×

Searchable investigation history for event data store

  • US 10,515,062 B2
  • Filed: 05/09/2016
  • Issued: 12/24/2019
  • Est. Priority Date: 05/09/2016
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving, by a processing device as part of an investigation, a first query comprising a first field value and a first time period, wherein the first field value comprises an internet protocol (IP) address, a port, or a user identification (ID);

    performing, by the processing device, a first search of a data store to identify a first plurality of events having the first time period and at least one field that comprises the first field value;

    generating, by the processing device, a first search object comprising the first field value;

    generating, by the processing device, a first search event comprising the first field value and a reference to the first search object;

    receiving, by the processing device, an indication of one or more search objects that contributed to a resolution of the investigation, the one or more search objects comprising the first search object;

    generating, by the processing device, a resolution object, the resolution object comprising a resolution object identifier, resolution information and references to the one or more search objects;

    generating, by the processing device, a resolution event associated with the resolution object; and

    writing at least one of an event entry for the first search event or an event entry for the resolution event to the data store, wherein the event entry for the first search event is indexed in the data store based on the first field value.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×