Presentation And Sorting Of Summaries Of Alert Instances Triggered By Search Questions

US2016253415A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016253415-A1
Application numberUS-201414396366-A
CountryUS
Kind codeA1
Filing dateJul 9, 2014
Priority dateJul 9, 2014
Publication dateSep 1, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods for presenting and sorting summaries of alerts triggered by search queries in data aggregation and analysis systems. An example method may comprise: causing, by one or more processing devices, one or more alert summaries to be displayed, each alert summary corresponding to an alert and representing one or more instances of the alert, the alert defined by a search query and a triggering condition; wherein an instance of the alert corresponds to a particular dataset that (i) is generated by executing the search query over time-series data falling within a particular time range in a set of time ranges over which the search query has been instructed to search, and (ii) satisfies the triggering condition for the alert; wherein an alert summary includes an indication of at least one of: a total count of alert instances generated by the alert, or a count of alert instances generated by the alert that have not been viewed by a user.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method, comprising: causing, by one or more processing devices, one or more alert summaries to be displayed, each alert summary corresponding to an alert and representing one or more instances of the alert, the alert defined by a search query and a triggering condition; wherein an instance of the alert corresponds to a particular dataset that (i) is generated by executing the search query over time-series data falling within a particular time range in a set of time ranges over which the search query has been instructed to search, and (ii) satisfies the triggering condition for the alert; wherein an alert summary includes an indication of at least one of: a total count of alert instances generated by the alert, or a count of alert instances generated by the alert that have not been viewed by a user. 2 . The method of claim 1 , wherein the alert summary comprises a selectable user interface element visually representing the alert, a title of the alert, or a description of the alert. 3 . The method of claim 1 , further comprising: receiving a selection of a particular displayed alert summary; and based on the selection of the alert summary, causing one or more alert instances represented by the selected alert summary to be displayed. 4 . The method of claim 1 , further comprising: receiving a selection of a particular displayed alert summary; based on the selection of the alert summary, causing one or more alert instances represented by the selected alert summary to be displayed; receiving a selection of a particular displayed alert instance; and based on the selection of the alert instance, causing a data set that has triggered the selected alert instance to be displayed. 5 . The method of claim 1 , further comprising: for each alert summary, maintaining an unviewed instance count of alert instances of a respective alert that have not been viewed. 6 . The method of claim 1 , further comprising: for each alert summary, updating an unviewed instance count of alert instances of a respective alert that have not been viewed; and causing the updated unviewed instance count to be displayed with the alert summary. 7 . The method of claim 1 , further comprising: updating, for each alert summary, an unviewed instance count of alert instances of a respective alert that have not been viewed; and causing the alert summaries to be displayed in a sorted order according to unviewed instance counts of the alert summaries. 8 . The method of claim 1 , further comprising: updating a count of alert instances that have been generated by the alert corresponding to the alert summary; and causing the updated count of alert instances of the event to be displayed with the alert summary. 9 . The method of claim 1 , further comprising: updating, for each alert summary, a total count of alert instances of a respective alert; and causing the alert summaries to be displayed in a sorted order according to the total counts of the alert instances of the respective alerts of the alert summaries. 10 . The method of claim 1 , further comprising: executing the search query over the time-series data falling within the particular time range to produce the particular dataset; responsive to determining that the dataset satisfies the triggering condition, generating the instance of the alert. 11 . The method of claim 1 , further comprising: executing the search query over the time-series data falling within the particular time range to produce the particular dataset; responsive to determining that the dataset satisfies the triggering condition, generating the instance of the alert; and updating a count of alert instances generated for the alert corresponding to the alert summary. 12 . The method of claim 1 , further comprising: executing the search query over the time-series data falling within the particular time range to produce the particular dataset, wherein execution of the search query includes applying a late binding schema to the time-series data, the late binding schema including one or more fields defined by one or more extraction rules; responsive to determining that the particular dataset satisfies the triggering condition, generating an instance of the alert. 13 . The method of claim 1 , wherein the alert summaries are displayed by either a desktop computing device or a mobile computing device. 14 . The method of claim 1 , wherein the time-series data includes portions of raw machine data. 15 . The method of claim 1 , wherein determining whether the particular dataset satisfies the triggering condition for the alert includes comparing a number of data items in the particular dataset with a threshold value. 16 . The method of claim 1 , wherein determining whether the particular dataset satisfies the triggering condition includes performing a secondary conditional search on the particular dataset. 17 . A computer system comprising: a memory; and one or more processing devices, coupled to the memory, to: cause, by one or more processing devices, one or more alert summaries to be displayed, each alert summary corresponding to an alert and representing one or more instances of the alert, the alert defined by a search query and a triggering condition; wherein an instance of the alert corresponds to a particular dataset that (i) is generated by executing the search query over time-series data falling within a particular time range in a set of time ranges over which the search query has been instructed to search, and (ii) satisfies the triggering condition for the alert; wherein an alert summary includes an indication of at least one of: a total count of alert instances generated by the alert, or a count of alert instances generated by the alert that have not been viewed by a user. 18 . The computer system of claim 17 , wherein the alert summary comprises a selectable user interface element visually representing the alert, a title of the alert, or a description of the alert. 19 . The computer system of claim 17 , wherein the processing devices are further to: receive a selection of a particular displayed alert summary; and based on the selection of the alert summary, cause one or more alert instances represented by the selected alert summary to be displayed. 20 . The computer system of claim 17 , wherein the processing devices are further to: receive a selection of a particular displayed alert summary; based on the selection of the alert summary, cause one or more alert instances represented by the selected alert summary to be displayed; receive a selection of a particular displayed alert instance; and based on the selection of the alert instance, cause a data set that has triggered the selected alert instance to be displayed. 21 . The computer system of claim 17 , wherein the processing devices are further to: for each alert summary, maintain an unviewed instance count of alert instances of a respective alert that have not been viewed. 22 . The computer system of claim 17 , wherein the processing devices are further to: for each alert summary, update an unviewed instance count of alert instances of a respective alert that have not been viewed; and cause the updated unviewed instance count to be displayed with the alert summary. 23 . The computer system of claim 17 , wherein the processing devices are further to: update, for each alert summary, an unviewed i

Assignees

Inventors

Classifications

  • Triggers; Constraints · CPC title

  • Query processing · CPC title

  • Event management; Broadcasting; Multicasting; Notifications · CPC title

  • G06F16/345Primary

    Summarisation for human users · CPC title

  • Selection of displayed objects or displayed text elements (G06F3/0482 takes precedence) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016253415A1 cover?
Systems and methods for presenting and sorting summaries of alerts triggered by search queries in data aggregation and analysis systems. An example method may comprise: causing, by one or more processing devices, one or more alert summaries to be displayed, each alert summary corresponding to an alert and representing one or more instances of the alert, the alert defined by a search query and a…
Who is the assignee on this patent?
Splunk Inc
What technology area does this patent fall under?
Primary CPC classification G06F16/345. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Sep 01 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).