IP Library Granted Patent US 11,036,567
Granted Patent B2
US 11,036,567 · App. 16/399,136 · Granted Jun 15, 2021

Determining system behavior using event patterns in machine data

Inventors: Michael Joseph Baum (Ross, CA); R. David Carasso (San Rafael, CA); Robin Kumar Das (Healdsburg, CA); Bradley Hall (Palo Alto, CA); Brian Philip Murphy (London, GB); Stephen Phillip Sorkin (San Francisco, CA); Andre David Stechert (Brooklyn, NY); Erik M. Swan (Piedmont, CA); Rory Greene (San Francisco, CA); Nicholas Christian Mealy (Oakland, CA); Christina Frances Regina Noren (San Francisco, CA)
Assignee: Splunk Inc.
G06F9/542G06F9/54G06F9/541
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,036,567
App. No.
16/399,136
Filed
Apr 30, 2019
Granted
Jun 15, 2021
Kind
B2
Art Unit
2198
USPC
719/318
Abstract

Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.

Claims (68)

1. A method, comprising:

receiving machine data from two or more components in an information technology environment, the machine data reflecting activity in the information technology environment;

identifying, in real-time, a first behavioral pattern between a first plurality of events from first machine data from a first component of the two or more components and a second behavioral pattern between a second plurality of events from second machine data from a second component of the two or more components;

identifying a first event from the first plurality of events from the first machine data and a second event from the second plurality of events from the second machine data;

determining a third behavioral pattern between the first event and the second event based on a co-occurrence of the first event and the second event within a time window;

identifying, in real-time, an associative relationship between the first behavioral pattern and the second behavioral pattern based on the third behavioral pattern;

determining that the associative relationship represents typical system behavior in the information technology environment; and

sending information associated with the associative relationship to a computing system;

wherein the method is performed by one or more computing devices.

2. The method as recited in claim 1 , wherein the typical system behavior identifies typical system processes.

3. The method as recited in claim 1 , wherein the typical system behavior identifies relationships between the first plurality of events from the first machine data and the second plurality of events from the second machine data.

4. The method as recited in claim 1 , wherein the typical system behavior identifies relationships between the first plurality of events from the first machine data and the second plurality of events from the second machine data, wherein the first plurality of events and the second plurality of events co-occur within the time window.

5. The method as recited in claim 1 , wherein the typical system behavior identifies that the first plurality of events and the second plurality of events are connected as part of a larger activity in the information technology environment.

6. The method as recited in claim 1 , wherein the first machine data from the first component has a different data format than the second machine data from the second component.

7. The method as recited in claim 1 , the method further comprising:

determining a number of occurrences of the third behavioral pattern, and

determining that the number of occurrences satisfies a threshold;

wherein identifying the associative relationship is based at least in part on determining that the number of occurrences satisfies the threshold.

8. The method as recited in claim 1 , wherein the identifying the first behavioral pattern and the second behavioral pattern comprises:

analyzing the first machine data from the first component to identify a first relationship between the first event and a third event from the first machine data; and

analyzing the second machine data from the second component to identify a second relationship between the second event and a fourth event from the second machine data.

9. The method as recited in claim 1 , wherein the identifying the first behavioral pattern and the second behavioral pattern comprises:

analyzing the first machine data from the first component to identify a first relationship between the first event and a third event from the first machine data;

linking the first event and the third event based at least in part on the first relationship;

analyzing the second machine data from the second component to identify a second relationship between the second event and a fourth event from the second machine data; and

linking the second event and the fourth event based at least in part on the second relationship.

10. The method as recited in claim 1 , further comprising:

analyzing the first machine data in order to segment the first machine data into the first plurality of events by determining a beginning and ending of each event in the first plurality of events from the first machine data, each event in the first plurality of events including a portion of the first machine data segmented for that event; and

analyzing the second machine data in order to segment the second machine data into the second plurality of events by determining a beginning and ending of each event in the second plurality of events from the second machine data, each event in the second plurality of events including a portion of the second machine data segmented for that event.

11. The method as recited in claim 1 , further comprising:

analyzing the first machine data in order to segment the first machine data into the first plurality of events by determining a beginning and ending of each event in the first plurality of events from the first machine data, each event in the first plurality of events including a portion of the first machine data segmented for that event;

associating a first time stamp with each event in the first plurality of events, the first time stamp derived from the portion of the first machine data segmented for that event;

analyzing the second machine data in order to segment the second machine data into the second plurality of events by determining a beginning and ending of each event in the second plurality of events from the second machine data, each event in the second plurality of events including a portion of the second machine data segmented for that event; and

associating a second time stamp with each event in the second plurality of events, the second time stamp derived from the portion of the second machine data segmented for that event.

12. One or more non-transitory computer-readable storage media, storing one or more sequences of instructions, which when executed by one or more processors cause the one or more processors to:

receive machine data from two or more components in an information technology environment, the machine data reflecting activity in the information technology environment;

identify, in real-time, a first behavioral pattern between a first plurality of events from first machine data from a first component of the two or more components and a second behavioral pattern between a second plurality of events from second machine data from a second component of the two or more components;

identify a first event from the first plurality of events from the first machine data and a second event from the second plurality of events from the second machine data;

determine a third behavioral pattern between the first event and the second event based on a co-occurrence of the first event and the second event within a time window;

identify, in real-time, an associative relationship between the first behavioral pattern and the second behavioral pattern based on the third behavioral pattern;

determine that the associative relationship represents typical system behavior in the information technology environment; and

send information associated with the associative relationship to a computing system.

13. The one or more non-transitory computer-readable storage media as recited in claim 12 , wherein the typical system behavior identifies typical system processes.

14. The one or more non-transitory computer-readable storage media as recited in claim 12 , wherein the typical system behavior identifies relationships between the first plurality of events from the first machine data and the second plurality of events from the second machine data.

15. The one or more non-transitory computer-readable storage media as recited in claim 12 , wherein the typical system behavior identifies relationships between the first plurality of events from the first machine data and the second plurality of events from the second machine data, wherein the first plurality of events and the second plurality of events co-occur within the time window.

16. The one or more non-transitory computer-readable storage media as recited in claim 12 , wherein the typical system behavior identifies that the first plurality of events and the second plurality of events are connected as part of a larger activity in the information technology environment.

17. The one or more non-transitory computer-readable storage media as recited in claim 12 , wherein execution of the one or more sequences of instructions by the one or more processors further causes the one or more processors to:

determine a number of occurrences of the third behavioral pattern, and

determine that the number of occurrences satisfies a threshold;

wherein identifying the associative relationship is based at least in part on determining that the number of occurrences satisfies the threshold.

18. The one or more non-transitory computer-readable storage media as recited in claim 12 , wherein to identify the first behavioral pattern and the second behavioral pattern, execution of the one or more sequences of instructions by the one or more processors further causes the one or more processors to:

analyze the first machine data from the first component to identify a first relationship between the first event and a third event from the first machine data; and

analyze the second machine data from the second component to identify a second relationship between the second event and a fourth event from the second machine data.

19. The one or more non-transitory computer-readable storage media as recited in claim 12 , wherein execution of the one or more sequences of instructions by the one or more processors further causes the one or more processors to:

analyze the first machine data in order to segment the first machine data into the first plurality of events by determining a beginning and ending of each event in the first plurality of events from the first machine data, each event in the first plurality of events including a portion of the first machine data segmented for that event;

associate a first time stamp with each event in the first plurality of events, the first time stamp derived from the portion of the first machine data segmented for that event;

analyze the second machine data in order to segment the second machine data into the second plurality of events by determining a beginning and ending of each event in the second plurality of events from the second machine data, each event in the second plurality of events including a portion of the second machine data segmented for that event; and

associate a second time stamp with each event in the second plurality of events, the second time stamp derived from the portion of the second machine data segmented for that event.

20. An apparatus, comprising:

one or more processors; and

a memory storing instructions, which when executed by the one or more processors, causes the one or more processors to:

receive machine data from two or more components in an information technology environment, the machine data reflecting activity in the information technology environment;

identify, in real-time, a first behavioral pattern between a first plurality of events from first machine data from a first component of the two or more components and a second behavioral pattern between a second plurality of events from second machine data from a second component of the two or more components;

identify a first event from the first plurality of events from the first machine data and a second event from the second plurality of events from the second machine data;

determine a third behavioral pattern between the first event and the second event based on a co-occurrence of the first event and the second event within a time window;

identify, in real-time, an associative relationship between the first behavioral pattern and the second behavioral pattern based on the third behavioral pattern;

determine that the associative relationship represents typical system behavior in the information technology environment; and

send information associated with the associative relationship to a computing system.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2019
From: BAUM, MICHAEL JOSEPH; CARASSO, R. DAVID; DAS, ROBIN KUMAR; HALL, BRADLEY; MURPHY, BRIAN PHILIP; SORKIN, STEPHEN PHILLIP; STECHERT, ANDRE DAVID; SWAN, ERIK M.; GREENE, RORY; MEALY, NICHOLAS CHRISTIAN; NOREN, CHRISTINA
To: SPLUNK INC.
Reel/Frame 049056/0501 →
Continuity (8)
Continuation 15011622 · Jan 31, 2016
Continuation 14611188 · Jan 31, 2015
Continuation 14170228 · Jan 31, 2014
Continuation 13664109 · Oct 30, 2012
Continuation 13099268 · May 2, 2011
Continuation 11459632 · Jul 24, 2006
Provisional Application 60702496 · Jul 25, 2005
Related Publication 20190258649A1 · Aug 22, 2019