Exploratory data analysis system for generation of wildcards within log templates through log clustering and analysis thereof

    公开(公告)号:US12182174B1

    公开(公告)日:2024-12-31

    申请号:US18147639

    申请日:2022-12-28

    Applicant: SPLUNK Inc.

    Abstract: A search assistant engine is described that integrates with a data intake and query system and provides an intuitive user interface to assist a user in searching and evaluating indexed event data. Additionally, the search assistant engine provides logic to intelligently provide data to the user through the user interface such as determining fields of events likely to be of interest based on determining a mutual information score for each field and determining groups of related fields based on determining a mutual information score for each field grouping. Some implementations utilize machine learning techniques in certain analyses such as when clustering events and determining an event templates for each cluster. Additionally, the search assistant engine may import terms or characters from user interaction into predetermined search query templates to generate tailored search query for the user.

    System and method for data ingestion, anomaly and root cause detection

    公开(公告)号:US12216527B1

    公开(公告)日:2025-02-04

    申请号:US17583056

    申请日:2022-01-24

    Applicant: Splunk, Inc.

    Abstract: A computerized method is disclosed for automated handling of data ingestion anomalies. The method features operations of detecting a data ingestion anomaly and determining a cause for the data ingestion anomaly. The causal determination may be conducted by at least (i) determining features of an anomalous data ingestion volume, (ii) training a second data model, after a first data model being used to detect the data ingestion anomaly, with data sets consistent with the determined features, (iii) applying the second data model to predict whether a data ingestion sub-volume is anomalous, (iv) obtaining system state information during ingestion of the anomalous data ingestion sub-volume, and (v) determining the cause of the anomalous data ingestion volume based on the system state information.

Patent Agency Ranking