modify the dashboard based on the modified first property.

    Online data decomposition
    108.
    发明授权

    公开(公告)号:US11729074B1

    公开(公告)日:2023-08-15

    申请号:US17069693

    申请日:2020-10-13

    Applicant: SPLUNK Inc.

    CPC classification number: H04L43/067 H04L43/022 H04L43/04 H04L43/062

    Abstract: Embodiments of the present invention are directed to facilitating performing online data decomposition. In accordance with aspects of the present disclosure, an incoming data point of a time series data set is obtained. Thereafter, an iterative process of estimating trend and seasonality is performed to decompose the incoming data point to a set of data components based on a particular set of previous data points of the time series data set and corresponding data components. Generally, the set of data components for the incoming data point include a trend component, a seasonality component, and a residual component. The set of data components is provided for analysis of the incoming data point, such as, for example, to identify data anomalies.

    Low-latency streaming analytics
    109.
    发明授权

    公开(公告)号:US11727039B2

    公开(公告)日:2023-08-15

    申请号:US17811849

    申请日:2022-07-11

    Applicant: Splunk Inc.

    Abstract: Systems and methods are disclosed for implementing a low-latency data stream monitoring system. The data stream monitoring system may obtain raw data from a data source as soon after the data is generated, and may classify the data according to different topics. The topics may be published in a publish-subscribe messaging model, and data enrichment systems may subscribe to the topics to receive data for enrichment. The data enrichment systems may supplement or replace the raw data with additional information, and may further classify or reclassify the enriched data into different topics. The enriched data may then be published to an alert generation system, which may apply various criteria to the enriched data to determine that alerts should be generated, generate the alerts, and publish or transmit the alerts to client devices. Individual data streams, topics, enrichments, criteria, and alarms may be added, removed, or modified as required.

Patent Agency Ranking