Dynamic resource allocation for common storage query

    公开(公告)号:US10795884B2

    公开(公告)日:2020-10-06

    申请号:US15665302

    申请日:2017-07-31

    Applicant: Splunk Inc.

    Abstract: Systems and methods are disclosed for processing queries against a common storage utilizing dynamically allocated partitions operating on one or more worker nodes. The common storage can include one or more data stores, which collectively contain a data set divided across multiple buckets of data. To query the common storage, a query coordinator can retrieve metadata regarding the multiple buckets, in order to determine a subset of buckets that are potentially relevant to a query. The query coordinator can then dynamically allocate partitions operating on worker nodes to retrieve and intake individual buckets of the subset into a phased search process. The dynamic allocation can be selected to maximize parallelization of the buckets across partitions, thus increasing a speed at which the common storage can be searched.

    DYNAMIC RESOURCE ALLOCATION FOR COMMON STORAGE QUERY

    公开(公告)号:US20180089262A1

    公开(公告)日:2018-03-29

    申请号:US15665302

    申请日:2017-07-31

    Applicant: Splunk Inc.

    Abstract: Systems and methods are disclosed for processing queries against a common storage utilizing dynamically allocated partitions operating on one or more worker nodes. The common storage can include one or more data stores, which collectively contain a data set divided across multiple buckets of data. To query the common storage, a query coordinator can retrieve metadata regarding the multiple buckets, in order to determine a subset of buckets that are potentially relevant to a query. The query coordinator can then dynamically allocate partitions operating on worker nodes to retrieve and intake individual buckets of the subset into a phased search process. The dynamic allocation can be selected to maximize parallelization of the buckets across partitions, thus increasing a speed at which the common storage can be searched.

    VISUALIZATIONS OF STATISTICS ASSOCIATED WITH CAPTURED NETWORK DATA
    4.
    发明申请
    VISUALIZATIONS OF STATISTICS ASSOCIATED WITH CAPTURED NETWORK DATA 审中-公开
    与被捕获的网络数据相关的统计数据的可视化

    公开(公告)号:US20150341212A1

    公开(公告)日:2015-11-26

    申请号:US14699807

    申请日:2015-04-29

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements containing a set of statistics associated with one or more event streams that comprise the time-series event data. The system then causes for display, in the GUI, one or more graphs comprising one or more values from the set of statistics. Finally, the system causes for display, in the GUI, a value of a statistic from the set of statistics based on a position of a cursor over the one or more graphs.

    Abstract translation: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,该系统导致显示用于从由一个或多个远程捕获代理捕获的网络分组生成时间序列事件数据的图形用户界面(GUI)。 接下来,系统导致在GUI中显示包含与包括时间序列事件数据的一个或多个事件流相关联的一组统计信息的第一组用户界面元素。 然后,系统在GUI中显示包括来自该组统计信息中的一个或多个值的一个或多个图形。 最后,系统导致在GUI中根据一个或多个图形上的光标的位置从该组统计显示统计值的值。

    Grouping evens into episodes using a streaming data processor

    公开(公告)号:US11675816B1

    公开(公告)日:2023-06-13

    申请号:US17163258

    申请日:2021-01-29

    Applicant: Splunk Inc.

    CPC classification number: G06F16/285 G06N20/00

    Abstract: Systems and methods are described for using a streaming data processor to group notable events reflecting operation of a computing system into episodes of related events reflecting an incident on the computing system, such as to enable root cause analysis of the incident. Each notable event can be generated based on one or more events detected within raw machine data. The streaming data processor can ingest a data stream of notable events, and apply a clustering algorithm to the events to cluster those events into episodes. When the episodes satisfy an action rule, the streaming data processor can take an action appropriate to that rule, such as transmitting an alert or programmatically altering operation of the computing system. The streaming data processor can utilize feedback as to the grouping of events into episodes to modify the clustering algorithm and improve accuracy of clustering.

    SELECTIVE EVENT STREAM DATA STORAGE BASED ON HISTORICAL STREAM DATA

    公开(公告)号:US20200014593A1

    公开(公告)日:2020-01-09

    申请号:US16573937

    申请日:2019-09-17

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements containing a set of statistics associated with one or more event streams that comprise the time-series event data. The system then causes for display, in the GUI, one or more graphs comprising one or more values from the set of statistics. Finally, the system causes for display, in the GUI, a value of a statistic from the set of statistics based on a position of a cursor over the one or more graphs.

Patent Agency Ranking