US 12,174,812 B2
Searchable investigation history for event data store
Kenny Tidwell, Los Altos, CA (US); David Frampton, Portola Valley, CA (US); and Brendan O'Connell, Sandown, NH (US)
Assigned to Sumo Logic, Inc., Redwood City, CA (US)
Filed by Sumo Logic, Inc., Redwood City, CA (US)
Filed on Sep. 12, 2023, as Appl. No. 18/465,472.
Application 18/465,472 is a continuation of application No. 17/662,721, filed on May 10, 2022.
Application 17/662,721 is a continuation of application No. 16/656,448, filed on Oct. 17, 2019, granted, now 11,360,957.
Application 16/656,448 is a continuation of application No. 15/150,131, filed on May 9, 2016, granted, now 10,515,062.
Prior Publication US 2023/0418796 A1, Dec. 28, 2023
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 16/22 (2019.01); G06F 11/30 (2006.01); G06F 16/245 (2019.01); G06F 16/28 (2019.01); G06F 21/00 (2013.01); G06F 21/55 (2013.01); G06Q 10/10 (2023.01); H04L 9/40 (2022.01)
CPC G06F 16/2228 (2019.01) [G06F 11/30 (2013.01); G06F 16/245 (2019.01); G06F 16/282 (2019.01); G06F 21/00 (2013.01); G06F 21/55 (2013.01); G06F 21/552 (2013.01); G06F 21/554 (2013.01); G06Q 10/10 (2013.01); H04L 63/1416 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method comprising:
performing one or more search queries for querying an event data store, the search queries being part of an investigation;
storing, in the event data store, search object associated with each search query during the investigation, where at least one search query references a previously-executed search query that produced results to generate the at least one search query;
creating a resolution object after reaching a resolution of the investigation, the resolution object comprising information on search objects that contributed to the resolution of the investigation;
receiving a new search query;
detecting that the new search query matches search values during the investigation;
presenting, in response to the detecting, details of the investigation and the resolution of the investigation, the presenting comprising providing options to select any of the search objects from the investigation;
detecting a selection of one of the search objects from the investigation;
executing a new query based on the selected search object; and
causing presentation of results from the new query.