Invention Grant
- Patent Title: Identifying notable events based on execution of correlation searches
-
Application No.: US15421393Application Date: 2017-01-31
-
Publication No.: US11196756B2Publication Date: 2021-12-07
- Inventor: Mark Seward , John Robert Coates
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: Splunk Inc.
- Current Assignee: Splunk Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Nicholson De Vos Webster & Elliott LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F16/21 ; G06F16/951

Abstract:
Systems and methods are provided for identifying network addresses and/or IDs of a deduplicated list among network data, machine data, and/or events derived from network data and/or machine data, and for identifying notable events by searching for the presence of network addresses and/or network IDs that are deduplicated across lists received from multiple external sources. One method includes receiving a plurality of lists of network locations, wherein each list is received from over a network, wherein each of the network locations includes a domain name or an IP address, and wherein at least two of the plurality of lists each include a same network location; aggregating the plurality of lists of network locations into a deduplicated list of unique network locations; and searching network data or machine data for a network location included in the deduplicated list of unique network locations.
Public/Granted literature
- US20170142143A1 IDENTIFYING NOTABLE EVENTS BASED ON EXECUTION OF CORRELATION SEARCHES Public/Granted day:2017-05-18
Information query