US 11,816,108 B1
Dynamic alert messages using tokens based on searching events
Nicholas John Filippi, Atherton, CA (US); Katherine Kyle Feeney, Oakland, CA (US); Cory Eugene Burke, San Bruno, CA (US); Abhinav Prasad Nekkanti, Daly City, CA (US); Marc Vincent Robichaud, San Francisco, CA (US); and Irina Korobova, San Francisco, CA (US)
Assigned to Splunk Inc., San Francisco, CA (US)
Filed by SPLUNK INC., San Francisco, CA (US)
Filed on Jun. 2, 2022, as Appl. No. 17/805,095.
Application 17/805,095 is a continuation of application No. 16/260,998, filed on Jan. 29, 2019, granted, now 11,392,590.
Application 16/260,998 is a continuation of application No. 14/528,905, filed on Oct. 30, 2014, granted, now 10,223,423, issued on Mar. 5, 2019.
Claims priority of provisional application 62/058,952, filed on Oct. 2, 2014.
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 16/20 (2019.01); G06F 16/2455 (2019.01); G06F 11/07 (2006.01); H04L 41/0631 (2022.01); G06F 11/00 (2006.01); G06Q 10/00 (2023.01); H04L 41/00 (2022.01); G06F 16/9536 (2019.01); G06F 9/54 (2006.01); G06F 16/00 (2019.01); G06F 16/25 (2019.01)
CPC G06F 16/24565 (2019.01) [G06F 9/542 (2013.01); G06F 11/00 (2013.01); G06F 11/0709 (2013.01); G06F 11/0751 (2013.01); G06F 11/0766 (2013.01); G06F 16/9536 (2019.01); G06Q 10/00 (2013.01); H04L 41/00 (2013.01); H04L 41/0631 (2013.01); G06F 16/00 (2019.01); G06F 16/254 (2019.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method, comprising:
receiving, from a user interface, an assignment of one or more tokens for use in generating a message for an alert, the one or more tokens defining first one or more values generated from second one or more values of one or more fields of search results of a search query, wherein a triggering condition of the alert is evaluated against the search results during execution of the search query, the execution determining the search results as a subset of events that meet criteria specified by the search query,
wherein the search query is performed on the events in a data store, an event of the events including a portion of raw machine data associated with a timestamp,
wherein the criteria specified by the search query includes at least a field of the one or more fields, the field defined by an extraction rule for extracting a subportion of text from the portion of raw machine data in the event to produce a value of the second one or more values for the field for the event; and
based at least on the triggering condition being satisfied, causing display of the message including the first one or more values of the one or more tokens on a user device associated with the alert.