Splunk Inc.
PROVIDING ACTION RECOMMENDATIONS BASED ON ACTION EFFECTIVENESS ACROSS INFORMATION TECHNOLOGY ENVIRONMENTS

Last updated:

Abstract:

Systems, methods, and software described herein provide action recommendations to administrators of a computing environment based on effectiveness of previously implemented actions. In one example, an advisement system identifies a security incident for an asset in the computing environment, and obtains enrichment information for the incident. Based on the enrichment information a rule set and associated recommended security actions are identified for the incident. Once the recommended security actions are identified, a subset of the action recommendations are organized based on previous action implementations in the computing environment, and the subset is provided to an administrator for selection.

Status:
Application
Type:

Utility

Filling date:

20 May 2021

Issue date:

9 Sep 2021