FACILITATING CUSTOM CONTENT EXTRACTION FROM NETWORK PACKETS
    13.
    发明申请
    FACILITATING CUSTOM CONTENT EXTRACTION FROM NETWORK PACKETS 审中-公开
    促进网络包的自定义内容提取

    公开(公告)号:US20160226944A1

    公开(公告)日:2016-08-04

    申请号:US14609292

    申请日:2015-01-29

    Applicant: SPLUNK INC.

    CPC classification number: H04L69/22 H04L43/028 H04L43/0876

    Abstract: The disclosed embodiments provide a system for extracting custom content from network packets. During operation, the system receives a stream of packets. The system then parses packets in the stream to determine a protocol for each packet. Next, the system applies a custom-content-extraction rule to each packet associated with a target protocol to obtain the extracted content. Then, the system stores the extracted content in events in a data store to facilitate subsequent queries involving the extracted content.

    Abstract translation: 所公开的实施例提供了一种用于从网络分组中提取定制内容的系统。 在操作过程中,系统接收到一个数据包流。 然后系统解析流中的数据包,以确定每个数据包的协议。 接下来,系统对与目标协议相关联的每个分组应用自定义内容提取规则以获得提取的内容。 然后,系统将所提取的内容存储在数据存储器中的事件中,以便于涉及提取的内容的后续查询。

    Searching archived data
    14.
    发明授权

    公开(公告)号:US10956362B1

    公开(公告)日:2021-03-23

    申请号:US16177358

    申请日:2018-10-31

    Applicant: SPLUNK INC.

    Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.

    Archiving indexed data
    16.
    发明授权

    公开(公告)号:US10152480B2

    公开(公告)日:2018-12-11

    申请号:US14611225

    申请日:2015-01-31

    Applicant: Splunk Inc.

    Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.

    FILE BROWSER USER INTERFACE
    18.
    发明申请

    公开(公告)号:US20170270132A1

    公开(公告)日:2017-09-21

    申请号:US14611227

    申请日:2015-01-31

    Applicant: Splunk Inc.

    CPC classification number: G06F16/134 G06F16/148 G06F16/168 G06F16/182

    Abstract: A search support system allows a customer to browse data contained in files stored on an external storage system. The search support system allows a customer to specify data processing tasks to be performed on raw data retrieved from a file stored on the external storage system. The customer specifies each data processing task and the search support system performs each task as it is selected by the customer on raw data retrieved from the file. The search support system concurrently displays the results of each data processing task in real time in a graphical user interface. The search support system saves the customer's settings as a late binding schema that can be applied to raw data retrieved from the external storage system in order to parse the raw data and to create, index, and search timestamped events derived from the raw data.

    Topology navigator for IT services
    19.
    发明授权
    Topology navigator for IT services 有权
    IT服务拓扑导航仪

    公开(公告)号:US09491059B2

    公开(公告)日:2016-11-08

    申请号:US14800675

    申请日:2015-07-15

    Applicant: Splunk Inc.

    Abstract: Techniques are disclosed for providing a topology navigator that may enable a user to view performance information for multiple IT services associated with a user's IT environment. The topology navigator may include multiple display components for displaying information about the services. A first display component may display multiple services as a graph of interdependent service nodes and a second display component may display information about one or more of the service nodes. The topology navigator may enable a user to visually inspect the aggregate KPI (e.g., health score) of multiple services to identify dependent services that are of interest (e.g., low performance) and navigate through the services to identify dependent services that may adversely affect a service of interest to the user. In one example, the second display component may display key performance indicators (KPIs) associated with the dependent service and the user may select one or more of the KPIs to add them to another display component for further analysis.

    Abstract translation: 公开了用于提供拓扑导航器的技术,其可以使得用户能够查看与用户的IT环境相关联的多个IT服务的性能信息。 拓扑导航器可以包括用于显示关于服务的信息的多个显示组件。 第一显示组件可以将多个服务显示为相互依赖的服务节点的图,并且第二显示组件可以显示关于一个或多个服务节点的信息。 拓扑导航器可以使用户能够目视地检查多个服务的聚合KPI(例如,健康评分)以识别感兴趣的依赖服务(例如,低性能),并且浏览服务以识别可能不利地影响 用户感兴趣的服务。 在一个示例中,第二显示组件可以显示与依赖服务相关联的关键性能指标(KPI),并且用户可以选择一个或多个KPI以将它们添加到另一显示组件以进一步分析。

    ARCHIVING INDEXED DATA
    20.
    发明申请
    ARCHIVING INDEXED DATA 审中-公开
    归档索引数据

    公开(公告)号:US20160224570A1

    公开(公告)日:2016-08-04

    申请号:US14611225

    申请日:2015-01-31

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30073 G06F17/30336 G06F17/30427

    Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.

    Abstract translation: 分布式服务器中的原始数据被划分为称为存储桶的数据组,其中包含具有落在特定时间范围内的时间戳的原始数据。 当桶变为不活动时,服务器可以将存储桶存储到外部存储系统。 可以在搜索查询中指定包含归档数据的外部存储系统。 获取,处理来自外部存储系统的存档数据,并使用搜索查询对已处理归档数据执行搜索。

Patent Agency Ranking