-
公开(公告)号:US20180089286A1
公开(公告)日:2018-03-29
申请号:US15339863
申请日:2016-10-31
Applicant: Splunk Inc.
Inventor: David Ryan Marquardt , Hailun Yan , Christopher Pride , Vishal Patel
IPC: G06F17/30
CPC classification number: G06F16/248 , G06F3/0481 , G06F16/22 , G06F16/2228 , G06F16/2255 , G06F16/2425 , G06F16/2455 , G06F16/24568 , G06F16/2462 , G06F16/2477 , G06F16/25 , G06F16/285 , G06F16/8373 , G06F16/901 , G06F16/90335 , G06F16/9038 , G06F16/951 , G06F16/9535 , G06T11/206 , G06T2200/24 , H04L43/08 , H04L67/02 , H04L67/025
Abstract: The disclosed embodiments include a method performed by a data intake and query system to store and query metrics data. The method includes ingesting metrics, where each metric includes key values and numerical value indicative of a measured characteristic of a computing resource. The method further includes populating a first portion of a metric-series index (msidx) file with the key values and a second portion of the msidx file with numerical values indicative of a measured characteristic, where the first portion is distinct from the second portion. The method further includes receiving a query including criteria, evaluating the query by applying the criteria to the first portion of the msidx file to obtain query results indicative of metrics that satisfy the criteria, and displaying, on a display device, the query results or data indicative of the query results.
-
公开(公告)号:US12141137B1
公开(公告)日:2024-11-12
申请号:US17816132
申请日:2022-07-29
Applicant: Splunk Inc.
Inventor: Raman Arora , Ankit Jain , Meng Su , Hailun Yan , Sophia Rui Zhu
IPC: G06F7/00 , G06F16/2452 , G06F16/2458
Abstract: A computing device can receive a query in a first query language that identifies a set of data to be processed and determine that at least a portion of the set of data resides in an external data system that uses a different query language. The query system can translate the query in the first query language in to a second query language for the external data system. In translating the query, the computing device may translate one or more time-based query commands into the second query language.
-
公开(公告)号:US20220245091A1
公开(公告)日:2022-08-04
申请号:US17163039
申请日:2021-01-29
Applicant: SPLUNK INC.
Inventor: Alexandros Batsakis , Ankit Jain , Manu Jose , Jonah Pan , Hailun Yan
IPC: G06F16/13 , G06F16/182
Abstract: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, a set of events are indexed, each of the events having a corresponding index time representing a time at which the event was indexed in an indexer. Index time parameters including an index earliest time indicating a first index time at which to begin generating a data model summary and an index latest time indicating a second index time at which to complete generating the data model summary are obtained. Thereafter, a data model summary is generated. Such a data model summary summarizes events having corresponding index times between the index earliest time and the index latest time. The data model summary is provided to a remote data store that is separate from the indexer at which at least a portion of the events were indexed.
-
公开(公告)号:US11144608B2
公开(公告)日:2021-10-12
申请号:US16900628
申请日:2020-06-12
Applicant: SPLUNK INC.
Inventor: Hailun Yan , Ledion Bitincka , Kishore Reddy Ramasayam , Elizabeth Lin , David Ryan Marquardt
IPC: G06F16/9535 , G06F16/28 , G06F16/2455
Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.
-
公开(公告)号:US10713314B2
公开(公告)日:2020-07-14
申请号:US15011361
申请日:2016-01-29
Applicant: Splunk Inc.
Inventor: Hailun Yan , Ledion Bitincka , Kishore Reddy Ramasayam , Elizabeth Lin , David Ryan Marquardt
IPC: G06F16/9535 , G06F16/28 , G06F16/2455
Abstract: Embodiments are directed to facilitating data model acceleration in association with an external data system. In some embodiments, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.
-
-
-
-