IDENTIFYING NOTABLE EVENTS BASED ON EXECUTION OF CORRELATION SEARCHES
First Claim
1. A computer-implemented method, comprising:
- obtaining network data generated by at least one component in an IT environment;
generating event data based on the network data;
receiving input indicating search criteria which, when executed as part of a search query, identify instances of notable events, wherein a notable event comprises one or more events of the event data satisfying the search criteria; and
executing a search query including the search criteria to identify at least one notable event.
1 Assignment
0 Petitions
Accused Products
Abstract
Systems and methods are provided for identifying network addresses and/or IDs of a deduplicated list among network data, machine data, and/or events derived from network data and/or machine data, and for identifying notable events by searching for the presence of network addresses and/or network IDs that are deduplicated across lists received from multiple external sources. One method includes receiving a plurality of lists of network locations, wherein each list is received from over a network, wherein each of the network locations includes a domain name or an IP address, and wherein at least two of the plurality of lists each include a same network location; aggregating the plurality of lists of network locations into a deduplicated list of unique network locations; and searching network data or machine data for a network location included in the deduplicated list of unique network locations.
69 Citations
30 Claims
-
1. A computer-implemented method, comprising:
-
obtaining network data generated by at least one component in an IT environment; generating event data based on the network data; receiving input indicating search criteria which, when executed as part of a search query, identify instances of notable events, wherein a notable event comprises one or more events of the event data satisfying the search criteria; and executing a search query including the search criteria to identify at least one notable event. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A non-transitory computer-readable storage medium storing instructions which, when executed by one or more processors, cause performance of operations, comprising:
-
obtaining network data generated by at least one component in an IT environment; generating event data based on the network data; receiving input indicating search criteria which, when executed as part of a search query, identify instances of notable events, wherein a notable event comprises one or more events of the event data satisfying the search criteria; and executing a search query including the search criteria to identify at least one notable event. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
-
21. An apparatus, comprising:
-
one or more processors; a non-transitory computer-readable storage medium coupled to the one or more processors, the computer-readable storage medium storing instructions which, when executed by the one or more processors, causes the apparatus to; obtain network data generated by at least one component in an IT environment; generate event data based on the network data; receive input indicating search criteria which, when executed as part of a search query, identify instances of notable events, wherein a notable event comprises one or more events of the event data satisfying the search criteria; and execute a search query including the search criteria to identify at least one notable event. - View Dependent Claims (22, 23, 24, 25, 26, 27, 28, 29, 30)
-
Specification