- 专利标题: Identifying evidence within an information technology (IT) operations platform
-
申请号: US16429044申请日: 2019-06-02
-
公开(公告)号: US11416561B1公开(公告)日: 2022-08-16
- 发明人: Sourabh Satish , David Wayman , Kavita Varadarajan
- 申请人: Splunk Inc.
- 申请人地址: US CA San Francisco
- 专利权人: Splunk Inc.
- 当前专利权人: Splunk Inc.
- 当前专利权人地址: US CA San Francisco
- 代理机构: Nicholson De Vos Webster & Elliott LLP
- 主分类号: G06F16/906
- IPC分类号: G06F16/906 ; H04L9/40 ; G06F16/907 ; G06F16/9038 ; G06F16/11 ; G06F3/0482
摘要:
Techniques are described for enabling analysts and other users of an IT operations platform to identify certain data objects managed by the platform (for example, events, files, notes, actions results, etc.) as “evidence” when such data objects are believed to be of particular significance to an investigation or other matter. For example, an event generated based on data ingested from an anti-virus service and representing a security-related incident might include artifacts indicating an asset identifier, a hash value of a suspected malicious file, a file path on the infected endpoint, and so forth. An analyst can use various interfaces and interface elements of an IT operations platform to indicate which of such events and/or artifacts, if any, represent evidence in the context of the investigation that the analyst is conducting. In response, the IT operations platform can perform various automated actions.
信息查询