Generating event streams based on application-layer events captured by remote capture agents

    公开(公告)号:US11936764B1

    公开(公告)日:2024-03-19

    申请号:US17865041

    申请日:2022-07-14

    申请人: Splunk Inc.

    IPC分类号: H04L69/22 H04L67/10

    CPC分类号: H04L69/22 H04L67/10

    摘要: The disclosed embodiments provide a system that processes network data. During operation, the system obtains, at a remote capture agent, a first protocol classification for a first packet flow captured by the remote capture agent. Next, the system uses configuration information associated with the first protocol classification to build a first event stream from the first packet flow at the remote capture agent, wherein the first event stream comprises time-series event data generated from network packets in the first packet flow based on the first protocol classification. The system then transmits the first event stream over a network for subsequent storage and processing of the first event stream by one or more components on the network.

    Real-time processing of data streams received from instrumented software

    公开(公告)号:US11928046B1

    公开(公告)日:2024-03-12

    申请号:US17515272

    申请日:2021-10-29

    申请人: Splunk Inc.

    摘要: An analysis system receives data streams generated by instances of instrumented software executing on external systems. The analysis system evaluates an expression using data values of the data streams over a plurality of time intervals. For example, the analysis system may aggregate data values of data streams for each time interval. The analysis system determines whether or not a data stream is considered for a time interval based on when the data value arrives during the time interval. The analysis system determines a maximum expected delay value for each data stream being processed. The analysis system evaluates the expression using data values that arrive before their maximum expected delay values. The analysis system also determines a failure threshold value for a data stream. If a data value of a data stream fails to arrive before the failure threshold value, the analysis system marks the data stream as dead.

    System and method for changepoint detection in streaming data

    公开(公告)号:US11907227B1

    公开(公告)日:2024-02-20

    申请号:US17591511

    申请日:2022-02-02

    申请人: Splunk, Inc.

    摘要: A computerized method is disclosed including operations of receiving a data stream, performing a changepoint detection resulting in a detection of changepoints in the data stream including: maintaining a listing of starting indices for each run within the data stream in a buffer of size L wherein each index of the listing has a run length probability representing a likelihood of being a changepoint, receiving a new data point within the data stream and adding a new index to the buffer resulting in the buffer having size L+1, calculating a posterior run length probability that the new data point is a changepoint, and removing an index from the listing that has a lowest run length probability thereby returning the buffer to size L, and responsive to determining the index removed from the listing does not correspond to the new data point, identifying a changepoint associated with the new data point.

    Display screen or portion thereof having a graphical user interface with a time slider for a map

    公开(公告)号:USD1013705S1

    公开(公告)日:2024-02-06

    申请号:US29800320

    申请日:2021-07-20

    申请人: SPLUNK Inc.

    摘要: The patent or application file contains at least one drawing executed in color. Copies of this patent or patent application publication with color drawing(s) will be provided by the Office upon request and payment of the necessary fee.
    FIG. 1 is a first embodiment of a display screen or portion thereof having a graphical user interface with a time slider for a map showing my new design;
    FIG. 2 is a second embodiment thereof; and,
    FIG. 3 is a third embodiment thereof.
    The broken dashed lines depict portions of the display screen or portion thereof having a graphical user interface with a time slider for a map in which the design is embodied that form no part of the claimed design. The contents of the area within the dashed lines presented in a dot-dash pattern form no part of the claimed design.

    Analyzing data across tenants of an information technology (IT) and security operations application

    公开(公告)号:US11895126B1

    公开(公告)日:2024-02-06

    申请号:US16657964

    申请日:2019-10-18

    申请人: Splunk Inc.

    IPC分类号: H04L29/06 H04L9/40 G06F9/451

    摘要: An information technology (IT) and security operations application is described that enables cross-tenant analyses of data to derive insights that can be used to provide actionable information across the application including, for example, action recommendations, threat confidence scores, and other incident data enrichments. The generation and presentation of such information to users of an IT and security operations application can enable analyst teams to more efficiently and accurately respond to various types of incidents in IT environments, thereby improving the overall operation and security of the IT environments. Furthermore, because of the shared use of an IT and security operations application concurrently by any number of separate tenants, such cross-tenant analyses can be performed in near real-time and on an ongoing basis to deliver relevant insights.