Systems and methods for machine-learning based alert grouping

    公开(公告)号:US12086045B1

    公开(公告)日:2024-09-10

    申请号:US17589833

    申请日:2022-01-31

    Applicant: Splunk, Inc.

    CPC classification number: G06F11/3075 G06F16/244 G06F16/2477 G06F18/2178

    Abstract: A computerized method is disclosed for grouping alerts through machine learning. The method including receiving an alert to be assigned to any of a plurality of existing issues or to a newly created issue, wherein an issue is a grouping of alerts, determining a temporal distance between the alert and each of the existing issues, determining either of (i) a numerical distance between the alert and each of the existing issues for a particular numerical field, or (ii) a categorical distance between the alert and each of the existing issues for a particular categorical field, determining an overall distance between the alert and each of the existing issues, and assigning the alert to either (i) an existing issue having a shortest overall distance to the alert that satisfies one or more time constraints, or (ii) the newly created issue.

    Online data forecasting
    32.
    发明授权

    公开(公告)号:US12079304B1

    公开(公告)日:2024-09-03

    申请号:US17246228

    申请日:2021-04-30

    Applicant: SPLUNK INC.

    CPC classification number: G06F18/10 G06F18/214 G06Q10/04

    Abstract: Embodiments of the present disclosure are directed to facilitating performing online data forecasting. In operation, data decomposition of an incoming data point is performed to determine a trend component associated with the incoming data point. Such a trend component, and previous trend components, can be used to determine a trend component expected for a data point subsequent to the incoming data point. A seasonality component expected for the data point subsequent to the incoming data point can be identified, for example, based on a seasonality component associated with a previous corresponding data point. Thereafter, the expected trend and seasonality components can be used to predict the data point subsequent to the incoming data point. Such a data prediction can be performed in an online processing manner such that a subsequent data point is not used to decompose the incoming data point or forecast the data point.

    Accessibility controls for manipulating data visualizations

    公开(公告)号:US12072859B1

    公开(公告)日:2024-08-27

    申请号:US18050016

    申请日:2022-10-26

    Applicant: Splunk Inc.

    Inventor: Ryan O'Connor

    CPC classification number: G06F16/22 G06F3/04847 G06F16/2474

    Abstract: A computer system displays a graphical user interface (GUI) that includes data visualizations corresponding to data having timestamps within a time interval. A first type of input signal is mapped to a second type of input signal. The first type of input signal is associated with an input device communicatively coupled to the computer system. The second type of input signal is configured to operate a graphical user control of the GUI. Before mapping, the first type of input signal is configured to perform a function that is different from operation of the graphical user control. After receiving an input signal of the first type, an input signal of the second type is applied to the graphical user control based on the mapping. The time interval is adjusted, and the data visualizations are updated automatically to correspond to updated data having timestamps within the adjusted time interval.

    Ingest health monitoring
    37.
    发明授权

    公开(公告)号:US12061533B1

    公开(公告)日:2024-08-13

    申请号:US17877725

    申请日:2022-07-29

    Applicant: Splunk Inc.

    CPC classification number: G06F11/3476 G06F3/0619 G06F2201/81

    Abstract: Ingest health monitoring includes receiving an event stream of events in a data intake and query system to store on at least one storage system and obtaining an event from the event stream. Ingest health monitoring further includes transmitting the event to a selected ingest module queue for the event, updating an output rate indicator counter for the selected ingest module queue when failure to store the event in the ingest module queue occurs, obtaining the event from the selected ingest module queue, processing the event to generate a file for the event, and transmitting the file to the at least one storage system. Ingest health monitoring further includes updating the write failure indicator counter for a storage system of the at least one storage system when failure to transmit to the storage system occurs and updating the user interface based on the output rate indicator counter and the write failure indicator counter.

Patent Agency Ranking