×

Incident review interface

  • US 9,158,811 B1
  • Filed: 01/31/2015
  • Issued: 10/13/2015
  • Est. Priority Date: 10/09/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • automatically performing a correlation search in accordance with a defined frequency, the correlation search associated with a service provided by one or more entities that each have corresponding machine data, the service having one or more key performance indicators (KPIs), each KPI defined by a search query that derives a value from the corresponding machine data to indicate a state of the service at a point in time or during a period of time;

    wherein the correlation search associated with the service comprises search criteria pertaining to the one or more KPIs, and a triggering condition to be applied to data identified by a search query using the search criteria;

    storing a notable event in response to the data identified by the search query satisfying the triggering condition; and

    causing display of a graphical user interface presenting information pertaining to the stored notable event, the information comprising an identification of the correlation search that triggered the storing of the notable event and an identification of the service associated with the correlation search;

    wherein each of the entities corresponds to a stored entity definition having an identification of the corresponding machine data, and the service corresponds to a stored service definition referencing the stored entity definitions;

    wherein the method is performed by a computer system comprising one or more processing devices coupled to a memory for storing the notable event, the service definition, the entity definitions, and the KPIs.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×