Collaborative incident management for networked computing systems

US11258693B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11258693-B2
Application numberUS-202016863533-A
CountryUS
Kind codeB2
Filing dateApr 30, 2020
Priority dateSep 25, 2017
Publication dateFeb 22, 2022
Grant dateFeb 22, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Information technology environment monitoring systems, for example, perform analytics over machine data received from networked entities. Outputs of such a system may be useful to help a user identify a problem and resolve an incident. Inventive aspects enable user interactions to trigger automatic connection with network servers to establish communication channels for conveying analytics and other information related to the problem between and among network nodes participating in the resolution of the problem or incident.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, comprising: receiving one or more parameters associated with an incident occurring within a networked computing environment, wherein the one or more parameters specify (i) a first type of communications channel for establishing communications associated with the incident, and (ii) one or more members of an incident response team associated with the incident; enabling, based on the one or more parameters, communications over a network with at least one member included in the incident response team via a communications channel, wherein the communications channel is of the first type; identifying, based on the one or more parameters, at least one service affected by the incident; and causing display of a visualization indicating information associated with the at least one service. 2. The computer-implemented method of claim 1 , further comprising causing display of a first interactive element associated with the communications channel. 3. The computer-implemented method of claim 1 , further comprising causing display of a timeline that includes one or more key events associated with the incident, wherein each key event is displayed on the timeline at a given time at which the key event occurred. 4. The computer-implemented method of claim 1 , further comprising causing display of a timeline that includes one or more key events and a screenshot view, wherein the screenshot view displays a given screen shot based on a selection of a given key event on the timeline. 5. The computer-implemented method of claim 1 , further comprising: transmitting a search query via the network at a plurality of different times within a first range of time; for each time included in the plurality of different times, receiving a different value indicating a measure of the at least one service; and causing display of a second visualization based on the different values indicating the measure of the at least one service at the plurality of different times. 6. The computer-implemented method of claim 1 , further comprising: transmitting a search query via the network at a plurality of different times within a first range of time; for each time included in the plurality of different times, receiving a different value indicating a measure of the at least one service; determining that at least one value included in the different values exceeds a threshold; and transmitting, to the one or more members via the communications channel, a notification indicating that the at least one value exceeded the threshold. 7. The computer-implemented method of claim 1 , further comprising: transmitting a search query via the network at a plurality of different times within a first range of time; for each time included in the plurality of different times, receiving a different value indicating a measure of the at least one service; determining that at least one value included in the different values exceeds a threshold; retrieving incident-related data associated with the at least one service represented by a stored service definition; and causing display of the at least one value and the incident-related data. 8. The computer-implemented method of claim 1 , wherein the at least one service includes a plurality of services, each service being represented by a different service definition, and further comprising: for each service included in the plurality of services, receiving a different value indicating a measure of the service; causing display of a plurality of graphical controls, wherein each graphical control included in the plurality of graphical controls corresponds to a different service included in the plurality of services; and causing display of a plurality of graphical indicators, wherein: each graphical indicator included in the plurality of graphical indicators is displayed in conjunction with a corresponding graphical control included in the plurality of graphical controls, and each graphical indicator included in the plurality of graphical indicators includes a value indicating a measure of a corresponding service included in the plurality of services. 9. The computer-implemented method of claim 1 , further comprising: identifying a check item for a task related to resolving the incident; receiving a drag-and-drop action between a graphical control that corresponds to the check item, and the visualization indicating a status of the at least one service; and in response to receiving the drag-and-drop action, associating the check item with the at least one service. 10. The computer-implemented method of claim 1 , wherein the at least one service includes a plurality of services, each service being represented by a different service definition, and further comprising: receiving, via the network, information that identifies interdependencies among the services included in the plurality of services; and causing display of a second visualization indicating the interdependencies among the services included in the plurality of services. 11. One or more non-transitory computer-readable storage media including instructions that, when executed by one or more processors, cause the one or more processors to perform the steps of: receiving one or more parameters associated with an incident occurring within a networked computing environment, wherein the one or more parameters specify (i) a first type of communications channel for establishing communications associated with the incident, and (ii) one or more members of an incident response team associated with the incident; enabling, based on the one or more parameters, communications over a network with at least one member included in the incident response team via a communications channel, wherein the communications channel is of the first type; identifying, based on the one or more parameters, at least one service affected by the incident; and causing display of a visualization indicating information associated with the at least one service. 12. The one or more non-transitory computer-readable media of claim 11 , further comprising causing display of a first interactive element associated with the communications channel. 13. The one or more non-transitory computer-readable media of claim 11 , further comprising causing display of a timeline that includes one or more key events associated with the incident, wherein each key event is displayed on the timeline at a given time at which the key event occurred. 14. The one or more non-transitory computer-readable media of claim 11 , further comprising causing display of a timeline that includes one or more key events and a screenshot view, wherein the screenshot view displays a given screen shot based on a selection of a given key event on the timeline. 15. The one or more non-transitory computer-readable media of claim 11 , further comprising: transmitting a search query via the network at a plurality of different times within a first range of time; for each time included in the plurality of different times, receiving a different value indicating a measure of the at least one service; and causing display of a second visualization based on the different values indicating the measure of the at least one service at the plurality of different times. 16. The one or more non-transitory computer-readable media of claim 11 , further comprising: transmitting a search query via the network at a plurality of different times within a first range of time; for each time included in the plurality of different times, receiving a different value indicating a m

Assignees

Inventors

Classifications

  • H04L43/16Primary

    Threshold monitoring · CPC title

  • H04L41/22Primary

    comprising specially adapted graphical user interfaces [GUI] · CPC title

  • Measuring contribution of individual network components to actual service level · CPC title

  • Delays · CPC title

  • Indexing; Web crawling techniques · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11258693B2 cover?
Information technology environment monitoring systems, for example, perform analytics over machine data received from networked entities. Outputs of such a system may be useful to help a user identify a problem and resolve an incident. Inventive aspects enable user interactions to trigger automatic connection with network servers to establish communication channels for conveying analytics and o…
Who is the assignee on this patent?
Splunk Inc
What technology area does this patent fall under?
Primary CPC classification H04L43/16. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 22 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).