Displaying a series of events along a time axis in enterprise threat detection

US10986111B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10986111-B2
Application numberUS-201715847478-A
CountryUS
Kind codeB2
Filing dateDec 19, 2017
Priority dateDec 19, 2017
Publication dateApr 20, 2021
Grant dateApr 20, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

One or more entities are selected for which logged Events are to be displayed in an Event Series Chart. One or more filters and a timeframe are selected. Events are fetched from one or more selected log files based on the one or more selected filters and the timeframe. The fetched Events are displayed in an Event Series Chart according to an associated timestamp and identification Event property value associated with each fetched Event.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, comprising: selecting, by one or more processors, one or more entities for which logged events are to be displayed in an event series chart; selecting, by the one or more processors, one or more filters and a timeframe; fetching, by the one or more processors, events from one or more selected log files based on the one or more filters and the timeframe; generating, by the one or more processors, a display of the fetched events in an event series chart according to an associated timestamp and an identification event property value associated with each fetched event, the event series chart comprising a first portion of the fetched events that occurred with a first frequency that are displayed as a continuous distribution within the timeframe and a second portion of the fetched events that occurred with a second frequency that is lower than the first frequency that are displayed as separate event icons within the timeframe; receiving, by the one or more processors, a user input to adjust the display of the fetched events in the event series chart corresponding to a reduced timeframe that is a portion of the timeframe; and adjusting, by the one or more processors, the display of the fetched events in the event series chart according to the associated timestamp and the identification event property value associated with each fetched event, the event series chart comprising a portion of the first portion of the fetched events that occurred with the first frequency and are displayed as separate event icons within the reduced timeframe and a portion of the second portion of the fetched events that occurred with the second frequency that is lower than the first frequency and are displayed as separate event icons within the reduced timeframe. 2. The computer-implemented method of claim 1 , comprising selecting one or more log files for enterprise threat detection (ETD) analysis containing logged events associated with the one or more entities. 3. The computer-implemented method of claim 1 , wherein the one or more entities are selectable from the group consisting of computing systems, users, servers, proxies, clients, and firewalls. 4. The computer-implemented method of claim 1 , wherein the filters is based on a property associated with an event. 5. The computer-implemented method of claim 1 , wherein the event series chart comprises two identical time axes. 6. The computer-implemented method of claim 1 , comprising enabling zooming and panning functionality for the event series chart. 7. The computer-implemented method of claim 1 , comprising enabling tooltip functionality for property values associated with each displayed event in the event series chart. 8. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising: selecting one or more entities for which logged events are to be displayed in an event series chart; selecting one or more filters and a timeframe; fetching events from one or more selected log files based on the one or more filters and the timeframe; and generating a display of the fetched events in an event series chart according to an associated timestamp and an identification event property value associated with each fetched event, the event series chart comprising a first portion of the fetched events that occurred with a first frequency that are displayed as a continuous distribution within the timeframe and a second portion of the fetched events that occurred with a second frequency that is lower than the first frequency that are displayed as separate event icons within the timeframe; receiving a user input to adjust the display of the fetched events in the event series chart corresponding to a reduced timeframe that is a portion of the timeframe; and adjusting the display of the fetched events in the event series chart according to the associated timestamp and the identification event property value associated with each fetched event, the event series chart comprising a portion of the first portion of the fetched events that occurred with the first frequency and are displayed as separate event icons within the reduced timeframe and a portion of the second portion of the fetched events that occurred with the second frequency that is lower than the first frequency and are displayed as separate event icons within the reduced timeframe. 9. The non-transitory, computer-readable medium of claim 8 , the operations comprising one or more instructions for selecting one or more log files for enterprise threat detection (ETD) analysis containing logged events associated with the one or more entities. 10. The non-transitory, computer-readable medium of claim 8 , wherein the one or more entities are selectable from the group consisting of computing systems, users, servers, proxies, clients, and firewalls. 11. The non-transitory, computer-readable medium of claim 8 , wherein the filters is based on a property associated with an event. 12. The non-transitory, computer-readable medium of claim 8 , wherein the event series chart comprises two identical time axes. 13. The non-transitory, computer-readable medium of claim 8 , the operations comprising enabling zooming and panning functionality for the event series chart. 14. The non-transitory, computer-readable medium of claim 8 , the operations comprising enabling tooltip functionality for property values associated with each displayed event in the event series chart. 15. A computer-implemented system, comprising: one or more computers; and one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising: selecting one or more entities for which logged events are to be displayed in an event series chart; selecting one or more filters and a timeframe; fetching events from one or more selected log files based on the one or more filters and the timeframe; and generating a display of the fetched events in an event series chart according to an associated timestamp and an identification event property value associated with each fetched event, the event series chart comprising a first portion of the fetched events that occurred with a first frequency that are displayed as a continuous distribution within the timeframe and a second portion of the fetched events that occurred with a second frequency that is lower than the first frequency that are displayed as separate event icons within the timeframe; receiving a user input to adjust the display of the fetched events in the event series chart corresponding to a reduced timeframe that is a portion of the timeframe; and adjusting the display of the fetched events in the event series chart according to the associated timestamp and the identification event property value associated with each fetched event, the event series chart comprising a portion of the first portion of the fetched events that occurred with the first frequency and are displayed as separate event icons within the reduced timeframe and a portion of the second portion of the fetched events that occurred with the second frequency that is lower than the first frequency and are displayed as separate event icons within the reduced timeframe. 16. The computer-implemented system of claim 15 , the one or more operations comprising one or more instructions for selecting the one or more log files for ent

Assignees

Inventors

Classifications

  • Scrolling or panning · CPC title

  • Zoom, i.e. interaction techniques or interactors for controlling the zooming operation · CPC title

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • Selection of displayed objects or displayed text elements (G06F3/0482 takes precedence) · CPC title

  • Interaction with lists of selectable items, e.g. menus · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10986111B2 cover?
One or more entities are selected for which logged Events are to be displayed in an Event Series Chart. One or more filters and a timeframe are selected. Events are fetched from one or more selected log files based on the one or more selected filters and the timeframe. The fetched Events are displayed in an Event Series Chart according to an associated timestamp and identification Event propert…
Who is the assignee on this patent?
Sap Se
What technology area does this patent fall under?
Primary CPC classification H04L63/0227. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 20 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).