IP Library › Granted Patent US 10,942,960
Granted Patent B2
US 10,942,960 · App. 16/049,748 · Granted Mar 9, 2021

Automatic triage model execution in machine data driven monitoring automation apparatus with visualization

Inventors: Adam Jamison Oliner (San Francisco, CA); Kristal Curtis (San Francisco, CA); Iman Makaremi (San Francisco, CA); Ross Andrew Lazerowitz (San Francisco, CA)
Assignee: SPLUNK INC.
G06F16/338G06F9/451G06F9/542G06F16/334G06F16/38G06F16/903G06Q10/06393G06Q10/20H04L41/0604H04L41/069H04L41/0681H04L41/22H04L41/5009H04L41/0609
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,942,960
App. No.
16/049,748
Filed
Jul 30, 2018
Granted
Mar 9, 2021
Kind
B2
Art Unit
2175
USPC
715/736
Abstract

Network connections are established between machines of an operating environment to be monitored and a server group of a data intake and query system (DIQS). Data reflecting machine and component operations of the environment is conveyed via the network to the DIQS where it is reflected as timestamped entries in a field-searchable datastore. Monitoring components may search the datastore and identify and record instances of notable events. Triaging models are selectively applied against the notable event instances to produce an enhanced notable event instance representation with modeled results effective to automatically perform or assist in triaging the notable events so they are dispatched in an optimal, effective, and efficient, manner.

Claims (39)

1. A method performed by one or more processing devices, the method comprising:

receiving machine data via one or more network connections from multiple machine data sources;

reflecting the machine data as entries in a field-searchable datastore, wherein each of the entries comprises a portion of the received machine data and a timestamp associated with the portion;

determining a plurality of notable events, each notable event determined at least in part from a result of a search query addressing at least one of the entries, and reflecting each of the notable events in a memory;

determining, by applying a model, a relevance score of a notable event of the plurality of notable events;

causing display of a user interface comprising information about the one or more of the notable events, wherein the user interface comprises an attribute visually representing the relevance score of the notable event.

2. The method of claim 1 wherein the model is a score-type model.

3. The method of claim 1 wherein the model is a score-type model having a numeric result.

4. The method of claim 1 wherein the model is a score-type model having a categorical result.

5. The method of claim 1 wherein the model is a score-type model having a categorical result and a numeric result.

6. The method of claim 1 wherein the model is a score-type model having at least one of a categorical result or a numeric result.

7. The method of claim 1 wherein the user interface includes an interactive component to trigger an action identified based on a result produced by the model.

8. The method of claim 1 wherein the user interface includes interactive components enabling a user to indicate at least one of: approval or disapproval.

9. The method of claim 1 wherein the user interface includes interactive components enabling a user to indicate a selection of an action identified based on a result produced by the model.

10. The method of claim 1 wherein the user interface includes interactive components enabling a user to indicate a selection of an action identified based on a result produced by the model, and wherein the action is associated with a recommended status.

11. The method of claim 1 wherein the user interface includes a representation of an action identified based on a result produced by the model.

12. The method of claim 1 the user interface includes a representation of an action identified based on a result produced by the model, the representation includes an interactive component enabling a user to indicate a selection state for the action.

13. The method of claim 1 wherein the model comprises a self-referential component.

14. The method of claim 1 wherein the model comprises a model template definition and a model instance definition.

15. The method of claim 1 wherein the user interface includes a relative presentation order of a plurality of representations of respective notable event instances.

16. The method of claim 1 wherein the attribute is a color attribute.

17. The method of claim 1 wherein the attribute is a shape.

18. The method of claim 1 wherein the user interface includes a representation of a rationale included in a result produced by the model.

19. The method of claim 1 wherein the user interface includes a representation of a rationale included in a result produced by the model, the representation to be displayed in response to a hover-over event.

20. The method of claim 1 wherein the the user interface includes a representation of a rationale included in a result produced by the model, the representation to be displayed in a pop-up user interface component in response to a hover-over event.

21. A system comprising:

a memory; and

a processing device coupled with the memory to perform operations comprising:

receiving machine data via one or more network connections from multiple machine data sources;

reflecting the machine data as entries in a field-searchable datastore, wherein each of the entries comprises a portion of the received machine data and a timestamp associated with the portion;

determining a plurality of notable events, each notable event determined at least in part from a result of a search query addressing at least one of the entries, and reflecting each of the notable events in the memory;

determining, by applying a model, a relevance score of a notable event of the plurality of notable events;

causing display of a user interface comprising information about the one or more of the notable events, wherein the user interface comprises an attribute visually representing the relevance score of the notable event.

22. A non-transitory computer readable storage medium encoding instructions thereon that, in response to execution by one or more processing devices, cause the one or more processing devices to perform operations comprising:

receiving machine data via one or more network connections from multiple machine data sources;

reflecting the machine data as entries in a field-searchable datastore wherein each of the entries comprises a portion of the received machine data and a timestamp associated with the portion;

determining a plurality of notable events, each notable event determined at least in part from a result of a search query addressing at least one of the entries, and reflecting each of the notable events in a memory;

determining, by applying a model, a relevance score of a notable event of the plurality of notable events;

causing display of a user interface comprising information about the one or more of the notable events, wherein the user interface comprises an attribute visually representing the relevance score of the notable event.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2018
From: OLINER, ADAM JAMISON; CURTIS, KRISTAL; MAKAREMI, IMAN; LAZEROWITZ, ROSS ANDREW
To: SPLUNK INC.
Reel/Frame 046523/0662 →
Continuity (2)
Continuation In Part 15276750 · Sep 26, 2016
Related Publication 20180349482A1 · Dec 6, 2018
Cited By (2)
US 12,585,462 US 12,632,306