IP Library › Granted Patent US 12,079,100
Granted Patent B1
US 12,079,100 · App. 17/589,847 · Granted Sep 3, 2024

Systems and methods for machine-learning based alert grouping and providing remediation recommendations

Inventors: William Deaderick (Austin, TX); William Stanton (Boulder, CO); Thomas Camp Vieth (Cambridge, MA)
Assignee: Splunk Inc.
G06F11/3082G06F11/0793G06F11/3409G06F16/2477G06F16/244
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,079,100
App. No.
17/589,847
Filed
Jan 31, 2022
Granted
Sep 3, 2024
Kind
B1
Art Unit
2113
USPC
709/224
Abstract

A computerized method is disclosed for grouping alerts and providing remediation recommendation. The method includes receiving the alert to be assigned to an existing open issue or a newly created issue, wherein an issue is a grouping of one or more alerts, assigning the alert to either a first existing open issue or the newly created issue by determining a weighted sum of the distance between the feature vectors of the alert and each existing open issue, determining a weighted sum of the distance between the feature vectors of the alert and each closed issue, and generating a user interface that illustrates an assignment of the alert and at least one of (i) a closed issue having a shortest distance to the alert or (ii) recommended remediation efforts associated with the closed issue having the shortest distance to the alert.

Claims (43)

1. A computerized method comprising:

generating a user interface that illustrates assignments of a plurality of alerts into one or more alert groupings that are positioned so that each alert grouping of the one or more of alert groupings is positioned at different regions of a dashboard produced by the user inferface, wherein an alert grouping is a grouping of one or more alerts;

receiving user feedback via the user interface indicating that a first alert grouping of the one or more alert groupings is to be closed such that alerts may no longer be assigned to the first alert grouping;

subsequent to receiving the user feedback closing the first alert grouping, receiving an alert to be assigned to any of a plurality of existing open alert groupings or to a newly created alert grouping;

assigning the alert through deployment of a machine learning model implementing a distance metric to either a first existing open alert grouping of the plurality of existing open alert groupings or the newly created alert grouping, wherein the distance metric includes a set of weightings determined for a feature vector of the alert, and wherein assigning the alert is based on an overall distance between the feature vector of the alert and a feature vector of each of the plurality of existing open alert groupings according to a weighted sum of the distance between the feature vector of the alert and the feature vector of each of the plurality of existing open alert groupings, wherein the alert is assigned to either (i) an existing open alert grouping having a shortest overall distance to the alert that satisfies one or more time constraints, or (ii) the newly created alert grouping;

determining (i) that the first alert grouping, which is closed, has a shortest distance to the alert and (ii) a remediation effort taken that resulted in resolution of an incident indicated by the first alert grouping; and

updating the user interface resulting in illustrating (i) an assignment of the alert, (ii) the first alert grouping having the shortest distance to the alert and (iii) an instruction to a viewer on the remediation effort taken to resolve the incident indicated by the first alert grouping.

2. The computerized method of claim 1 , wherein the remediation effort includes one or more remediation efforts taken to resolve the incident causing generation of alerts assigned to the first alert grouping having the shortest distance to the alert.

3. The computerized method of claim 1 , wherein determining the first alert grouping having the shortest distance to the alert includes determining the overall distance between a feature vector of the alert and a feature vector of each of the plurality of existing open alert groupings based on the weighted sum of a weighted sum of the distance between the feature vector of the alert and the feature vector of each of the plurality of existing open alert groupings includes:

determining a temporal distance between the alert and each of the plurality of existing open alert groupings,

determining either of (i) a numerical distance between the alert and each of the plurality of existing open alert groupings for a particular numerical field, or (ii) a categorical distance between the alert and each of the plurality of existing open alert groupings for a particular categorical field, and

determining a weighted sum of the temporal distance and either at least one of (i) the numerical distance or (ii) the categorical distance.

4. The computerized method of claim 1 , wherein satisfying the one or more time constraints includes satisfying either of a first constraint or a second time constraint, wherein the first time constraint includes a maximum allowable elapsed time for the temporal distance and the second constraint includes a maximum sue-alert grouping time length of the first existing open alert grouping.

5. The computerized method of claim 1 , wherein the feature vector of the alert includes a feature corresponding to each of a temporal field and at least one of (i) a numerical field or (ii) a categorical field.

6. A computing device, comprising:

one or more processors; and

a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including:

generating a user interface that illustrates assignments of a plurality of alerts into one or more alert groupings that are positioned so that each alert grouping of the one or more of alert groupings is positioned at different regions of a dashboard produced by the user interface, wherein an alert grouping is a grouping of one or more alerts;

receiving user feedback via the user interface indicating that a first alert grouping of the one or more alert groupings is to be closed such that alerts may no longer be assigned to the first alert grouping;

subsequent to receiving the user feedback closing the first alert grouping, receiving an alert to be assigned to any of a plurality of existing open alert groupings or to a newly created alert grouping;

assigning the alert through deployment of a machine learning model implementing a distance metric to either a first existing open alert grouping of the plurality of existing open alert groupings or the newly created alert grouping, wherein the distance metric includes a set of weightings determined for a feature vector of the alert, and wherein assigning the alert is based on an overall distance between the feature vector of the alert and a feature vector of each of the plurality of existing open alert groupings according to a weighted sum of the distance between the feature vector of the alert and the feature vector of each of the plurality of existing open alert groupings, wherein the alert is assigned to either (i) an existing open alert grouping having a shortest overall distance to the alert that satisfies one or more time constraints, or (ii) the newly created alert grouping;

determining (i) that the first alert grouping, which is closed, has a shortest distance to the alert and (ii) a remediation effort taken that resulted in resolution of an incident indicated by the first alert grouping; and

updating the user interface resulting in illustrating (i) an assignment of the alert, (ii) the first alert grouping having the shortest distance to the alert and (iii) an instruction to a viewer on the remediation effort taken to resolve the incident indicated by the first alert grouping.

7. The computing device of claim 6 , wherein the remediation effort includes one or more remediation efforts taken to resolve the incident causing generation of alerts assigned to the first alert grouping having the shortest distance to the alert.

8. The computing device of claim 6 , determining the first alert grouping having the shortest distance to the alert includes determining the overall distance between a feature vector of the alert and a feature vector of each of the plurality of existing open alert groupings based on the weighted sum of a weighted sum of the distance between the feature vector of the alert and the feature vector of each of the plurality of existing open alert groupings includes:

determining a temporal distance between the alert and each of the plurality of existing open alert groupings,

determining either of (i) a numerical distance between the alert and each of the plurality of existing open alert groupings for a particular numerical field, or (ii) a categorical distance between the alert and each of the plurality of existing open alert groupings for a particular categorical field, and

determining a weighted sum of the temporal distance and either at least one of (i) the numerical distance or (ii) the categorical distance.

9. The computing device of claim 6 , wherein satisfying the one or more time constraints includes satisfying either of a first constraint or a second time constraint, wherein the first time constraint includes a maximum allowable elapsed time for the temporal distance and the second constraint includes a maximum alert grouping time length of the first existing open alert grouping.

10. The computing device of claim 6 , wherein the feature vector of the alert includes a feature corresponding to each of a temporal field and at least one of (i) a numerical field or (ii) a categorical field.

11. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to perform operations including:

generating a user interface that illustrates assignments of a plurality of alerts into one or more alert groupings that are positioned so that each alert grouping of the one gr more of alert groupings is positioned at different regions of a dashboard produced by the user interface, wherein an alert grouping is a grouping of one or more alerts;

receiving user feedback via the user interface indicating that a first alert grouping of the one or more alert groupings is to be closed such that alerts may no longer be assigned to the first alert grouping;

subsequent to receiving the user feedback closing the first alert grouping, receiving an alert to be assigned to any of a plurality of existing open alert groupings or to a newly created alert grouping;

assigning the alert through deployment of a machine learning model implementing a distance metric to either a first existing open alert grouping of the plurality of existing open alert groupings or the newly created alert grouping, wherein the distance metric includes a set of weightings determined for a feature vector of the alert, and wherein assigning the alert is based on an overall distance between the feature vector of the alert and a feature vector of each of the plurality of existing open alert groupings according to a weighted sum of the distance between the feature vector of the alert and the feature vector of each of the plurality of existing open alert groupings, wherein the alert is assigned to either (i) an existing open alert grouping having a shortest overall distance to the alert that satisfies one or more time constraints, or (ii) the newly created alert grouping;

determining (i) that the first alert grouping, which is closed, has a shortest distance to the alert and (ii) a remediation effort taken that resulted in resolution of an incident indicated by the first alert grouping; and

updating the user interface resulting in illustrating (i) an assignment of the alert, (ii) the first alert grouping having the shortest distance to the alert and (iii) an instruction to a viewer on the remediation effort taken to resolve the incident indicated by the first alert grouping.

12. The non-transitory computer-readable medium of claim 11 , wherein the remediation effort includes one or more remediation efforts taken to resolve the incident causing generation of alerts assigned to the first alert grouping having the shortest distance to the alert.

13. The non-transitory computer-readable medium of claim 11 , wherein determining the first alert grouping having the shortest distance to the alert includes determining the overall distance between a feature vector of the alert and a feature vector of each of the plurality of existing open alert groupings based on the weighted sum of a weighted sum of the distance between the feature vector of the alert and the feature vector of each of the plurality of existing open alert groupings includes:

determining a temporal distance between the alert and each of the plurality of existing open alert groupings,

determining either of (i) a numerical distance between the alert and each of the plurality of existing open alert groupings for a particular numerical field, or (ii) a categorical distance between the alert and each of the plurality of existing open alert groupings for a particular categorical field, and

determining a weighted sum of the temporal distance and either at least one of (i) the numerical distance or (ii) the categorical distance.

14. The non-transitory computer-readable medium of claim 11 , wherein satisfying the one or more time constraints includes satisfying either of a first constraint or a second time constraint, wherein the first time constraint includes a maximum allowable elapsed time for the temporal distance and the second constraint includes a maximum alert grouping time length of the first existing open alert grouping.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2023
From: DEADERICK, WILLIAM; STANTON, WILLIAM; VIETH, THOMAS CAMP
To: SPLUNK INC.
Reel/Frame 065126/0737 →
Continuity (1)
Division 17589532 · Jan 31, 2022
Cited By (1)
US 12,748,417