IP Library Granted Patent US 11,928,242
Granted Patent B2
US 11,928,242 · App. 17/128,522 · Granted Mar 12, 2024

Masking personally identifiable information from machine-generated data

Inventors: Adam Oliner (San Francisco, CA); Nghi Nguyen (San Francisco, CA)
Assignee: Splunk Inc.
G06F21/6254G06F16/2477
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,928,242
App. No.
17/128,522
Granted
Mar 12, 2024
Kind
B2
Abstract

Implementations include receiving a user provided example value of personally identifiable information (PII). Occurrences of the received example value are automatically identified in a dataset of events, wherein each occurrence is identified in a portion of raw machine data of a respective event of the events. For each occurrence of the identified occurrences, an extraction rule is generated, which defines a pattern of the occurrence of the example value and is executable to identify PII values in portions of raw machine data of the events using the pattern. Values of the PII are identified in a set of events using a set of extraction rules comprising the extraction rule of a plurality of the occurrences.

Claims (34)

1. A computer-implemented method, comprising:

identifying one or more occurrences of a particular value in a set of events, each event including machine data associated with a timestamp, wherein an occurrence represents a location of the particular value within the machine data of an event;

determining a set of extraction rules from the one or more occurrences, wherein each extraction rule defines a pattern that identifies values in other events that are of a same type of information as the particular value and that match the pattern;

identifying, using the set of extraction rules, a plurality of events that include the values in the other events; and

masking the values in the machine data included in the plurality of events, the values to mask being identified using the set of extraction rules that define different fields in the plurality of events, wherein masking obscures the values from the machine data in accordance with a query having one or more commands executable to mask the values from the machine data included in the plurality of events.

2. The method of claim 1 , wherein the same type of information is personally identifiable information (PII).

3. The method of claim 1 , wherein the masking includes replacing text in the machine data of the plurality of events.

4. The method of claim 1 , wherein the masking includes obscuring text in a graphical display of the machine data of the plurality of events.

5. The method of claim 1 , wherein the masking includes displaying a graphical indicator in place of one or more characters of the machine data of the plurality of events.

6. The method of claim 1 , wherein the masking is performed based at least on one or more permissions, roles, or account types associated with a user accessing the machine data of the plurality of events.

7. The method of claim 1 , wherein the masking comprise s anonymizing the values and the method further comprises causing display in a user interface of at least one of the plurality of events with the anonymized values.

8. The method of claim 1 , further comprising identifying and removing duplicates from the set of extraction rules prior to the masking.

9. The method of claim 1 , wherein the masking is performed based at least on identifying a label assigned to the set of extraction rules in a query.

10. A computer-implemented system comprising:

one or more processors; and

computer memory having instructions stored thereon, the instructions, when executed by the one or more processors causing the system to perform a method comprising:

identifying one or more occurrences of a particular value in a set of events, each event including machine data associated with a timestamp, wherein an occurrence represents a location of the particular value within the machine data of an event;

determining a set of extraction rules from the one or more occurrences, wherein each extraction rule defines a pattern that identifies values in other events that are of a same type of information as the particular value and that match the pattern;

identifying, using the set of extraction rules, a plurality of events that include the values in the other events; and

masking the values in the machine data included in the plurality of events, the values to mask being identified using the set of extraction rules that define different fields in the plurality of events, wherein masking obscures the values from the machine data in accordance with a query having one or more commands executable to mask the values from the machine data included in the plurality of events.

11. The system of claim 10 , wherein the same type of information is personally identifiable information (PII).

12. The system of claim 10 , wherein the masking includes replacing text in portions of raw machine data.

13. The system of claim 10 , wherein the masking includes obscuring text in a graphical display of portions of raw machine data.

14. The system of claim 10 , wherein the masking includes displaying a graphical indicator in place of one or more characters of text.

15. The system of claim 10 , wherein the masking is performed based at least on one or more permissions, roles, or account types associated with a user accessing portions of raw machine data.

16. One or more non-transitory computer-readable media having instructions stored thereon, the instructions, when executed by a processor of a computing device, to cause the computing device to perform a method comprising:

identifying one or more occurrences of a particular value in a set of events, each event including machine data associated with a timestamp, wherein an occurrence represents a location of the particular value within the machine data of an event;

determining a set of extraction rules from the one or more occurrences, wherein each extraction rule defines a pattern that identifies values in other events that are of a same type of information as the particular value and that match the pattern;

identifying, using the set of extraction rules, a plurality of events that include the values in the other events; and

masking the values in the machine data included in the plurality of events, the values to mask being identified using the set of extraction rules that define different fields in the plurality of events, wherein masking obscures the values from the machine data in accordance with a query having one or more commands executable to mask the values from the machine data included in the plurality of events.

17. The one or more non-transitory computer readable media of claim 16 , wherein the same type of information is personally identifiable information (PII).

18. The one or more non-transitory computer readable media of claim 16 , wherein the masking includes replacing the text in the machine data of the plurality of events.

19. The one or more non-transitory computer readable media of claim 16 , wherein the masking includes obscuring text in a graphical display of the machine data of the plurality of events.

20. The one or more non-transitory computer readable media of claim 16 , wherein the masking includes displaying a graphical indicator in place of one or more characters of the machine data of the plurality of events.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2020
From: NGUYEN, NGHI; OLINER, ADAM
To: SPLUNK INC.
Reel/Frame 054707/0647 →
Continuity (2)
Continuation 15582465 · Apr 28, 2017
Related Publication 20210110062A1 · Apr 15, 2021