IP Library Granted Patent US 12,574,403
Granted Patent B2
US 12,574,403 · App. 18/740,314 · Granted Mar 10, 2026

Automatic creation and updating of event group summaries

Inventors: John Coates (Berkeley, CA); Lucas Murphey (Wadsworth, IL); David Hazekamp (Tinley Park, IL); James Hansen (San Ramon, CA)
Assignee: Cisco Technology, Inc.
H04L63/1433G06F16/285G06F21/554H04L63/14H04L63/1408H04L63/1416G06F2221/034G06F2221/2151H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,403
App. No.
18/740,314
Granted
Mar 10, 2026
Kind
B2
Abstract

A disclosed computer-implemented method includes receiving and indexing the raw data. Indexing includes dividing the raw data into time stamped searchable events that include information relating to computer or network security. Store the indexed data in an indexed data store and extract values from a field in the indexed data using a schema. Search the extracted field values for the security information. Determine a group of security events using the security information. Each security event includes a field value specified by a criteria. Present a graphical interface (GI) including a summary of the group of security events, other summaries of security events, and a remove element (associated with the summary). Receive input corresponding to an interaction of the remove element. Interacting with the remove element causes the summary to be removed from the GI. Update the GI to remove the summary from the GI.

Claims (57)

1 . A method comprising:

generating, by a computer system, an event group that includes two or more events, wherein generating the event group includes:

searching, based on a security criterion, a data store that stores a plurality of events from a plurality of data sources, wherein each event of the plurality of events is based on computer activity and corresponds to one or more field values, and wherein a particular field value of the one or more field values corresponds to the security criterion; and

adding, to the event group, particular events from the plurality of events that correspond to the particular field value;

causing, by the computer system, display of a graphical user interface that includes an event group summary that represents the event group and an interactive user interface element associated with the event group summary, wherein the graphical user interface is configured such that activation of the interactive user interface element will cause allow-listing or deny-listing of the event group;

receiving user input directed to the interactive user interface element; and

responsive to receiving the user input, allow-listing or deny-listing the event group.

2 . The method of claim 1 , wherein allow-listing the event group includes removing the event group summary from the graphical user interface.

3 . The method of claim 1 , wherein allow-listing the event group includes removing the event group summary from being displayed in the graphical user interface, and deny-listing the event group includes modifying a visual appearance of the event group summary in the graphical user interface.

4 . The method of claim 1 , further comprising:

receiving second user input indicating a time frame; and

suppressing the event group summary from being displayed in the graphical user interface only during the time frame indicated by the second user input.

5 . The method of claim 1 , wherein the event group summary includes domain activity information.

6 . The method of claim 1 , wherein the event group summary is one of a plurality of event group summaries displayed in the graphical user interface, each of the plurality of event group summaries corresponding to a separate group of events of the plurality of events.

7 . The method of claim 1 , wherein the event group summary is one of a plurality of event group summaries displayed in the graphical user interface, each of the plurality of event group summaries corresponding to a separate group of events of the plurality of events;

the method further comprising:

changing a visual appearance of a particular event group summary among the plurality of event group summaries to indicate that the particular event group summary is a potential security threat.

8 . The method of claim 1 , wherein the event group summary is one of a plurality of event group summaries displayed in the graphical user interfaces, each of the plurality of event group summaries corresponding to a separate group of events of the plurality of events;

the method further comprising:

causing, by the computer system, display of a second graphical user interface including a second plurality of event group summaries, wherein each event group summary in the second plurality of event group summaries was suppressed from the graphical user interface to indicate that each event group summary in the second plurality of event group summaries is not a security threat.

9 . The method of claim 1 , wherein each event in the plurality of events contains machine data, and wherein at least some events of the plurality of events include log data;

the method further comprising:

organizing the machine data into the plurality of events, wherein an event comprises at least a portion of log data within the machine data.

10 . The method of claim 1 , wherein each event of the plurality of events is associated with a time stamp, and wherein the event group summary encompasses events having time stamps within a specified time period.

11 . The method of claim 1 , wherein the event group summary includes a numerical count of events in the event group.

12 . The method of claim 1 , wherein the security criterion includes at least one of: an HTTP agent string, a network traffic size, a length of a uniform resource locator string, a byte count per request, a domain name, or a source address.

13 . The method of claim 1 , further comprising:

generating, by the computer system, a display that includes an add element and one or more event group summaries that have been suppressed from the graphical user interface, wherein a user interaction with the add element causes the event group summary to be added back to the graphical user interface; and

in response to the user interaction with the add element, updating, by the computer system, the graphical user interface to add the event group summary back to the graphical user interface.

14 . At least one non-transitory machine-readable storage medium storing instructions, execution of which in a computer system causes performance by the computer system of operations comprising:

generating an event group that includes two or more events, wherein generating the event group includes:

searching, based on a security criterion, a data store that stores a plurality of events from a plurality of data sources, wherein each event of the plurality of events is based on computer activity and corresponds to one or more field values, and wherein a particular field value of the one or more field values corresponds to the security criterion; and

adding, to the event group, particular events from the plurality of events that correspond to the particular field value;

causing display of a graphical user interface that includes an event group summary that represents the event group and an interactive user interface element associated with the event group summary, wherein the graphical user interface is configured such that activation of the interactive user interface element will cause allow-listing or deny-listing of the event group;

receiving user input directed to the interactive user interface element; and

responsive to receiving the user input, allow-listing or deny-listing the event group.

15 . The at least one non-transitory machine-readable storage medium of claim 14 , such that allow-listing the event group includes removing the event group summary from the graphical user interface, and deny-listing the event group includes modifying a visual appearance of the event group summary in the graphical user interface.

16 . The at least one non-transitory machine-readable storage medium of claim 14 , wherein the operations further comprise:

receiving second user input indicating a time frame; and

suppressing the event group summary from being displayed in the graphical user interface only during the time frame indicated by the second user input.

17 . The at least one non-transitory machine-readable storage medium of claim 14 , such that the event group summary is one of a plurality of event group summaries displayed in the graphical user interface, each of the plurality of event group summaries corresponding to a separate group of events of the plurality of events.

18 . A computer system comprising:

a network interface via which to communicate with a remote computer system over a network;

a memory; and

a processor coupled to the memory and the network interface and configured to cause the computer system to perform operations including:

generating an event group that includes two or more events, wherein generating the event group includes:

searching, based on a security criterion, a data store that stores a plurality of events from a plurality of data sources, wherein each event of the plurality of events is based on computer activity and corresponds to one or more field values, and wherein a particular field value of the one or more field values corresponds to the security criterion; and

adding, to the event group, particular events from the plurality of events that correspond to the particular field value;

causing display of a graphical user interface that includes an event group summary that represents the event group and an interactive user interface element associated with the event group summary, wherein the graphical user interface is configured such that activation of the interactive user interface element will cause allow-listing or deny-listing of the event group;

receiving user input directed to the interactive user interface element; and

responsive to receiving the user input, allow-listing or deny-listing the event group.

19 . The computer system of claim 18 , wherein the event group summary is one of a plurality of event group summaries displayed in the graphical user interface, each of the plurality of event group summaries corresponding to a separate group of events of the plurality of events;

the operations further comprising:

causing, by the computer system, display of a second graphical user interface including a second plurality of event group summaries, wherein each event group summary in the second plurality of event group summaries was suppressed from the graphical user interface to indicate that each event group summary in the second plurality of event group summaries is not a security threat.

20 . The computer system of claim 18 , wherein the event group summary is one of a plurality of event group summaries displayed in the graphical user interface, each of the plurality of event group summaries corresponding to a separate group of events of the plurality of events;

the operations further comprising:

changing a visual appearance of a particular event group summary among the plurality of event group summaries to indicate that the particular event group summary is a potential security threat.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2024
From: COATES, JOHN; MURPHEY, LUCAS; HAZEKAMP, DAVID; HANSEN, JAMES
To: SPLUNK INC.
Reel/Frame 067720/0206 →
Continuity (8)
Continuation 17507698 · Oct 21, 2021
Continuation 16526354 · Jul 30, 2019
Continuation 15996866 · Jun 4, 2018
Continuation 15421420 · Jan 31, 2017
Continuation 15056999 · Feb 29, 2016
Continuation 14280311 · May 16, 2014
Continuation 13956285 · Jul 31, 2013
Related Publication 20240333752A1 · Oct 3, 2024
References Cited (18)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8412696B2 · Zhang et al. · 2013 [cited by applicant]
US 8752178B2 · Coates et al. · 2014 [cited by applicant]
US 9276946B2 · Coates et al. · 2016 [cited by applicant]
US 9596252B2 · Coates et al. · 2017 [cited by applicant]
US 9992220B2 · Coates et al. · 2018 [cited by applicant]
US 10382472B2 · Coates et al. · 2019 [cited by applicant]
US 11178167B2 · Coates et al. · 2021 [cited by applicant]
US 20060168331A1 · Thompson et al. · 2006 [cited by applicant]
US 20080229422A1 · Hudis · 2008 [cited by examiner]
US 20100024004A1 · Hicks et al. · 2010 [cited by applicant]
US 20110055590A1 · Lee et al. · 2011 [cited by applicant]
US 20110083180A1 · Mashevsky · 2011 [cited by examiner]
US 20220046052A1 · Coates et al. · 2022 [cited by applicant]
Splunk Inc., “Graphical Display Suppressing Events Indicating Security Threats in an Information Technology System”, U.S. Appl. No. 16/526,354, filed Jul. 30, 2019, including its prosecution history. [cited by applicant]
Bitincka, L. , et al., “Optimizing Data Analysis with a Semi-Structured Time Series Database”, In SLAML, '10, Jul. 31, 2013, 9 Pages. [cited by applicant]
Carasso, David , “Exploring Splunk—Search Processing Lanaguage (SPL) Primer and Cookbook”, Apr. 2012, 156 Pages. [cited by applicant]