IT Operations Platform Evidence Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern IT environments face challenges in analyzing and managing vast amounts of machine-generated data, which can be time-consuming and inefficient due to the complexity and variety of data types and formats generated by numerous components, leading to difficulties in identifying and responding to incidents effectively.
Innovation Solution
An IT operations platform with features like data intake and query systems, flexible schema, and automated evidence identification and management enables efficient data analysis and incident response by allowing users to mark data objects as evidence, perform automated actions, and execute playbooks to streamline incident handling and data retention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis and management of machine-generated data is performed, then data can be examined in detail, but the process becomes time-consuming and inefficient
Solution Approach 1:
The system performs preliminary actions by automatically collecting, normalizing, and storing machine-generated data from multiple sources in a standardized format before incidents occur. This pre-processing includes parsing different data formats, extracting relevant fields, and organizing data in a queryable structure, so that when incidents occur, analysts can immediately query and analyze pre-organized data without manual collection and formatting efforts
Solution Approach 2:
The system replaces manual mechanical analysis with automated computational processes. Automated data collection agents continuously gather data from IT infrastructure components, and automated normalization processes standardize diverse data formats. When incidents occur, automated query systems and alerting mechanisms replace manual data sifting, significantly reducing response time while maintaining analytical capability
2Reliability
If data from numerous components is collected and stored, then comprehensive incident analysis is possible, but data management complexity increases
Solution Approach 1:
The system segments data management by creating separate data collection agents for different IT infrastructure components (servers, networks, applications, databases). Each agent independently collects and pre-processes data from its specific source using component-appropriate formats and parsing rules. This segmentation allows comprehensive data collection while simplifying management, as each segment can be independently configured, monitored, and maintained
Solution Approach 2:
The system implements a universal data normalization layer that receives diverse data from numerous component-specific agents and converts all data into a standardized format with consistent schemas, field names, and data types. This universal normalization approach enables comprehensive incident analysis across all components while simplifying data management, as the standardized structure provides a single management interface for all collected data regardless of origin
3Productivity
If automated actions and playbooks are implemented, then incident response efficiency increases, but system automation complexity increases
Solution Approach 1:
The system performs preliminary actions by pre-defining automated response actions and playbooks for common incident types before incidents occur. These playbooks contain pre-configured sequences of automated actions (such as isolating affected systems, collecting additional diagnostics, or triggering alerts) that can be automatically executed when incident conditions are detected, eliminating the need to design and configure response procedures during time-critical incident response
Solution Approach 2:
The system implements self-service automation where the incident response system automatically detects incidents, queries relevant data, executes appropriate playbooks, and performs remediation actions without human intervention for routine incidents. The system serves itself by automatically monitoring its own state, identifying incidents based on predefined criteria, and triggering appropriate automated responses, thereby increasing efficiency while managing complexity through self-contained automation modules
Data Source
AI summary
Techniques are described for enabling analysts and other users of an IT operations platform to identify certain data objects managed by the platform (for example, events, files, notes, actions results, etc.) as “evidence” when such data objects are believed to be of particular significance to an investigation or other matter. For example, an event generated based on data ingested from an anti-virus service and representing a security-related incident might include artifacts indicating an asset identifier, a hash value of a suspected malicious file, a file path on the infected endpoint, and so forth. An analyst can use various interfaces and interface elements of an IT operations platform to indicate which of such events and/or artifacts, if any, represent evidence in the context of the investigation that the analyst is conducting. In response, the IT operations platform can perform various automated actions.


