Object Score Adjustment Based on Analyzing Machine Data
    42.
    发明申请
    Object Score Adjustment Based on Analyzing Machine Data 审中-公开
    基于分析机器数据的对象分数调整

    公开(公告)号:US20160147769A1

    公开(公告)日:2016-05-26

    申请号:US14977432

    申请日:2015-12-21

    Applicant: Splunk Inc.

    Abstract: Systems and methods for assigning scores to objects based on evaluating triggering conditions applied to datasets produced by search queries in data aggregation and analysis systems. An example method may comprise: executing, by one or more processing devices, a search query to produce a dataset comprising one or more data items derived from source data; and responsive to determining that at least a portion of the dataset satisfies a triggering condition, modifying a score assigned to an object to which the portion of the dataset pertains.

    Abstract translation: 根据对数据汇总和分析系统中搜索查询产生的数据集的触发条件进行评估,为对象分配分数的系统和方法。 示例性方法可以包括:由一个或多个处理设备执行搜索查询以产生包括从源数据导出的一个或多个数据项的数据集; 并且响应于确定所述数据集的至少一部分满足触发条件,修改分配给所述数据集的所述部分所属对象的得分。

    Investigative and dynamic detection of potential security-threat indicators from events in big data
    43.
    发明授权
    Investigative and dynamic detection of potential security-threat indicators from events in big data 有权
    从大数据中的事件调查和动态检测潜在的安全威胁指标

    公开(公告)号:US09215240B2

    公开(公告)日:2015-12-15

    申请号:US13956252

    申请日:2013-07-31

    Applicant: Splunk Inc.

    Abstract: A metric value is determined for each event in a set of events that characterizes a computational communication or object. For example, a metric value could include a length of a URL or agent string in the event. A subset criterion is generated, such that metric values within the subset are relatively separated from a population's center (e.g., within a distribution tail). Application of the criterion to metric values produces a subset. A representation of the subset is presented in an interactive dashboard. The representation can include unique values in the subset and counts of corresponding event occurrences. Clients can select particular elements in the representation to cause more detail to be presented with respect to individual events corresponding to specific values in the subset. Thus, clients can use their knowledge system operations and observance of value frequencies and underlying events to identify anomalous metric values and potential security threats.

    Abstract translation: 为表征计算通信或对象的一组事件中的每个事件确定度量值。 例如,度量值可以包括事件中的URL或代理字符串的长度。 生成子集标准,使得子集内的度量值与群体的中心(例如,分布尾部)相对分开。 将标准应用于度量值产生一个子集。 该子集的表示呈现在交互式仪表板中。 该表示可以包括子集中的唯一值和相应事件发生的计数。 客户端可以选择表示中的特定元素,以便相对于子集中的特定值对应的各个事件来呈现更多的细节。 因此,客户可以使用他们的知识系统操作和遵守价值频率和基础事件来识别异常度量值和潜在的安全威胁。

Patent Agency Ranking