CPC G06F 16/282 (2019.01) [G06F 9/542 (2013.01); G06F 16/213 (2019.01); G06F 16/903 (2019.01); G06Q 10/06393 (2013.01); G06Q 10/10 (2013.01); G06Q 10/20 (2013.01); H04L 41/0604 (2013.01); H04L 41/069 (2013.01); H04L 41/0681 (2013.01); H04L 41/22 (2013.01); H04L 41/5009 (2013.01); H04L 67/535 (2022.05)] | 19 Claims |
1. A method implemented by one or more computing devices, comprising:
generating a plurality of notable events using machine data obtained from an information technology environment, the machine data reflecting activity of one or more components in the information technology environment;
applying, to the plurality of notable events, a score model defined by one or more values of respective substitution variables referenced by a score model template, wherein the one or more values of respective substitution variables are derived from historical data, and wherein the score model produces a set of numeric values, each numeric value reflecting a ranking of a respective notable event against other notable events of the plurality of notable events;
identifying a subset of the plurality of notable events by filtering the plurality of notable events based on a selection criterion applied to the numeric values;
identifying, by applying an action model to the subset of notable events, an action to be performed in response to the subset of notable events; and
generating a display identifying the action to be performed in response to the subset of notable events.
|