ADJUSTING NETWORK DATA STORAGE BASED ON EVENT STREAM STATISTICS
    33.
    发明申请
    ADJUSTING NETWORK DATA STORAGE BASED ON EVENT STREAM STATISTICS 审中-公开
    基于事件流统计调整网络数据存储

    公开(公告)号:US20150295796A1

    公开(公告)日:2015-10-15

    申请号:US14699787

    申请日:2015-04-29

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for managing one or more event streams containing the time-series event data, wherein managing the one or more event streams includes enabling the generation of a set of statistics from an event stream without subsequently storing and processing at least a first portion of the event stream by one or more components on a network. The GUI then updates the configuration information based on input received through the first set of user-interface elements.

    Abstract translation: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,该系统导致显示用于从由一个或多个远程捕获代理捕获的网络分组生成时间序列事件数据的图形用户界面(GUI)。 接下来,系统导致在GUI中显示用于管理包含时间序列事件数据的一个或多个事件流的第一组用户界面元素,其中管理一个或多个事件流包括启用集合的生成 来自事件流的统计信息,而不是随后通过网络上的一个或多个组件存储和处理事件流的至少第一部分。 然后,GUI基于通过第一组用户界面元素接收的输入来更新配置信息。

    Creating entity definition from a search result set
    34.
    发明授权
    Creating entity definition from a search result set 有权
    从搜索结果集创建实体定义

    公开(公告)号:US09146954B1

    公开(公告)日:2015-09-29

    申请号:US14611195

    申请日:2015-01-31

    Applicant: Splunk Inc.

    Abstract: A processing device performs a search query to produce a search result set having entries having data items. Each data item has an ordinal position. A table, having rows and columns, is displayed in a graphical user interface. Each data item of a particular entry appears in a respective column of the same row of the table. Each column corresponds to the ordinal position of its respective data item. User input is received designating, for each respective column, a field name and an entity definition component type to which the respective column pertains, and stores for each data item of the particular entry an element value of an entity definition. The element has the element name designated for the respective column in which the data item appeared, and is associated with an entity definition component having the type designated for the respective column in which the data item appeared.

    Abstract translation: 处理装置执行搜索查询以产生具有具有数据项的条目的搜索结果集。 每个数据项都有一个序数位置。 具有行和列的表格显示在图形用户界面中。 特定条目的每个数据项出现在表的同一行的相应列中。 每列对应于其相应数据项的序数位置。 接收到用户输入,为每个相应列指定相应列所属的字段名称和实体定义组件类型,并且为特定条目的每个数据项存储实体定义的元素值。 元素具有为数据项出现的相应列指定的元素名称,并且与具有指定数据项出现的相应列的类型的实体定义组件相关联。

    Animated visualizations of network activity across network address spaces

    公开(公告)号:US11855863B1

    公开(公告)日:2023-12-26

    申请号:US17528963

    申请日:2021-11-17

    Applicant: Splunk Inc.

    CPC classification number: H04L43/045 H04L43/08 H04L43/106

    Abstract: Techniques and mechanisms are disclosed for generating visualizations which graphically depict network activity occurring between pairs of networked computing devices. The visualizations are based on data indicating the network activity, where the network activity can involve devices having any network addresses within an entire network address space (e.g., any address within the Internet Protocol version v4 (IPv4) or IPv6 network address space), or within some subset of an entire network address space. The ability to visualize high-level information related to network activity occurring across an entire network address space enables network analysts and other users to readily analyze characteristics of computer networks which otherwise might not be evident or difficult to obtain using other types of visualizations.

    Configuring event streams based on identified security risks

    公开(公告)号:US11818018B1

    公开(公告)日:2023-11-14

    申请号:US17875170

    申请日:2022-07-27

    Applicant: Splunk Inc.

    CPC classification number: H04L41/22 H04L43/022 H04L43/045

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display, on a computer system, a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for managing one or more ephemeral event streams that contain temporarily generated time-series event data from the network packets, wherein managing the one or more ephemeral event streams comprises modifying an end time for terminating the capture of time-series event data in an ephemeral event stream. The system then updates the configuration information based on input received through the first set of user-interface elements.

    Storage volume regulation for multi-modal machine data

    公开(公告)号:US11580067B1

    公开(公告)日:2023-02-14

    申请号:US17482196

    申请日:2021-09-22

    Applicant: Splunk Inc.

    Abstract: A network storage volume stores first entries in a first-mode storage bucket and a second entries in a second-mode storage bucket. The first-mode storage bucket has first bucket metadata, and the second-mode storage bucket has second bucket metadata. A computer-implemented method includes comparing a utilized capacity of the network storage volume to a target capacity information of the network storage volume to obtain a comparison result. Based on the comparison result, at least one bucket is selected to be purged from the buckets of the network storage volume based at least in part on bucket metadata of the buckets. The method further includes causing a purge of the at least one selected bucket from the network storage volume.

Patent Agency Ranking