Invention Grant
- Patent Title: Creating and testing a correlation search
-
Application No.: US15688323Application Date: 2017-08-28
-
Publication No.: US10860655B2Publication Date: 2020-12-08
- Inventor: Lucas Murphey , David Hazekamp
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: SPLUNK INC.
- Current Assignee: SPLUNK INC.
- Current Assignee Address: US CA San Francisco
- Agency: Lowenstein Sandler LLP
- Main IPC: G06F17/00
- IPC: G06F17/00 ; G06F16/903 ; G06F16/9032 ; G06F16/906 ; G06F16/907 ; G06F17/30

Abstract:
One or more processing devices receive a definition of a search query for a correlation search of a data store, the data store comprising time-stamped events that each comprise a portion of raw machine data reflecting activity in an information technology environment and produced by a component of the information technology environment, receive a definition of a triggering condition to be applied to a dataset that is produced by the search query, receive a definition of one or more actions to be performed when the dataset produced by the search query satisfies the triggering condition, test the search query with the triggering condition, and cause, based on results of the testing, generation of the correlation search using the defined search query, the triggering condition, and the one or more actions, the correlation search comprising search processing language having the search query and a processing command for criteria on which the triggering condition is based.
Public/Granted literature
- US20170371979A1 CREATING AND TESTING A CORRELATION SEARCH Public/Granted day:2017-12-28
Information query