Splunk Inc.
Automatic triage model execution in machine data driven monitoring automation apparatus with visualization

Last updated:

Abstract:

Network connections are established between machines of an operating environment to be monitored and a server group of a data intake and query system (DIQS). Data reflecting machine and component operations of the environment is conveyed via the network to the DIQS where it is reflected as timestamped entries in a field-searchable datastore. Monitoring components may search the datastore and identify and record instances of notable events. Triaging models are selectively applied against the notable event instances to produce an enhanced notable event instance representation with modeled results effective to automatically perform or assist in triaging the notable events so they are dispatched in an optimal, effective, and efficient, manner.

Status:
Grant
Type:

Utility

Filling date:

30 Jul 2018

Issue date:

9 Mar 2021