Invention Grant
- Patent Title: Supplementing a high performance analytics store with evaluation of individual events to respond to an event query
- Patent Title (中): 补充高性能分析商店,评估各种事件以响应事件查询
-
Application No.: US14170159Application Date: 2014-01-31
-
Publication No.: US09128985B2Publication Date: 2015-09-08
- Inventor: David Ryan Marquardt , Stephen Phillip Sorkin , Steve Yu Zhang
- Applicant: SPLUNK INC.
- Applicant Address: US CA San Francisco
- Assignee: Splunk, Inc.
- Current Assignee: Splunk, Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Wong & Rees LLP
- Agent Kirk D. Wong
- Main IPC: G06F17/30
- IPC: G06F17/30

Abstract:
Embodiments are directed are towards the transparent summarization of events. Queries directed towards summarizing and reporting on event records may be received at a search head. Search heads may be associated with one more indexers containing event records. The search head may forward the query to the indexers the can resolve the query for concurrent execution. If a query is a collection query, indexers may generate summarization information based on event records located on the indexers. Event record fields included in the summarization information may be determined based on terms included in the collection query. If a query is a stats query, each indexer may generate a partial result set from previously generated summarization information, returning the partial result sets to the search head. Collection queries may be saved and scheduled to run and periodically update the summarization information.
Public/Granted literature
Information query