DISTRIBUTED ALERT AND SUPPRESSION MANAGEMENT IN A CLUSTER COMPUTING SYSTEM

    公开(公告)号:US20230244660A1

    公开(公告)日:2023-08-03

    申请号:US17588079

    申请日:2022-01-28

    Applicant: Splunk Inc.

    CPC classification number: G06F16/245

    Abstract: A first processing node of a cluster of processing nodes issues a first alert when first event data satisfies a trigger condition, and sends, to an alert data store external to the cluster, a first alert record of the first alert and suppression information based at least in part on the first alert. A second processing node of the cluster determines that second event data satisfies the trigger condition, obtains, from the alert data store, the suppression information indicating that an expiration time for suppressing the first alert is unexpired, and sends, to the alert data store, a second alert record of a second alert without issuing the second alert.

    Artifact life tracking storage
    4.
    发明授权

    公开(公告)号:US12135710B2

    公开(公告)日:2024-11-05

    申请号:US17586634

    申请日:2022-01-27

    Applicant: Splunk Inc.

    Abstract: Artifact life tracking storage techniques include performing an artifact request of an artifact at an artifact storage node. A current time to live (TTL) value is identified. A determination is made whether to increment a TTL flag of the artifact. Responsive to determining that the TTL tag should be incremented, the TTL flag is incremented to a subsequent value in a TTL extender list. Responsive to incrementing the TTL tag, the TTL modified tag value is set to the current time value.

    Distributed alert and suppression management in a cluster computing system

    公开(公告)号:US12197431B2

    公开(公告)日:2025-01-14

    申请号:US17588079

    申请日:2022-01-28

    Applicant: Splunk Inc.

    Abstract: A first processing node of a cluster of processing nodes issues a first alert when first event data satisfies a trigger condition, and sends, to an alert data store external to the cluster, a first alert record of the first alert and suppression information based at least in part on the first alert. A second processing node of the cluster determines that second event data satisfies the trigger condition, obtains, from the alert data store, the suppression information indicating that an expiration time for suppressing the first alert is unexpired, and sends, to the alert data store, a second alert record of a second alert without issuing the second alert.

    Alert and suppression updating in a cluster computing system

    公开(公告)号:US12182104B1

    公开(公告)日:2024-12-31

    申请号:US18103374

    申请日:2023-01-30

    Applicant: Splunk Inc.

    Abstract: A set of alert records stored in a shared alert data store that is shared amongst a cluster of processing nodes are presented in an interface. From the interface, a request is received to delete an identified alert record from the set of alert records. A delete alert record matching the identified alert record is added to the shared alert data store. The identified alert record is deleted from the shared alert data store responsive to the request. The delete alert record is transmitted to a processing node of the cluster of processing nodes, wherein the processing node deletes a local copy of the identified alert record according to the delete alert record.

    ARTIFACT LIFE TRACKING STORAGE
    7.
    发明公开

    公开(公告)号:US20230237049A1

    公开(公告)日:2023-07-27

    申请号:US17586634

    申请日:2022-01-27

    Applicant: Splunk Inc.

    CPC classification number: G06F16/2379

    Abstract: Artifact life tracking storage techniques include performing an artifact request of an artifact at an artifact storage node. A current time to live (TTL) value is identified. A determination is made whether to increment a TTL flag of the artifact. Responsive to determining that the TTL tag should be incremented, the TTL flag is incremented to a subsequent value in a TTL extender list. Responsive to incrementing the TTL tag, the TTL modified tag value is set to the current time value.

    Dynamic reassignment in a search and indexing system

    公开(公告)号:US11630695B1

    公开(公告)日:2023-04-18

    申请号:US17163160

    申请日:2021-01-29

    Applicant: Splunk Inc.

    Abstract: Dynamic reassignment of search processes into workload pools includes receiving a search query to search at least one data store, assigning the search query to a first workload pool, and executing the search query using a first hardware resource in the first workload pool, the first hardware resource corresponding to a first portion of a hardware device. Dynamic reassignment further includes receiving, while executing the search query, an update command to move the search query to a second workload pool, moving, while executing the search query, the search query to the second workload pool; and continuing execution of the search query using a second hardware resource in the second workload pool. The second hardware resource corresponds to a second portion of the hardware device.

Patent Agency Ranking