IP Library Patent Application 19076410
Patent Application
App. No. 19/076,410

EXECUTING MODULAR ALERTS AND ASSOCIATED SECURITY ACTIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/076,410
Abstract

Techniques and mechanisms are disclosed for configuring actions to be performed by a network security application in response to the detection of potential security incidents, and for causing a network security application to report on the performance of those actions. For example, users may use such a network security application to configure one or more “modular alerts.” As used herein, a modular alert generally represents a component of a network security application which enables users to specify security modular alert actions to be performed in response to the detection of defined triggering conditions, and which further enables tracking information related to the performance of modular alert actions and reporting on the performance of those actions.

Claims (47)

1 . (canceled)

2 . A method comprising:

receiving, at a data intake and query system, raw machine data produced by one or more components of an information technology environment;

automatically generating one or more extraction rules for extracting event attributes from the raw machine data;

using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events;

providing the one or more structured events to a user;

receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule;

saving one or more extraction rules including the refined extraction rule as part of a data processing pipeline;

using the data processing pipeline to process raw machine data.

3 . The method of claim 2 , wherein providing the one or more structured events to a user includes displaying the results via a graphical user interface.

4 . The method of claim 2 , wherein the raw machine data produced by one or more components of an information technology environment includes one of system logs, network packet data, sensor data, application program data, error logs, stack traces, and system performance data.

5 . The method of claim 2 , wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and

providing the one or more structured events to a user happens on concurrently arriving raw machine data.

6 . The method of claim 2 , further including saving a portion of the raw machine data.

7 . The method of claim 6 , wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and

providing the one or more structured events to a user happens on saved raw machine data.

8 . A system comprising:

one or more computers each including a processor and a memory, wherein the one or more computers are operable to execute instructions which cause the system to perform operations including:

receiving, at a data intake and query system, raw machine data produced by one or more components of an information technology environment;

automatically generating one or more extraction rules for extracting event attributes from the raw machine data;

using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events;

providing the one or more structured events to a user;

receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule;

saving one or more extraction rules including the refined extraction rule as part of a data processing pipeline;

using the data processing pipeline to process raw machine data.

9 . The system of claim 8 , wherein providing the one or more structured events to a user includes displaying the results via a graphical user interface.

10 . The system of claim 8 , wherein the raw machine data produced by one or more components of an information technology environment includes one of system logs, network packet data, sensor data, application program data, error logs, stack traces, and system performance data.

11 . The system of claim 8 , wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events; and

providing the one or more structured events to a user happens on concurrently arriving raw machine data.

12 . The system of claim 8 , further including saving a portion of the raw machine data.

13 . The system of claim 12 , wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events; and

providing the one or more structured events to a user happens on saved raw machine data.

14 . A volatile computer-readable media including instructions, which when executed on one or more computers each including a processor and a memory, cause the computers to perform operations including:

receiving, at a data intake and query system, raw machine data produced by one or more components of an information technology environment;

automatically generating one or more extraction rules for extracting event attributes from the raw machine data;

using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events;

providing the one or more structured events to a user;

receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule;

saving one or more extraction rules including the refined extraction rule as part of a data processing pipeline;

using the data processing pipeline to process raw machine data.

15 . The computer-readable media of claim 14 , wherein providing the one or more structured events to a user includes displaying the results via a graphical user interface.

16 . The computer-readable media of claim 14 , wherein the raw machine data produced by one or more components of an information technology environment includes one of system logs, network packet data, sensor data, application program data, error logs, stack traces, and system performance data.

17 . The computer-readable media of claim 14 , wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events; and

providing the one or more structured events to a user happens on concurrently arriving raw machine data.

18 . The computer-readable media of claim 14 , further including saving a portion of the raw machine data.

19 . The computer-readable media of claim 18 , wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events; and

providing the one or more structured events to a user happens on saved raw machine data.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2026
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 074735/0375 →
CHANGE OF NAME Recorded Feb 11, 2026
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 074768/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2026
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 074331/0001 →
CHANGE OF NAME Recorded Jan 13, 2026
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 074331/0875 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2025
From: SHAHBAZ, BANIPAL; OAKLANDER DE LICORI, SIRI ATMA; COATES, JOHN ROBERT; HAZEKAMP, DAVID; BADHANI, DEVENDRA; MURPHEY, LUKE; SCHULZ, PATRICK
To: SPLUNK INC.
Reel/Frame 070753/0635 →