IP Library Granted Patent US 11,816,108
Granted Patent B1
US 11,816,108 · App. 17/805,095 · Granted Nov 14, 2023

Dynamic alert messages using tokens based on searching events

Inventors: Nicholas John Filippi (Atherton, CA); Katherine Kyle Feeney (Oakland, CA); Cory Eugene Burke (San Bruno, CA); Abhinav Prasad Nekkanti (Daly City, CA); Marc Vincent Robichaud (San Francisco, CA); Irina Korobova (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/24565G06F9/542G06F11/00G06F11/0709G06F11/0751G06F11/0766G06F16/9536G06Q10/00H04L41/00H04L41/0631G06F16/00G06F16/254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,816,108
App. No.
17/805,095
Granted
Nov 14, 2023
Kind
B1
Abstract

Custom communication alert techniques are described. In one or more implementations, a triggering condition is detected by one or more computing devices that is found by searching data using one or more extraction rules of a late-binding schema. Responsive to the detection of the triggering condition of the alert, a communication is formed by the one or more computing devices that corresponds to the alert and that includes one or more tokens based on one or more values of the data taken from fields defined by the one or more extraction rules. The communication is caused to be transmitted by the one or more computing device via a network for receipt by at least one computing device of an intended recipient of the communication.

Claims (33)

1. A computer-implemented method, comprising:

receiving, from a user interface, an assignment of one or more tokens for use in generating a message for an alert, the one or more tokens defining first one or more values generated from second one or more values of one or more fields of search results of a search query, wherein a triggering condition of the alert is evaluated against the search results during execution of the search query, the execution determining the search results as a subset of events that meet criteria specified by the search query,

wherein the search query is performed on the events in a data store, an event of the events including a portion of raw machine data associated with a timestamp,

wherein the criteria specified by the search query includes at least a field of the one or more fields, the field defined by an extraction rule for extracting a subportion of text from the portion of raw machine data in the event to produce a value of the second one or more values for the field for the event; and

based at least on the triggering condition being satisfied, causing display of the message including the first one or more values of the one or more tokens on a user device associated with the alert.

2. The computer-implemented method of claim 1 , wherein the assignment of the one or more tokens is specified in the user interface based on user input placing a representation of the one or more tokens in a message field for the message.

3. The computer-implemented method of claim 1 , wherein the assignment of the one or more tokens is specified in the user interface based on user input placing a placeholder for the first one or more values of the token at a location within static verbiage of the message.

4. The computer-implemented method of claim 1 , wherein the one or more fields include multiple fields and a value of the first one or more values for a token of the tokens is generated from a combination of values from the multiple fields.

5. The computer-implemented method of claim 1 , wherein the first one or more values specify a recipient of the message using the second one or more values taken from the one or more fields.

6. The computer-implemented method of claim 1 , wherein the first one or more values are included in a subject line of the message.

7. The computer-implemented method of claim 1 , wherein the first one or more values describe one or more of a search that triggered the alert, a severity level of the alert, a quantity of the search results, a link via which one or more portions of the search results may be viewed, an absolute path to a results file comprising the search results, or a search identifier of a search that triggered the alert.

8. The computer-implemented method of claim 1 , wherein the triggering condition is determined to be satisfied based on a continual evaluation of the triggering condition against the search results of the search query during execution of the search query.

9. The computer-implemented method of claim 1 , wherein the triggering condition specifies an amount of the search results that are to be found during the execution of the search query in order to trigger the alert.

10. A computer-implemented system comprising:

one or more processors, and one or more computer memory to store instructions, the instructions when executed by the one or more processors to perform operations comprising:

receiving, from a user interface, an assignment of one or more tokens for use in generating a message for an alert, the one or more tokens defining first one or more values generated from second one or more values of one or more fields of search results of a search query, wherein a triggering condition of the alert is evaluated against the search results during execution of the search query, the execution determining the search results as a subset of events that meet criteria specified by the search query,

wherein the search query is performed on the events in a data store, an event of the events including a portion of raw machine data associated with a timestamp,

wherein the criteria specified by the search query includes at least a field of the one or more fields, the field defined by an extraction rule for extracting a subportion of text from the portion of raw machine data in the event to produce a value of the second one or more values for the field for the event; and

based at least on the triggering condition being satisfied, causing display of the message including the first one or more values of the one or more tokens on a user device associated with the alert.

11. The computer-implemented system of claim 10 , wherein the assignment of the one or more tokens is specified in the user interface based on user input placing a representation of the one or more tokens in a message field for the message.

12. The computer-implemented system of claim 10 , wherein the assignment of the one or more tokens is specified in the user interface based on user input placing a placeholder for the first one or more values of the token at a location within static verbiage of the message.

13. The computer-implemented system of claim 10 , wherein the one or more fields include multiple fields and a value of the first one or more values for a token of the tokens is generated from a combination of values from the multiple fields.

14. The computer-implemented system of claim 10 , wherein the first one or more values specify a recipient of the message using the second one or more values taken from the one or more fields.

15. The computer-implemented system of claim 10 , wherein the first one or more values are included in a subject line of the message.

16. One or more computer-readable storage media comprising instructions stored thereon that, responsive to execution by one or more computing devices, causes the one or more computing devices to perform operations comprising:

receiving, from a user interface, an assignment of one or more tokens for use in generating a message for an alert, the one or more tokens defining first one or more values generated from second one or more values of one or more fields of search results of a search query, wherein a triggering condition of the alert is evaluated against the search results during execution of the search query, the execution determining the search results as a subset of events that meet criteria specified by the search query,

wherein the search query is performed on the events in a data store, an event of the events including a portion of raw machine data associated with a timestamp,

wherein the criteria specified by the search query includes at least a field of the one or more fields, the field defined by an extraction rule for extracting a subportion of text from the portion of raw machine data in the event to produce a value of the second one or more values for the field for the event; and

based at least on the triggering condition being satisfied, causing display of the message including the first one or more values of the one or more tokens on a user device associated with the alert.

17. The one or more computer-readable storage media of claim 16 , wherein the assignment of the one or more tokens is specified in the user interface based on user input placing a representation of the one or more tokens in a message field for the message.

18. The one or more computer-readable storage media of claim 16 , wherein the assignment of the one or more tokens is specified in the user interface based on user input placing a placeholder for the first one or more values of the token at a location within static verbiage of the message.

19. The one or more computer-readable storage media of claim 16 , wherein the one or more fields include multiple fields and a value of the first one or more values for a token of the tokens is generated from a combination of values from the multiple fields.

20. The one or more computer-readable storage media of claim 16 , wherein the first one or more values specify a recipient of the message using the second one or more values taken from the one or more fields.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2022
From: FILIPPI, NICHOLAS JOHN; FEENEY, KATHERINE KYLE; BURKE, CORY EUGENE; NEKKANTI, ABHINAV PRASAD; ROBICHAUD, MARC VINCENT; KOROBOVA, IRINA
To: SPLUNK INC.
Reel/Frame 060085/0650 →
Continuity (3)
Continuation 16260998 · Jan 29, 2019
Continuation 14528905 · Oct 30, 2014
Provisional Application 62058952 · Oct 2, 2014