Blacklisting and whitelisting of security-related events
First Claim
1. A method, comprising:
- receiving raw data from one or more data sources;
segmenting the raw data into a plurality of time-stamped, searchable events, wherein each event in the plurality of time-stamped, searchable events includes information relating to performance or security of an information technology system;
creating an event group from the plurality of time-stamped, searchable events, each event in the event group matching criteria relating to one or more fields;
determining an event group summary, the summary summarizing one or more fields of the events in the event group;
causing display of a graphical user interface displaying a plurality of event group summaries including the event group summary;
based on user input in response to the display of the graphical user interface, placing a selected event group summary on a whitelist or a blacklist, wherein placing the selected event group summary on the whitelist removes the selected event group summary from the displayed plurality of event group summaries, and wherein placing the selected event group summary on the blacklist changes a visual appearance of the selected event group summary among the displayed plurality of event group summaries;
wherein the method is performed by one or more computing devices.
1 Assignment
0 Petitions
Accused Products
Abstract
A disclosed computer-implemented method includes receiving and indexing the raw data. Indexing includes dividing the raw data into time stamped searchable events that include information relating to computer or network security. Store the indexed data in an indexed data store and extract values from a field in the indexed data using a schema. Search the extracted field values for the security information. Determine a group of security events using the security information. Each security event includes a field value specified by a criteria. Present a graphical interface (GI) including a summary of the group of security events, other summaries of security events, and a remove element (associated with the summary). Receive input corresponding to an interaction of the remove element. Interacting with the remove element causes the summary to be removed from the GI. Update the GI to remove the summary from the GI.
-
Citations
21 Claims
-
1. A method, comprising:
-
receiving raw data from one or more data sources; segmenting the raw data into a plurality of time-stamped, searchable events, wherein each event in the plurality of time-stamped, searchable events includes information relating to performance or security of an information technology system; creating an event group from the plurality of time-stamped, searchable events, each event in the event group matching criteria relating to one or more fields; determining an event group summary, the summary summarizing one or more fields of the events in the event group; causing display of a graphical user interface displaying a plurality of event group summaries including the event group summary; based on user input in response to the display of the graphical user interface, placing a selected event group summary on a whitelist or a blacklist, wherein placing the selected event group summary on the whitelist removes the selected event group summary from the displayed plurality of event group summaries, and wherein placing the selected event group summary on the blacklist changes a visual appearance of the selected event group summary among the displayed plurality of event group summaries; wherein the method is performed by one or more computing devices. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. An apparatus, comprising:
-
a subsystem, implemented at least partially in hardware, that receives raw data from one or more data sources; a subsystem, implemented at least partially in hardware, that segments the raw data into a plurality of time-stamped, searchable events, wherein each event in the plurality of time-stamped, searchable events includes information relating to performance or security of an information technology system; a subsystem, implemented at least partially in hardware, that creates an event group from the plurality of time-stamped, searchable events, each event in the event group matching criteria relating to one or more fields; a subsystem, implemented at least partially in hardware, that determines an event group summary, the summary summarizing one or more fields of the events in the event group; a subsystem, implemented at least partially in hardware, that causing display of a graphical user interface that displays a plurality of event group summaries including the event group summary; a list subsystem, implemented at least partially in hardware, that, based on user input in response to the display of the graphical user interface, places a selected event group summary on a whitelist or a blacklist, wherein when the list subsystem places the selected event group summary on the whitelist the list subsystem removes the selected event group summary from the displayed plurality of event group summaries, and wherein when the list subsystem places the selected event group summary on the blacklist the list subsystem changes a visual appearance of the selected event group summary among the displayed plurality of event group summaries. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
-
15. A non-transitory computer readable medium, storing software instructions, which when executed by one or more processors cause performance of:
-
receiving raw data from one or more data sources; segmenting the raw data into a plurality of time-stamped, searchable events, wherein each event in the plurality of time-stamped, searchable events includes information relating to performance or security of an information technology system; creating an event group from the plurality of time-stamped, searchable events, each event in the event group matching criteria relating to one or more fields; determining an event group summary, the summary summarizing one or more fields of the events in the event group; causing display of a graphical user interface displaying a plurality of event group summaries including the event group summary; based on user input in response to the display of the graphical user interface, placing a selected event group summary on a whitelist or a blacklist, wherein placing the selected event group summary on the whitelist removes the selected event group summary from the displayed plurality of event group summaries, and wherein placing the selected event group summary on the blacklist changes a visual appearance of the selected event group summary among the displayed plurality of event group summaries. - View Dependent Claims (16, 17, 18, 19, 20, 21)
-
Specification