US 11,818,018 B1
Configuring event streams based on identified security risks
Fang I. Hsiao, Berkeley, CA (US); Clayton S. Ching, Sunnyvale, CA (US); Michael R. Dickey, Palo Alto, CA (US); Vladimir A. Shcherbakov, Pleasanton, CA (US); Nishant Teredesai, Mountain View, CA (US); and Cary Glen Noel, Pleasant Hill, CA (US)
Assigned to Splunk Inc., San Francisco, CA (US)
Filed by Splunk Inc., San Francisco, CA (US)
Filed on Jul. 27, 2022, as Appl. No. 17/875,170.
Application 17/875,170 is a continuation of application No. 16/670,816, filed on Oct. 31, 2019, granted, now 11,451,453.
Application 16/670,816 is a continuation of application No. 14/610,457, filed on Jan. 30, 2015, granted, now 10,523,521, issued on Dec. 31, 2019.
Application 14/610,457 is a continuation in part of application No. 14/528,898, filed on Oct. 30, 2014, granted, now 9,838,512, issued on Nov. 13, 2018.
Application 14/528,898 is a continuation in part of application No. 14/253,713, filed on Apr. 15, 2014, granted, now 10,127,273, issued on Dec. 5, 2017.
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 41/22 (2022.01); H04L 43/022 (2022.01); H04L 43/045 (2022.01)
CPC H04L 41/22 (2013.01) [H04L 43/022 (2013.01); H04L 43/045 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method comprising:
causing display of an interface including an indication of a potential security risk affecting one or more computing resources of a computing environment, wherein the potential security risk is identified based on event data received from a remote capture agent in the computing environment;
receiving input selecting the potential security risk and requesting generation of additional event data related to the potential security risk, wherein receiving the input causes a configuration server to:
generate configuration information to be used by the remote capture agent in the computing environment to generate the additional event data, wherein the additional event data is generated based on network data monitored by the remote capture agent; and
send the configuration information to the remote capture agent, wherein the remote capture agent uses the configuration information to generate the additional event data and to send the additional event data to another component for subsequent processing.