Integration of cloud-based and non-cloud-based data in a data intake and query system

    公开(公告)号:US12197442B1

    公开(公告)日:2025-01-14

    申请号:US17937902

    申请日:2022-10-04

    Applicant: Splunk Inc.

    Abstract: A software module ingests data into a data intake and query system. At least a portion of the data is cloud data. The software module includes an event type definition that specifies a type of data to be ingested by the software module, a first tag that associates ingested data of the event type with a data model, and a second tag that designates ingested data of the event type as cloud data. The ingested data is stored in a data repository, and subsequently a search query that includes the first tag and the second tag is executed against the data repository, to identify ingested cloud data that satisfies the search query and a first search constraint specified in the data model. A display device is caused to display a visualization based on the identified ingested cloud data that satisfies the search query.

    Generating information technology incident risk score narratives

    公开(公告)号:US12135788B1

    公开(公告)日:2024-11-05

    申请号:US17390290

    申请日:2021-07-30

    Applicant: Splunk Inc.

    Abstract: Techniques are described for enabling an application to automatically generate text narratives explaining risk scores assigned to risk objects. The application uses natural language generation (NLG) techniques to enable the automatic create text narratives providing context and explanation for risk scores. The described approaches use data from a variety of data sources (e.g., risk event indexes, correlation search data, attack framework data, etc.) to create compelling and useful explanations of the risk analysis associated with identified risk objects. These automatically generated text narratives can be readily presented in any number of different interfaces without the need for complex visualizations or user effort to derive the same information. The automatically created text narratives enable users to better understand the risk analysis for particular risk objects, obtain storylines detailing risk objects' activity patterns over time, and to better analyze, triage, and mitigate IT environment risks based on such information.

    Artifact life tracking storage
    456.
    发明授权

    公开(公告)号:US12135710B2

    公开(公告)日:2024-11-05

    申请号:US17586634

    申请日:2022-01-27

    Applicant: Splunk Inc.

    Abstract: Artifact life tracking storage techniques include performing an artifact request of an artifact at an artifact storage node. A current time to live (TTL) value is identified. A determination is made whether to increment a TTL flag of the artifact. Responsive to determining that the TTL tag should be incremented, the TTL flag is incremented to a subsequent value in a TTL extender list. Responsive to incrementing the TTL tag, the TTL modified tag value is set to the current time value.

    Creating a correlation search
    459.
    发明授权

    公开(公告)号:US12130866B1

    公开(公告)日:2024-10-29

    申请号:US17114423

    申请日:2020-12-07

    Applicant: Splunk Inc.

    CPC classification number: G06F16/90335 G06F16/9032 G06F16/906 G06F16/907

    Abstract: One or more processing devices receive a definition of a search query for a correlation search of a data store, the data store comprising time-stamped events that each include raw machine data reflecting activity in an information technology environment and produced by a component of the information technology environment, receive a definition of a triggering condition to be evaluated based on aggregated statistics of values of one or more fields of a dataset produced by the search query, receive a definition of one or more actions to be performed when the triggering condition is satisfied, generate, using search processing language, a statement to define the search query and the triggering condition, and in view of the results of the execution of the search processing language, cause generation of the correlation search using the defined search query, the triggering condition, and the one or more actions, the correlation search comprising updated search processing language having the search query and a processing command for criteria on which the triggering condition is based.

Patent Agency Ranking