Using storage reactors to transform event data generated by remote capture agents

    公开(公告)号:US11108659B2

    公开(公告)日:2021-08-31

    申请号:US16378400

    申请日:2019-04-08

    Applicant: Splunk Inc.

    Inventor: Michael Dickey

    Abstract: The disclosed embodiments provide a method and system for processing network data. During operation, the system obtains, at a remote capture agent, configuration information for the remote capture agent from a configuration server over a network. Next, the system uses the configuration information to configure the generation of event data from network data obtained from network packets at the remote capture agent. The system then uses the configuration information to configure transformation of the event data or the network data into transformed event data at the remote capture agent.

    TRANSLATING SECURITY ACTIONS INTO COMPUTING ASSET-SPECIFIC ACTION PROCEDURES

    公开(公告)号:US20210258340A1

    公开(公告)日:2021-08-19

    申请号:US17306703

    申请日:2021-05-03

    Applicant: Splunk Inc.

    Abstract: Systems, methods, and software described herein enhances how security actions are implemented within a computing environment. In one example, a method of implementing security actions for a computing environment comprising a plurality of computing assets includes identifying a security action in a command language for the computing environment. The method further provides identifying one or more computing assets related to the security action, and obtaining hardware and software characteristics for the one or more computing assets. The method also includes translating the security action in the command language to one or more action procedures based on the hardware and software characteristics, and initiating implementation of the one or more action procedures in the one or more computing assets.

    Information technology networked entity monitoring with dynamic metric and threshold selection

    公开(公告)号:US11093518B1

    公开(公告)日:2021-08-17

    申请号:US16049628

    申请日:2018-07-30

    Applicant: Splunk Inc.

    Abstract: Data intake and query system (DIQS) instances supporting applications including lower-tier, focused, work group oriented applications, are tailored to display the metrics for the needs of the user. An interface caused by operation of an entity monitoring system (EMS) operating in conjunction with the lower-tier DIQS displays the monitored entities as individual representations. The user selects a metric and a metric threshold. The EMS causes a display of an interface having a representation for each monitored entity. Each representation includes a metric value and indicates an entity status based on the metric value and the threshold. The user can dynamically change the threshold on the interface for easy visualization of aggregation of monitored entities to determine the performance of the infrastructure. The interface also provides the user with the ability to select an entity and click through to the entity analysis workspace for more detailed information.

    Extraction rule validation
    245.
    发明授权

    公开(公告)号:US11086890B1

    公开(公告)日:2021-08-10

    申请号:US16264525

    申请日:2019-01-31

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present invention are directed to validating extraction rules. In embodiments, a set of events for which field extraction is desired is obtained. Thereafter, an extraction rule is applied to the set of events to extract fields of the events. The application of the extraction rule can be monitored to determine that the applied extraction rule is invalid. Based on the applied extraction rule being invalid, a new extraction rule can be generated to apply to the set of events.

    Measuring mobile application program reliability caused by runtime errors

    公开(公告)号:US11074152B2

    公开(公告)日:2021-07-27

    申请号:US16888771

    申请日:2020-05-31

    Applicant: Splunk Inc.

    Abstract: A quality score for a computer application release is determined using a first number of unique users who have launched the computer application release on user devices and a second number of unique users who have encountered at least once an abnormal termination with the computer application release on user devices. Additionally or optionally, an application quality score can be computed for a computer application based on quality scores of computer application releases that represent different versions of the computer application. Additionally or optionally, a weighted application quality score can be computed for a computer application by further taking into consideration the average application quality score and popularity of a plurality of computer applications.

    Context-sensitive user interfaces in an information technology (IT) and security operations application

    公开(公告)号:US11061548B1

    公开(公告)日:2021-07-13

    申请号:US16657995

    申请日:2019-10-18

    Applicant: Splunk Inc.

    Abstract: An information technology (IT) and security operations application is described that stores data reflecting customizations that users make to GUIs displaying information about various types of incidents, and further uses such data to generate “popular” interface profiles indicating popular GUI modifications. The analysis of the GUI customizations data is performed using data associated with multiple tenants of the IT and security operations application to develop profiles that may represent a general consensus on a collection and arrangement of interface elements that enable analysts to efficiently respond to certain types of incidents. Users of the IT and security operations application can then optionally apply these popular interface profiles to various GUIs during their use of the application. Among other benefits, the ability to generate and provide popular interface profiles can help analysts and other users more efficiently investigate and respond to a wide variety of incidents within IT environments, thereby improving the operation and security of those environments.

Patent Agency Ranking