Method and apparatus for event/alert enrichment
US-9170951-B1 · Oct 27, 2015 · US
US10986111B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10986111-B2 |
| Application number | US-201715847478-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 19, 2017 |
| Priority date | Dec 19, 2017 |
| Publication date | Apr 20, 2021 |
| Grant date | Apr 20, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
One or more entities are selected for which logged Events are to be displayed in an Event Series Chart. One or more filters and a timeframe are selected. Events are fetched from one or more selected log files based on the one or more selected filters and the timeframe. The fetched Events are displayed in an Event Series Chart according to an associated timestamp and identification Event property value associated with each fetched Event.
Opening claim text (preview).
What is claimed is: 1. A computer-implemented method, comprising: selecting, by one or more processors, one or more entities for which logged events are to be displayed in an event series chart; selecting, by the one or more processors, one or more filters and a timeframe; fetching, by the one or more processors, events from one or more selected log files based on the one or more filters and the timeframe; generating, by the one or more processors, a display of the fetched events in an event series chart according to an associated timestamp and an identification event property value associated with each fetched event, the event series chart comprising a first portion of the fetched events that occurred with a first frequency that are displayed as a continuous distribution within the timeframe and a second portion of the fetched events that occurred with a second frequency that is lower than the first frequency that are displayed as separate event icons within the timeframe; receiving, by the one or more processors, a user input to adjust the display of the fetched events in the event series chart corresponding to a reduced timeframe that is a portion of the timeframe; and adjusting, by the one or more processors, the display of the fetched events in the event series chart according to the associated timestamp and the identification event property value associated with each fetched event, the event series chart comprising a portion of the first portion of the fetched events that occurred with the first frequency and are displayed as separate event icons within the reduced timeframe and a portion of the second portion of the fetched events that occurred with the second frequency that is lower than the first frequency and are displayed as separate event icons within the reduced timeframe. 2. The computer-implemented method of claim 1 , comprising selecting one or more log files for enterprise threat detection (ETD) analysis containing logged events associated with the one or more entities. 3. The computer-implemented method of claim 1 , wherein the one or more entities are selectable from the group consisting of computing systems, users, servers, proxies, clients, and firewalls. 4. The computer-implemented method of claim 1 , wherein the filters is based on a property associated with an event. 5. The computer-implemented method of claim 1 , wherein the event series chart comprises two identical time axes. 6. The computer-implemented method of claim 1 , comprising enabling zooming and panning functionality for the event series chart. 7. The computer-implemented method of claim 1 , comprising enabling tooltip functionality for property values associated with each displayed event in the event series chart. 8. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising: selecting one or more entities for which logged events are to be displayed in an event series chart; selecting one or more filters and a timeframe; fetching events from one or more selected log files based on the one or more filters and the timeframe; and generating a display of the fetched events in an event series chart according to an associated timestamp and an identification event property value associated with each fetched event, the event series chart comprising a first portion of the fetched events that occurred with a first frequency that are displayed as a continuous distribution within the timeframe and a second portion of the fetched events that occurred with a second frequency that is lower than the first frequency that are displayed as separate event icons within the timeframe; receiving a user input to adjust the display of the fetched events in the event series chart corresponding to a reduced timeframe that is a portion of the timeframe; and adjusting the display of the fetched events in the event series chart according to the associated timestamp and the identification event property value associated with each fetched event, the event series chart comprising a portion of the first portion of the fetched events that occurred with the first frequency and are displayed as separate event icons within the reduced timeframe and a portion of the second portion of the fetched events that occurred with the second frequency that is lower than the first frequency and are displayed as separate event icons within the reduced timeframe. 9. The non-transitory, computer-readable medium of claim 8 , the operations comprising one or more instructions for selecting one or more log files for enterprise threat detection (ETD) analysis containing logged events associated with the one or more entities. 10. The non-transitory, computer-readable medium of claim 8 , wherein the one or more entities are selectable from the group consisting of computing systems, users, servers, proxies, clients, and firewalls. 11. The non-transitory, computer-readable medium of claim 8 , wherein the filters is based on a property associated with an event. 12. The non-transitory, computer-readable medium of claim 8 , wherein the event series chart comprises two identical time axes. 13. The non-transitory, computer-readable medium of claim 8 , the operations comprising enabling zooming and panning functionality for the event series chart. 14. The non-transitory, computer-readable medium of claim 8 , the operations comprising enabling tooltip functionality for property values associated with each displayed event in the event series chart. 15. A computer-implemented system, comprising: one or more computers; and one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising: selecting one or more entities for which logged events are to be displayed in an event series chart; selecting one or more filters and a timeframe; fetching events from one or more selected log files based on the one or more filters and the timeframe; and generating a display of the fetched events in an event series chart according to an associated timestamp and an identification event property value associated with each fetched event, the event series chart comprising a first portion of the fetched events that occurred with a first frequency that are displayed as a continuous distribution within the timeframe and a second portion of the fetched events that occurred with a second frequency that is lower than the first frequency that are displayed as separate event icons within the timeframe; receiving a user input to adjust the display of the fetched events in the event series chart corresponding to a reduced timeframe that is a portion of the timeframe; and adjusting the display of the fetched events in the event series chart according to the associated timestamp and the identification event property value associated with each fetched event, the event series chart comprising a portion of the first portion of the fetched events that occurred with the first frequency and are displayed as separate event icons within the reduced timeframe and a portion of the second portion of the fetched events that occurred with the second frequency that is lower than the first frequency and are displayed as separate event icons within the reduced timeframe. 16. The computer-implemented system of claim 15 , the one or more operations comprising one or more instructions for selecting the one or more log files for ent
Scrolling or panning · CPC title
Zoom, i.e. interaction techniques or interactors for controlling the zooming operation · CPC title
Filtering policies (mail message filtering H04L51/212) · CPC title
Selection of displayed objects or displayed text elements (G06F3/0482 takes precedence) · CPC title
Interaction with lists of selectable items, e.g. menus · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.