发明名称 BLACKLISTING AND WHITELISTING OF SECURITY-RELATED EVENTS
摘要 A disclosed computer-implemented method includes receiving and indexing the raw data. Indexing includes dividing the raw data into time stamped searchable events that include information relating to computer or network security. Store the indexed data in an indexed data store and extract values from a field in the indexed data using a schema. Search the extracted field values for the security information. Determine a group of security events using the security information. Each security event includes a field value specified by a criteria. Present a graphical interface (GI) including a summary of the group of security events, other summaries of security events, and a remove element (associated with the summary). Receive input corresponding to an interaction of the remove element. Interacting with the remove element causes the summary to be removed from the GI. Update the GI to remove the summary from the GI.
申请公布号 US2013318604(A1) 申请公布日期 2013.11.28
申请号 US201313956285 申请日期 2013.07.31
申请人 SPLUNK INC. 发明人 COATES JOHN;MURPHEY LUCAS;HAZEKAMP DAVID;HANSEN JAMES
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址
您可能感兴趣的专利