IP Library › Granted Patent US 12,748,626
Granted Patent B2
US 12,748,626 · App. 19/278,928 · Granted Sep 29, 2026

Method of handling a failure in a task pipeline between a source of alerts and a security incident and event management (SIEM) system

Inventors: Alec R. Kerr (Christiansburg, VA); Joseph Edmonds (Ellicott City, MD)
Assignee: MORGAN STANLEY SERVICES GROUP INC.
G06F9/5027G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,748,626
App. No.
19/278,928
Granted
Sep 29, 2026
Kind
B2
Abstract

A method of improving efficiency of processing alerts by a Security Incident & Event Management (SIEM) platform using a case creation platform, the method involves based upon contents of a configuration, creating a pipeline, comprising tasks, between a source of alerts and the SIEM platform, wherein, a task of the pipeline fails due to an exception, at least one object, including failed task input data, will be stored in an error log relating to the failure, and associated data will be stored in a task log, based upon additional content in the configuration, determining whether or not a rollback re-run can be attempted for the pipeline using at least a portion of tasks from a prior version/iteration of the pipeline; and if the rollback re-run can be attempted, executing the rollback re-run using the failed task input data.

Claims (47)

1 . A method of improving efficiency of processing alerts by a Security Incident & Event Management (SIEM) platform using a case creation platform, the method comprising:

based upon contents of a configuration, creating a pipeline between a source of alerts and the SIEM platform;

executing a source task in the pipeline so that it retrieves alerts from the source of alerts;

providing an output of the source task to a first of at least two process tasks in the pipeline;

processing the output of the source task, using the first of the at least two process tasks and output first processed alerts to a second of the at least two process tasks;

processing the first processed alerts with the second of the at least two process tasks such that when the second of the at least two process tasks completes, an output of the second of the at least two process tasks will be provided to a sink task for publication as one or more SIEM cases to the SIEM platform; and

when the second of the at least two process tasks fails due to an exception, (i) at least one object, including failed task input data, will be stored in an error log relating to the failure, and (ii) associated data will be stored in a task log;

based upon additional content in the configuration, determining whether or not a rollback re-run can be attempted for the pipeline using at least a portion of tasks from a prior version/iteration of the pipeline; and

when the rollback re-run can be attempted, executing the rollback re-run using the failed task input data.

2 . The method of claim 1 , wherein when a result of the determining indicates that a rollback re-run cannot be attempted, the method further comprises:

mocking out the pipeline using contents from the error log and the task log.

3 . The method of claim 1 wherein, when a result of the determining indicates that a rollback re-run can be attempted, the method further comprises:

creating a renewed pipeline.

4 . The method of claim 3 , wherein the creating the renewed pipeline comprises:

rebuilding a prior version/iteration of the pipeline.

5 . The method of claim 3 , wherein the creating the renewed pipeline comprises:

over writing at least the failed task with a replacement task from a prior version/iteration.

6 . The method of claim 3 , wherein the creating the renewed pipeline comprises:

overwriting the failed task and all subsequent tasks in the pipeline with tasks from a prior version/iteration.

7 . The method of claim 3 , wherein the creating the renewed pipeline comprises:

overwriting the failed task and all prior tasks in the pipeline with tasks from a prior version/iteration.

8 . The method of claim 1 further comprising:

based upon the configuration, using the error log to modify and/or swap an ordering of the at least two process tasks in the pipeline before determining whether or not a rollback re-run can be attempted.

9 . The method of claim 8 , wherein the creating the renewed pipeline comprises:

rebuilding a prior version/iteration of the pipeline.

10 . The method of claim 8 , wherein the creating the renewed pipeline comprises:

over writing at least the failed task with a replacement task from a prior version/iteration.

11 . The method of claim 8 , wherein the creating the renewed pipeline comprises:

overwriting the failed task and all subsequent tasks in the pipeline with tasks from a prior version/iteration.

12 . The method of claim 8 , wherein the creating the renewed pipeline comprises:

overwriting the failed task and all prior tasks in the pipeline with tasks from a prior version/iteration.

13 . The method of claim 1 wherein the determining includes, identifying a type of error.

14 . The method of claim 13 , wherein the type involves one or more of: a mistake in code syntax, a missing argument, an incorrect argument, an incorrect reference, a wrong data type or incorrect logic.

15 . A method of improving efficiency of processing alerts by a Security Incident & Event Management (SIEM) platform using a case creation platform, the method comprising:

based upon contents of a configuration, creating a pipeline, comprising tasks having a source task and a sink task, between a source of alerts and the SIEM platform;

wherein, when a task of the pipeline fails due to an exception, at least one object, including failed task input data, will be stored in an error log relating to the failure, and associated data will be stored in a task log,

based upon additional content in the configuration, determining whether or not a rollback re-run can be attempted for the pipeline using at least a portion of tasks from a prior version/iteration of the pipeline; and when the rollback re-run can be attempted, executing the rollback re-run using the failed task input data.

16 . The method of claim 15 wherein, when a result of the determining indicates that a rollback re-run can be attempted, the method further comprises:

creating a renewed pipeline and executing the rollback re-run using the renewed pipeline.

17 . The method of claim 16 , wherein the creating the renewed pipeline comprises:

rebuilding a prior version/iteration of the pipeline.

18 . The method of claim 16 , wherein the creating the renewed pipeline comprises:

over writing at least the failed task with a replacement task from a prior version/iteration.

19 . The method of claim 16 , wherein the creating the renewed pipeline comprises:

overwriting the failed task and all subsequent tasks in the pipeline with tasks from a prior version/iteration.

20 . The method of claim 16 , wherein the creating the renewed pipeline comprises:

overwriting the failed task and all prior tasks in the pipeline with tasks from a prior version/iteration.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2025
From: KERR, ALEC R; EDMONDS, JOSEPH
To: MORGAN STANLEY SERVICES GROUP INC.
Reel/Frame 071816/0595 →
Continuity (3)
Continuation In Part 19068551 · Mar 3, 2025
Continuation 18951880 · Nov 19, 2024
Related Publication 20260203121A1 · Jul 16, 2026
References Cited (58)
US 8266477B2 · Mankovskii · 2012 [cited by examiner]
US 8782784B1 · Bruskin · 2014 [cited by applicant]
US 8874550B1 · Soubramanien · 2014 [cited by applicant]
US 8904531B1 · Saklikar · 2014 [cited by applicant]
US 9064210B1 · Hart · 2015 [cited by applicant]
US 9069930B1 · Hart · 2015 [cited by applicant]
US 9282114B1 · Dotan · 2016 [cited by applicant]
US 9601000B1 · Gruss · 2017 [cited by applicant]
US 10049220B1 · Hatsutori et al. · 2018 [cited by applicant]
US 10129072B1 · Field · 2018 [cited by examiner]
US 10333948B2 · Rostamabadi · 2019 [cited by applicant]
US 10404751B2 · Rajkumar · 2019 [cited by applicant]
US 10515160B1 · Jarvis · 2019 [cited by examiner]
US 10681060B2 · Scheidler · 2020 [cited by applicant]
US 10698767B1 · De Kadt et al. · 2020 [cited by applicant]
US 10873614B2 · Kolan · 2020 [cited by applicant]
US 11106562B2 · Su et al. · 2021 [cited by applicant]
US 11290483B1 · Kannan · 2022 [cited by examiner]
US 11403136B1 · Willson · 2022 [cited by applicant]
US 11431817B2 · Kolan · 2022 [cited by applicant]
US 11494488B2 · Syed · 2022 [cited by applicant]
US 11621970B2 · Soliman · 2023 [cited by applicant]
US 11818156B1 · Parikh et al. · 2023 [cited by applicant]
US 12190161B1 · Kerr · 2025 [cited by applicant]
US 12511305B1 · Maghnani · 2025 [cited by examiner]
US 20060053334A1 · Ingen · 2006 [cited by applicant]
US 20140090068A1 · Guarnieri · 2014 [cited by applicant]
US 20140101673A1 · Klyuchevskyy · 2014 [cited by examiner]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20160019091A1 · Leber · 2016 [cited by examiner]
US 20180077183A1 · Swann · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180288126A1 · Smart · 2018 [cited by applicant]
US 20190303228A1 · Kowta et al. · 2019 [cited by applicant]
US 20190356679A1 · Sites · 2019 [cited by applicant]
US 20200042700A1 · Li · 2020 [cited by applicant]
US 20200177694A1 · Kolan · 2020 [cited by examiner]
US 20200186569A1 · Milazzo · 2020 [cited by applicant]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20210110032A1 · Yip · 2021 [cited by applicant]
US 20210352136A1 · Dojka et al. · 2021 [cited by applicant]
US 20220114252A1 · Syed et al. · 2022 [cited by applicant]
US 20220342707A1 · Alagna et al. · 2022 [cited by applicant]
US 20220343181A1 · Thomas · 2022 [cited by applicant]
US 20220345479A1 · Markonis et al. · 2022 [cited by applicant]
US 20220368696A1 · Karpovsky · 2022 [cited by applicant]
US 20230252138A1 · McCarthy · 2023 [cited by applicant]
US 20240080337A1 · Matefi · 2024 [cited by applicant]
US 20240089293A1 · Singla · 2024 [cited by applicant]
US 20240152371A1 · He · 2024 [cited by applicant]
US 20240192974A1 · Gadupudi · 2024 [cited by applicant]
US 20240256421A1 · Alexander · 2024 [cited by applicant]
US 20240394311A1 · Dash · 2024 [cited by applicant]
US 20260081937A1 · McCubbin · 2026 [cited by examiner]
Bhatt et al.; “The Operational Role of Security Information and Event Management Systems”; HP lab; Oct. 2014; IEEE; (Bhatt_2014.pdf; pp. 35-41) (Year: 2014). [cited by applicant]
Gonzalez et al.; “New Types of Alert Correlation for Security Information and Event Management Systems”; IEEE (Gonzalez_2016. pdf; pp. 1-7) (Year: 2016). [cited by applicant]
Lu et al.,; “Log-based Abnormal Task Detection and Root Cause Analysis for Spark”; 2017 IEEE International Conference on Web Services (ICWS); DOI 10.1109/ICWS.2017; (Lu_2017.pdf; pp. 389-396) (Year: 2017). [cited by applicant]
Granadillo et al.; “Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures”; Sensors 2021, 21, 4759. https://doi.org/10.3390/s21144759 (Granadillo_2021.pdf; pp. 1-28) (… [cited by applicant]