Conexus LLC v. Splunk Inc.: Cybersecurity Patent Case Dismissed With Prejudice in 7 Days
Conexus LLC filed suit against Splunk Inc. in the District of Delaware asserting US10812497B2, a patent covering systems for detecting security threats via application execution and connection lineage tracing. The case was voluntarily dismissed with prejudice just 7 days after filing — one of the shortest lifecycles seen in Delaware patent litigation.
A Delaware cybersecurity patent suit resolved before the defendant could respond
On July 17, 2025, Conexus LLC filed a patent infringement action against Splunk, Inc. in the U.S. District Court for the District of Delaware before Judge Jennifer L. Hall. The suit centred on US10812497B2, a patent directed at systems and methods for detecting and responding to security threats through application execution and connection lineage tracing — a technology domain directly relevant to Splunk’s core security information and event management (SIEM) business.
Just seven days later, on July 24, 2025, Conexus filed a voluntary notice of dismissal with prejudice pursuant to Rule 41(a)(1)(A)(i) of the Federal Rules of Civil Procedure. The dismissal was self-executing — requiring no court order because it was filed before Splunk had served an answer or motion for summary judgment. Critically, the ‘with prejudice’ designation permanently bars Conexus from re-asserting the same claims against Splunk on the same patent.
The resolution timeline of seven days is exceptional even by the standards of rapid pre-answer dismissals and likely reflects an out-of-court resolution, licensing agreement, or a strategic reassessment by Conexus rather than any merits adjudication. The public record is silent on the underlying commercial terms, if any. The mutual cost-bearing provision is consistent with a negotiated exit rather than a plaintiff concession under duress.
Filing to Dismissed with Prejudice in 7 days
7 days from filing to dismissal — far below the median Delaware patent case lifecycle of 2+ years
Dismissed with prejudice: what the Rule 41 exit means for both parties
Rule 41(a)(1)(A)(i): self-executing dismissal before answer
Under Rule 41(a)(1)(A)(i), a plaintiff may dismiss an action without a court order by filing a notice before the opposing party serves an answer or a motion for summary judgment. The ‘with prejudice’ designation was voluntarily added by Conexus — it was not compelled. This makes the dismissal a final adjudication on the merits for res judicata purposes, permanently extinguishing Conexus’s right to re-litigate the same claims against Splunk on US10812497B2.
Permanent bar on re-filingConexus permanently forfeits its claims against Splunk
By accepting a with-prejudice dismissal, Conexus surrendered its litigation leverage against Splunk on US10812497B2 in perpetuity. This is a significant concession relative to a without-prejudice dismissal, which would have preserved optionality. The most commercially rational explanation is that a licensing or settlement agreement was reached privately, making continued litigation unnecessary — though the public record does not confirm this.
Claims extinguished vs. SplunkSplunk exits litigation cleanly with no record of liability
Splunk achieved a full exit without filing a single responsive pleading. There is no finding of infringement, no damages award, and no injunctive exposure. Crucially, no invalidity determination was made — US10812497B2 remains a valid, enforceable patent that Conexus could assert against other parties in the SIEM and cybersecurity sector. Splunk’s own costs and fees are self-borne, consistent with a negotiated resolution.
No liability finding; patent survivesUS10812497B2 remains live — threat to other security platform vendors
The dismissal resolves only the Conexus–Splunk dispute. US10812497B2 is not invalidated and Conexus retains full enforcement rights against the broader market. Vendors offering application-level threat detection, EDR pipelines, or connection graph analysis — including competitors in the SIEM, XDR, and cloud security segments — remain potential targets. The speed of resolution may signal a licensing strategy rather than a litigation-first posture by Conexus.
Patent enforceable against othersFull party and counsel information
| Role | Name | Type | Detail |
|---|---|---|---|
| Plaintiff | Conexus LLC | Company | Cybersecurity patent licensing entity — holder of US10812497B2 covering threat detection via lineage tracingSearch in Eureka ↗ |
| Defendant | Splunk, Inc. | Company | Splunk, Inc. — enterprise security and observability platform provider (now Cisco subsidiary)Search in Eureka ↗ |
| Plaintiff counsel | Antranig N. Garibian | Attorney | Counsel for Conexus LLCSearch in Eureka ↗ |
| Plaintiff law firm | Garibian Law Offices, PC | Law Firm | Representing Conexus LLCSearch in Eureka ↗ |
| Presiding judge | Judge Jennifer L. Hall | Judge | Delaware District CourtSearch in Eureka ↗ |
Official order — verbatim text
The dismissal notice invokes Rule 41(a)(1)(A)(i), meaning it took effect immediately upon filing without requiring judicial approval — the court played no adjudicative role. The ‘with prejudice’ language, voluntarily inserted by Conexus, converts what would otherwise be a neutral procedural exit into a permanent merits bar. The mutual cost-bearing clause — ‘each party shall bear its own costs, expenses, and attorneys’ fees’ — departs from default fee-shifting and is consistent with a negotiated resolution where both sides accepted defined terms. No substantive findings were made on infringement, validity, or claim scope.
US10812497B2 — Security Threat Detection via Application Execution and Connection Lineage Tracing
US10812497B2 (App. No. US15/372304) protects systems and methods for detecting and responding to security threats by tracing application execution behaviour and network connection lineage. This approach — mapping the ancestry of processes and their associated connections — enables detection of lateral movement, privilege escalation, and covert channels that evade signature-based tools. The patent sits at the intersection of endpoint detection, behavioural analytics, and network security monitoring, all of which are growth areas in enterprise cybersecurity.
The patent’s claims are strategically positioned against core architectural features of modern SIEM and XDR platforms. Splunk’s security offering — which ingests telemetry, correlates process execution data, and maps network connections for threat hunting — is precisely the type of system this patent targets. With no invalidity finding from this case, the patent retains full presumptive validity. Competing platforms from vendors such as Microsoft Sentinel, Elastic, Exabeam, and Securonix may face analogous exposure if Conexus pursues a broader licensing campaign.
Should your security platform run an FTO against US10812497B2?
Any R&D or product team building systems that trace application execution graphs, monitor process ancestry, or correlate network connection lineage for security threat detection should treat US10812497B2 as a priority FTO target. This includes vendors in the SIEM, XDR, EDR, SOAR, and cloud-native security spaces. The patent’s survival through this case — with no invalidity challenge on the record — means it carries full presumptive validity going into any future dispute.
PatSnap Eureka’s FTO Search Agent can map the claim scope of US10812497B2 against your product architecture, surface related family members and continuations that may extend the risk perimeter, and identify prior art that could support an IPR petition if a design-around is not commercially viable. Given the speed with which Conexus resolved the Splunk matter, acting proactively before a demand letter arrives is materially cheaper than responding to litigation.
Run a freedom-to-operate analysis on US10812497B2 to assess your product’s exposure
Run FTO in Eureka →Similar Patent Cases: Cybersecurity Threat Detection Assertions in Delaware
Cases involving cybersecurity and threat detection patents in the District of Delaware, including NPE assertions against SIEM and XDR platform vendors.
Related patent case — similar technology
Comparable case in the same technology domain. Patent holder and defendant reached resolution after proceedings.
SettledRelated infringement action — same court
Comparable Systems and methods for detecting and responding to security threats using application execution and connection lineage tracing-adjacent infringement action. Patent enforcement dynamics analysed in depth.
Active · District CourtRelated invalidity challenge — appellate outcome
Combined invalidity and infringement action in the same technology space. Decided after substantive proceedings.
DecidedConexus LLC’s broader IP enforcement history
Conexus LLC’s full litigation history covering prior enforcement, licensing activity, and inter partes review proceedings.
Portfolio viewWhat this case signals for the cybersecurity IP enforcement landscape
A seven-day lifecycle with a with-prejudice exit suggests calculated licensing strategy — not a failed assertion.
Pre-answer dismissals with prejudice often signal private licensing resolution
When a plaintiff voluntarily adds ‘with prejudice’ before the defendant even answers, the most consistent explanation is a confidential licensing or settlement agreement. Conexus gave up future litigation rights against Splunk — a major concession only rational if compensated commercially. IP teams at potential targets should monitor Conexus’s licensing activity across the cybersecurity sector.
US10812497B2 remains enforceable — FTO exposure persists for security platform vendors
No invalidity ruling was made. The patent covering application execution and connection lineage tracing for threat detection remains a live enforcement risk for any vendor in the SIEM, XDR, EDR, or cloud security space. Companies with products that trace process execution trees or network connection graphs should assess their FTO position against this patent now.
Conexus’s litigation posture suggests a portfolio licensing campaign may be underway
Filing in Delaware, naming a high-profile SIEM vendor, and resolving within a week is consistent with a pre-litigation licensing approach used by NPEs. If Conexus holds related continuations or family members of US10812497B2, the threat profile for the broader security industry could be materially higher than this single case suggests.
Delaware District Court venue choice amplifies enforcement credibility for NPEs
Delaware remains the preferred jurisdiction for patent assertion entities targeting technology defendants. Filing there — even briefly — signals litigation sophistication and credibility. Security platform vendors incorporated in Delaware face particular procedural exposure and should review their IP insurance and defensive patent portfolio strategies in light of this enforcement pattern.
Conexus v Splunk — key questions answered
Conexus LLC filed a patent infringement suit against Splunk, Inc. in the District of Delaware on July 17, 2025, asserting US10812497B2. Seven days later, Conexus voluntarily dismissed all claims with prejudice under Rule 41(a)(1)(A)(i), with each party bearing its own costs. No merits ruling was issued.
A dismissal with prejudice permanently extinguishes Conexus’s right to bring the same patent claims against Splunk again. It functions as a final adjudication on the merits for res judicata purposes. Conexus cannot re-file this suit or assert US10812497B2 against Splunk in future litigation.
Yes. The dismissal resolves only the dispute between Conexus and Splunk. No invalidity or non-infringement determination was made. US10812497B2 retains its presumptive validity and Conexus may assert it against other parties in the cybersecurity and SIEM sector.
The public record does not disclose the reason. However, a with-prejudice dismissal filed before the defendant answers is most commonly consistent with a confidential licensing agreement or settlement. The mutual cost-bearing provision further suggests a negotiated exit rather than a unilateral concession by Conexus.
US10812497B2 (App. No. US15/372304) covers systems and methods for detecting and responding to security threats using application execution and connection lineage tracing. It protects approaches that map process ancestry and associated network connections to identify threats such as lateral movement and privilege escalation — capabilities central to modern SIEM, XDR, and EDR platforms.
Track cybersecurity patent enforcement before a demand letter arrives
US10812497B2 is live and uncontested on validity. PatSnap Eureka can map its claim scope against your product architecture and monitor new assertions across the SIEM, XDR, and EDR market.
PatSnap Eureka searches patents and litigation data to answer instantly.