Systems and methods for machine-learning based alert grouping including temporal constraints

    公开(公告)号:US12182169B1

    公开(公告)日:2024-12-31

    申请号:US17589600

    申请日:2022-01-31

    Applicant: Splunk, Inc.

    Abstract: A computerized method is disclosed for grouping alerts through machine learning while implementing certain time constraints. The method includes receiving an alert to be assigned to any of a plurality of existing issues or to a newly created issue, the alert including a temporal field that includes a timestamp of an arrival time of the alert, wherein an issue is a grouping of one or more alerts, determining a subset of existing issues from the plurality of existing issues that each satisfy time constraints, wherein the time constraints correspond to (i) a time elapsed between a most recent alert of a first existing issue and a timestamp of the alert, or (ii) a maximum issue time length of the first existing issue, and deploying a trained machine learning model to assign the alert to either an existing issue of the subset of existing issues or a newly created issue.

    Systems and methods for machine-learning based alert grouping

    公开(公告)号:US12086045B1

    公开(公告)日:2024-09-10

    申请号:US17589833

    申请日:2022-01-31

    Applicant: Splunk, Inc.

    CPC classification number: G06F11/3075 G06F16/244 G06F16/2477 G06F18/2178

    Abstract: A computerized method is disclosed for grouping alerts through machine learning. The method including receiving an alert to be assigned to any of a plurality of existing issues or to a newly created issue, wherein an issue is a grouping of alerts, determining a temporal distance between the alert and each of the existing issues, determining either of (i) a numerical distance between the alert and each of the existing issues for a particular numerical field, or (ii) a categorical distance between the alert and each of the existing issues for a particular categorical field, determining an overall distance between the alert and each of the existing issues, and assigning the alert to either (i) an existing issue having a shortest overall distance to the alert that satisfies one or more time constraints, or (ii) the newly created issue.

Patent Agency Ranking