IP Library › Granted Patent US 12,568,103
Granted Patent B2
US 12,568,103 · App. 18/754,659 · Granted Mar 3, 2026

Systems and methods for querying incident investigations

Inventors: Gemma Lowe (Coffs Harbour, AU); Gregory Kowalczyk (Amsterdam, NL); Ramazan Uysal (Amsterdam, NL)
Assignee: ATLASSIAN PTY, LTD.
H04L63/1425G06F16/24575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,103
App. No.
18/754,659
Granted
Mar 3, 2026
Kind
B2
Abstract

Systems and methods provide techniques for improving incident investigation efficiency. In various embodiments, a method includes obtaining historical query inputs associated with historical incident investigations; generating an incident investigation dataset based on the historical query inputs and respective metadata associated with the historical incident investigations; receiving, from a computing device via an application programming interface (API), a query search string; generating a response based on the query search string and the incident investigation dataset, the request response comprising a historical query input and a digital reference to the metadata for a respective historical incident investigation associated with the historical query input, wherein metadata or historical query input are within a threshold similarity to the query search string; and provisioning the response to the computing device via the API, wherein the request response causes the computing device to render a graphical user interface comprising the historical query input and digital reference.

Claims (70)

1 . A method for incident investigation querying, comprising:

obtaining a plurality of historical query inputs, wherein subsets of the historical query inputs are associated with respective historical incident investigations;

generating an incident investigation dataset based at least in part on the historical query inputs and respective metadata associated with the historical incident investigations;

receiving, from a computing device via an application programming interface (API), a query search string;

generating a request response based at least in part on the query search string and the incident investigation dataset, wherein the request response comprises:

at least one historical query input; and

a digital reference to the metadata for a respective historical incident investigation associated with the at least one historical query input, wherein at least one of the metadata or the at least one historical query input are within a threshold similarity to the query search string; and

provisioning the request response to the computing device via the API, wherein the request response causes the computing device to render a graphical user interface (GUI) comprising the at least one historical query input and the digital reference to the metadata.

2 . The method of claim 1 , wherein:

the metadata comprises an incident identifier.

3 . The method of claim 1 , wherein:

the metadata comprises an incident summary.

4 . The method of claim 1 , wherein:

the metadata comprises a timestamp associated with initiation of the respective historical incident investigation.

5 . The method of claim 1 , wherein:

the metadata comprises at least one user identifier associated with the at least one historical query input.

6 . The method of claim 1 , further comprising:

filtering the plurality of historical query inputs based at least in part on a regular expression (regex) definition.

7 . The method of claim 1 , further comprising:

receiving, via a second API, at least one incident investigation summary; and

extracting at least a subset of the plurality of historical query inputs from the at least one incident investigation summary, wherein the at least one incident investigation summary is obtained from a remote computing environment via a second API.

8 . The method of claim 7 , wherein:

extracting a respective historical query input from the at least one incident investigation summary comprises:

verifying that the historical query input contains at least one unformatted substring component; and

verifying that at least a portion of the at least one unformatted substring component matches a naming convention of a log source associated with the at least one incident investigation summary.

9 . The method of claim 1 , further comprising:

obtaining at least one additional query input via an asynchronous task service; and

updating the incident investigation dataset based at least in part on the at least one additional query input.

10 . The method of claim 1 , further comprising:

generating a respective utilization level for a plurality of log sources based at least in part on the incident investigation dataset;

generating, based on the respective utilization levels, at least one of i) a set of unused log sources, or ii) a set of high utilization log sources; and

provisioning to a second computing device at least one of the set of unused log sources or the set of high utilization log sources.

11 . The method of claim 1 , further comprising:

in response to the computing device receiving an input selecting a respective digital reference, causing rendering of the metadata associated with one of the plurality of historical incident investigations on the GUI.

12 . The method of claim 1 , wherein:

the query search string comprises at least one regex operator; and

generating the request response comprises filtering respective entries of the incident investigation dataset based at least in part on the at least one regex operator.

13 . The method of claim 1 , wherein:

the query search string comprises at least one metadata type.

14 . The method of claim 1 , wherein:

the query search string comprises at least one at least one incident identifier associated with a respective historical incident investigation.

15 . An apparatus for incident investigation querying, the apparatus comprising at least one processor and at least one non-transitory memory comprising program code, wherein the at least one non-transitory memory and the program code are configured to, with the at least one processor, cause the apparatus to:

obtain a plurality of historical query inputs, wherein subsets of the historical query inputs are associated with respective historical incident investigations;

generate an incident investigation dataset based at least in part on the historical query inputs and respective metadata associated with the historical incident investigations;

receive from a computing device via an application programming interface (API), a query search string;

generate a request response based at least in part on the query search string and the incident investigation dataset, wherein the request response comprises:

at least one historical query input; and

a digital reference to the metadata for a respective historical incident investigation associated with the at least one historical query input, wherein at least one of the metadata or the at least one historical query input are within a threshold similarity to the query search string; and

provision the request response to the computing device via the API, wherein the request response causes the computing device to render a graphical user interface (GUI) comprising the at least one historical query input and the digital reference to the metadata.

16 . The apparatus of claim 15 , wherein:

the at least one non-transitory memory and the program code are further configured to, with the at least one processor, cause the apparatus to:

configure the threshold similarity based at least in part on a request from the computing device, wherein the request indicates a precise search mode or an approximate search mode.

17 . The apparatus of claim 15 , wherein:

the at least one non-transitory memory and the program code are further configured to, with the at least one processor, cause the apparatus to:

obtain investigation data representative of a current incident investigation; and

generate the request response based at least in part on respective comparisons between the investigation data and the incident investigation dataset.

18 . The apparatus of claim 15 , wherein:

the at least one non-transitory memory and the program code are further configured to, with the at least one processor, cause the apparatus to:

receive from the computing device via the API a command to generate the request response in a precise search mode; and

in response to the command, verify that at least a subset of the at least one historical query input exactly matches at least a portion of the query search string.

19 . The apparatus of claim 15 , wherein:

the digital reference comprises a hyperlink to a remote computing environment comprising the metadata for the respective historical incident investigation associated with the at least one historical query input.

20 . A computer program product for incident investigation querying, the computer program product comprising at least one non-transitory computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions configured to:

obtain a plurality of historical query inputs, wherein subsets of the historical query inputs are associated with respective historical incident investigations;

generate an incident investigation dataset based at least in part on the historical query inputs and respective metadata associated with the historical incident investigations;

receive from a computing device via an application programming interface (API), a query search string;

generate a request response based at least in part on the query search string and the incident investigation dataset, wherein the request response comprises:

at least one historical query input; and

a digital reference to the metadata for a respective historical incident investigation associated with the at least one historical query input, wherein at least one of the metadata or the at least one historical query input are within a threshold similarity to the query search string; and

provision the request response to the computing device via the API, wherein the request response causes the computing device to render a graphical user interface (GUI) comprising the at least one historical query input and the digital reference to the metadata.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2024
From: LOWE, GEMMA; KOWALCZYK, GREGORY; UYSAL, RAMAZAN
To: ATLASSIAN PTY LTD.
Reel/Frame 067975/0596 →
Continuity (1)
Related Publication 20260006046A1 · Jan 1, 2026
References Cited (13)
US 8032507B1 · Bayardo · 2011 [cited by examiner]
US 8225407B1 · Thrower · 2012 [cited by examiner]
US 9027121B2 · Hammer · 2015 [cited by examiner]
US 10530805B1 · Tamersoy · 2020 [cited by examiner]
US 10542017B1 · Gates · 2020 [cited by examiner]
US 10721266B1 · Herman-Saffar · 2020 [cited by examiner]
US 11075951B1 · Kats · 2021 [cited by examiner]
US 20140172843A1 · Upstill · 2014 [cited by examiner]
US 20170289178A1 · Roundy · 2017 [cited by examiner]
US 20200220885A1 · Will · 2020 [cited by examiner]
US 20200314141A1 · Vajipayajula · 2020 [cited by examiner]
US 20210200826A1 · Schuler · 2021 [cited by examiner]
US 20220414571A1 · Buggins · 2022 [cited by examiner]