CLUSTERING EVENTS WHILE EXCLUDING EXTRACTED VALUES

    公开(公告)号:US20210149912A1

    公开(公告)日:2021-05-20

    申请号:US17158880

    申请日:2021-01-26

    Applicant: SPLUNK INC.

    Abstract: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

    Tool for machine-learning data analysis

    公开(公告)号:US10956834B2

    公开(公告)日:2021-03-23

    申请号:US16707845

    申请日:2019-12-09

    Applicant: Splunk Inc.

    Abstract: Disclosed herein is a computer-implemented tool that facilitates data analysis by use of machine learning (ML) techniques. The tool cooperates with a data intake and query system and provides a graphical user interface (GUI) that enables a user to train and apply a variety of different ML models on user-selected datasets of stored machine data. The tool can provide active guidance to the user, to help the user choose data analysis paths that are likely to produce useful results and to avoid data analysis paths that are less likely to produce useful results.

    Adaptive key performance indicator thresholds

    公开(公告)号:US10235638B2

    公开(公告)日:2019-03-19

    申请号:US14859236

    申请日:2015-09-18

    Applicant: Splunk Inc.

    Abstract: Techniques are disclosed for providing adaptive thresholding technology for Key Performance Indicators (KPIs). Adaptive thresholding technology may automatically assign new values or adjust existing values for one or more thresholds of one or more time policies. Assigning threshold values using adaptive thresholding may involve identifying training data (e.g., historical data, simulated data, or example data) for the time frames and analyzing the training data to identify variations within the data (e.g., patterns, distributions, trends). A threshold value may be determined based on the variations and may be assigned to one or more of the thresholds without additional user intervention.

    EVENT FORECASTING
    38.
    发明申请
    EVENT FORECASTING 审中-公开

    公开(公告)号:US20180218269A1

    公开(公告)日:2018-08-02

    申请号:US15419918

    申请日:2017-01-30

    Applicant: SPLUNK INC.

    CPC classification number: G06N5/04 G06F16/2465 G06F16/26 G06N20/00

    Abstract: Embodiments of the present invention are directed to facilitating event forecasting. In accordance with aspects of the present disclosure, a set of events determined from raw machine data is obtained. The events are analyzed to identify leading indicators that indicate a future occurrence of a target event, wherein the leading indicators occur during a search period of time the precedes a warning period of time, thereby providing time for an action to be performed prior to an occurrence of a predicted target event. At least one of the leading indicators is used to predict a target event. An event notification is provided indicating the prediction of the target event.

    AUTOMATICALLY GENERATING FIELD EXTRACTION RECOMMENDATIONS

    公开(公告)号:US20180089561A1

    公开(公告)日:2018-03-29

    申请号:US15420754

    申请日:2017-01-31

    Applicant: SPLUNK INC.

    Abstract: Systems and methods include obtaining a set of events, each event in the set of events comprising a time-stamped portion of raw machine data, the raw machine data produced by one or more components within an information technology or security environment and reflects activity within the information technology or security environment. Thereafter, a first neural network is used to automatically identify variable text to extract as a field from the set of events. An indication of the variable text is provided as a field extraction recommendation, for example, to a user device for presentation to a user.

    Machine Learning in Edge Analytics
    40.
    发明申请

    公开(公告)号:US20180032908A1

    公开(公告)日:2018-02-01

    申请号:US15224439

    申请日:2016-07-29

    Applicant: Splunk Inc.

    CPC classification number: G06N20/00 G06F11/30

    Abstract: Disclosed is a technique that can be performed by an electronic device. The technique can include generating raw data based on inputs to the electronic device, and sending the raw data or data items over a network to a server computer system. The sent raw data or the data items can include training data. The technique can further include receiving global model data from the server computer system over the network. The global model data may have been derived from the training data in accordance with a machine learning process. The technique can further include generating an updated local model by updating a local model associated with the electronic device based on the received global model data, and processing local data based on the updated local model to generate output data. The local data can include raw data or data items generated based on inputs to the electronic device.

Patent Agency Ranking