-
公开(公告)号:US10419450B2
公开(公告)日:2019-09-17
申请号:US14929037
申请日:2015-10-30
Applicant: Splunk Inc.
Inventor: Sudhakar Muddu , Christos Tryfonas
IPC: H04L9/00 , H04L29/06 , G06N20/00 , G06F16/25 , G06F16/28 , G06F16/44 , G06F16/901 , G06F16/2457 , G06N7/00 , G06F3/0482 , G06K9/20 , G06F3/0484 , H04L12/24 , H04L12/26 , G06F17/22 , G06N5/04 , G06N5/02
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
公开(公告)号:US10409668B2
公开(公告)日:2019-09-10
申请号:US15663513
申请日:2017-07-28
Applicant: Splunk Inc.
Inventor: Konstantinos Polychronis
Abstract: Various methods and systems for tracking incomplete purchases in correlation with application performance, such as application errors or crashes, are provided. In this regard, aspects of the invention facilitate monitoring transaction and application error events and analyzing data associated therewith to identify data indicating an impact of incomplete purchases in relation to an error(s) such that application performance can be improved. In various implementations, application data associated with an application installed on a mobile device is received. The application data is used to determine that an error that occurred in association with the application installed on the mobile device correlates with an incomplete monetary transaction initiated via the application. Based on the error correlating with the incomplete monetary transaction, a transaction attribute associated with the error is determined.
-
公开(公告)号:US10402384B2
公开(公告)日:2019-09-03
申请号:US15421127
申请日:2017-01-31
Applicant: SPLUNK INC.
IPC: G06F16/00 , G06F16/22 , G06F16/2453 , G06F16/33 , G06F16/242 , G06F16/248 , G06F16/28 , G06F16/31 , G06F16/338 , G06F16/23 , G06F16/2458 , G06F16/2455
Abstract: Embodiments are directed towards a method for searching data. The method comprises providing an inverted index that comprises at least one record, wherein the at least one record comprises at least one field name and a corresponding at least one field value. The at least one field name and corresponding value are extracted from time-stamped searchable events that are stored in a field searchable datastore and comprise portions of raw data. The at least one record further comprises a posting value that identifies a location in the field searchable datastore where an event associated with the at least one record is stored. The method further comprises receiving an incoming search query that references a field name and evaluating the incoming search query. Furthermore, responsive to the evaluating, the method comprises determining results for the incoming search query using the field searchable datastore or the inverted index.
-
公开(公告)号:US20190268446A1
公开(公告)日:2019-08-29
申请号:US16404644
申请日:2019-05-06
Applicant: Splunk Inc.
Inventor: Fang I. Hsiao , Clayton S. Ching , Michael R. Dickey , Vladimir A. Shcherbakov , Clint Sharp
Abstract: The disclosed embodiments provide a system for extracting custom content from network packets. During operation, the system receives a stream of packets. The system then parses packets in the stream to determine a protocol for each packet. Next, the system applies a custom-content-extraction rule to each packet associated with a target protocol to obtain the extracted content. Then, the system stores the extracted content in events in a data store to facilitate subsequent queries involving the extracted content.
-
公开(公告)号:US10394946B2
公开(公告)日:2019-08-27
申请号:US15694654
申请日:2017-09-01
Applicant: SPLUNK INC.
Inventor: Jesse Miller , Micah James Delfino , Marc Robichaud , Catherine Anne Hanson , David Carasso
IPC: G06F3/048 , G06F17/24 , G06F16/2458
Abstract: The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.
-
公开(公告)号:US20190260819A1
公开(公告)日:2019-08-22
申请号:US16397434
申请日:2019-04-29
Applicant: SPLUNK INC.
Inventor: Vijay Chauhan , Liu-Yuan Lai , Wenhui Yu , Luke Murphey , David Hazekamp
IPC: H04L29/08
Abstract: Provided are systems and methods for indicating deployment of application features. In one embodiment, a method is provided that includes determining available features of a current deployment of an application for receiving machine-generated data from one or more data sources of a data system, determining un-deployed features of the current deployment of the application, wherein the un-deployed features comprise one or more of the available features that is configured to use input data from a data source and wherein the input data is not available to the feature in the current deployment of the application, and causing display of a deployment graphical user interface (GUI) that comprises an indication of the un-deployed features.
-
公开(公告)号:US20190251099A1
公开(公告)日:2019-08-15
申请号:US16398104
申请日:2019-04-29
Applicant: Splunk Inc.
Inventor: Michael Joseph Baum , R. David Carasso , Robin Kumar Das , Bradley Hall , Brian Philip Murphy , Stephen Phillip Sorkin , Andre David Stechert , Erik M. Swan , Rory Greene , Nicholas Christian Mealy , Christina Frances Regina Noren
IPC: G06F16/28 , G06F16/2457 , G06K9/62 , G06F17/27 , G06F16/2455 , G06F16/2458 , G06F16/23 , G06F16/31 , G06F16/35 , H04L29/06
CPC classification number: G06F16/285 , G06F11/3476 , G06F16/2358 , G06F16/2455 , G06F16/24564 , G06F16/24573 , G06F16/2477 , G06F16/288 , G06F16/316 , G06F16/3331 , G06F16/35 , G06F17/2785 , G06F2216/03 , G06K9/6217 , H04L63/1425 , H04L63/20
Abstract: Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.
-
公开(公告)号:US10382599B2
公开(公告)日:2019-08-13
申请号:US15665268
申请日:2017-07-31
Applicant: Splunk Inc.
Inventor: Vladimir A. Shcherbakov , Michael Dickey
Abstract: The disclosed embodiments provide a system that processes network data. During operation, the system obtains, at a remote capture agent, a first protocol classification for a first packet flow captured by the remote capture agent. Next, the system uses configuration information associated with the first protocol classification to build a first event stream from the first packet flow at the remote capture agent, wherein the first event stream comprises time-series event data generated from network packets in the first packet flow based on the first protocol classification. The system then transmits the first event stream over a network for subsequent storage and processing of the first event stream by one or more components on the network.
-
公开(公告)号:US20190238635A1
公开(公告)日:2019-08-01
申请号:US15885690
申请日:2018-01-31
Applicant: SPLUNK, INC.
Inventor: Jonathan Ng , Thomas Haggie
CPC classification number: H04L67/1095 , G06F16/951 , H04L67/02
Abstract: A computerized method is disclosed. The method comprises detecting a change in a first webpage, constructing a search query based on the changed detected in the first webpage, determining a second webpage is associated with the first webpage, and synchronizing at least a portion of the second webpage with the first webpage based on the search query. The method may comprise updating a display of the first webpage based on the detected change. In certain embodiments of the method, detecting the change includes detecting input indicating one or more search parameters and the search query may be a text string including one or more alphanumeric characters. Additionally, the search query may comprise a pipelined command language. The synchronization of webpages displayed in separate tabs or windows of a web browser may use a browser extension to maintain state, as well as track and coordinate changes between the tabs or windows.
-
360.
公开(公告)号:US10353957B2
公开(公告)日:2019-07-16
申请号:US15421370
申请日:2017-01-31
Applicant: Splunk Inc.
Inventor: Brian Bingham , Tristan Fletcher , Alok Anant Bhide
IPC: G06F16/9038 , G06F16/26 , G06F11/32 , G06F11/34 , G06F9/455 , G06F16/901 , G06F16/903 , G06F3/0482 , G06F3/0488 , G06F16/9032
Abstract: The disclosed system and method acquire and store performance measurements relating to performance of a component in an information technology (IT) environment and log data produced by the IT environment, in association with corresponding time stamps. The disclosed system and method correlate at least one of the performance measurements with at least one of the portions of log data.
-
-
-
-
-
-
-
-
-