首页> 外国专利> Analyzing a group of values extracted from events of machine data relative to a population statistic for those values

Analyzing a group of values extracted from events of machine data relative to a population statistic for those values

机译:分析从机器数据事件中提取的一组值,相对于这些值的总体统计数据

摘要

A metric value is determined for each event in a set of events that characterizes a computational communication or object. For example, a metric value could include a length of a URL or agent string in the event. A subset criterion is generated, such that metric values within the subset are relatively separated from a population's center (e.g., within a distribution tail). Application of the criterion to metric values produces a subset. A representation of the subset is presented in an interactive dashboard. The representation can include unique values in the subset and counts of corresponding event occurrences. Clients can select particular elements in the representation to cause more detail to be presented with respect to individual events corresponding to specific values in the subset. Thus, clients can use their knowledge system operations and observance of value frequencies and underlying events to identify anomalous metric values and potential security threats.
机译:为一组事件中的每个事件确定一个度量值,该度量值表征了计算通信或对象。例如,度量值可以包括事件中URL或代理字符串的长度。生成子集标准,以使子集内的度量值与总体中心(例如在分布尾部内)相对分离。将标准应用于度量值会产生一个子集。子集的表示形式显示在交互式仪表板中。该表示可以包括子集中的唯一值和相应事件发生的计数。客户可以选择表示中的特定元素,以针对与子集中特定值相对应的各个事件提供更多详细信息。因此,客户可以使用他们的知识系统操作以及对值频率和基础事件的观察来识别异常度量值和潜在的安全威胁。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号