-
11.
公开(公告)号:US20180336216A1
公开(公告)日:2018-11-22
申请号:US16049609
申请日:2018-07-30
申请人: Splunk, Inc.
IPC分类号: G06F17/30 , G06F12/0875 , G06F3/06 , G06F12/0802 , G06F12/0862 , G06F12/0866 , G06F12/0873 , G06F12/0871 , G06F12/0868
摘要: Embodiments are disclosed for performing cache aware searching. In response to a search query, a first bucket and a second bucket in remote storage for processing the search query. A determination is made that a first file in the first bucket is present in a cache when the search query is received. In response to the search query, a search is performed using the first file based on the determination that the first file is present in the cache when the search query is received, and the search is performed using a second file from the second bucket once the second file is stored in the cache.
-
公开(公告)号:US20180196753A1
公开(公告)日:2018-07-12
申请号:US15402105
申请日:2017-01-09
申请人: Splunk, Inc.
IPC分类号: G06F12/0875 , G06F17/30
CPC分类号: G06F12/0875 , G06F12/0802 , G06F12/0862 , G06F12/0866 , G06F12/0868 , G06F12/0871 , G06F12/0873 , G06F17/30106 , G06F17/30132 , G06F17/30864 , G06F17/30902 , G06F2212/1021 , G06F2212/45 , G06F2212/6024 , G06F2212/6026 , G06F2212/6028
摘要: Embodiments are disclosed for a prefetching method that may include copying, in response to a search query, a first bucket from a remote storage to a cache. The first bucket may include first data associated with the search query. The method may further include identifying a first file type associated with a first file in the first bucket. The first file may be associated with a usage status. The method may further include accessing, based on the search query, a second bucket from the remote storage. The second bucket may include second data associated with the search query. The method may further include identifying a second file in the second bucket having the first file type, and copying, in response to the usage status indicating that the first file was used in processing the search query, the second file from the remote storage to the cache.
-
公开(公告)号:US11609913B1
公开(公告)日:2023-03-21
申请号:US17162536
申请日:2021-01-29
申请人: Splunk Inc.
发明人: Tameem Anwar , Alexandros Batsakis , Tianyi Gou , Mehul Goyal , Ashish Mathew , Douglas Rapp , Sai Krishna Sajja , Anish Shrigondekar , Igor Stojanovski , Eric Woo , Zhenghui Xie , Ruochen Zhang , Sophia Rui Zhu
IPC分类号: G06F16/00 , G06F16/2455 , G06F16/248 , G06F16/2458
摘要: A data intake and query system can manage the search of large amounts of data using one or more processing nodes. When a new processing node is added or becomes available, the node coordinator can reassign duties from one or more processing nodes to the new processing node. The node coordinator can initially assign the new processing node one or more groups of data for backup purposes. At a later time, the node coordinator can reassign the new processing node to the one or more groups of data for searching purposes.
-
公开(公告)号:US11500783B1
公开(公告)日:2022-11-15
申请号:US17382043
申请日:2021-07-21
申请人: Splunk Inc.
IPC分类号: G06F12/121 , G06F16/22 , G06F16/2455
摘要: Systems and methods are disclosed for making space available in a local storage of a data intake and query system. A cache manager of the data intake and query system may determine an amount of storage space of a local data store that is available for use to perform a query. The cache manager may then use one or more eviction policies associated with content stored at the local data store to purge content items to evict from the local storage. The system may then retrieve content for performing the query from a remote storage and store the retrieved content at the local storage.
-
15.
公开(公告)号:US20220269727A1
公开(公告)日:2022-08-25
申请号:US17646841
申请日:2022-01-03
申请人: Splunk Inc.
发明人: Alexandros Batsakis , Sourav Pal , Sai Krishna Sajja , Igor Stojanovski , Tameem Anwar , Paul J. Lucas , Eric Woo , Steve Wong
IPC分类号: G06F16/901 , G06F3/06 , G06F16/23 , G06F16/27 , G06F16/903
摘要: Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system receives raw machine data at an indexing system, and stores at least a portion of the raw machine data in buckets using containerized indexing nodes instantiated in a containerized environment. The data intake and query system stores the buckets in a shared storage system.
-
公开(公告)号:US20220245093A1
公开(公告)日:2022-08-04
申请号:US17163047
申请日:2021-01-29
申请人: SPLUNK INC.
发明人: Alexandros Batsakis , Ankit Jain , Manu Jose , Jonah Pan , Hailun Yan
IPC分类号: G06F16/14 , G06F16/182
摘要: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, obtaining a search query from a user device. A determination may be made to execute a search, in association with the search query, via an external computing service. As such, the search query, or a variant thereof, can be provided to the external computing service, wherein the external computing service executes the search using data model summaries stored in a remote data store that is separate from a set of events from which the data model summaries were generated. A set of search results are received from the external computing service, and such search results are provided to the user device.
-
17.
公开(公告)号:US11250056B1
公开(公告)日:2022-02-15
申请号:US15967573
申请日:2018-04-30
申请人: Splunk Inc.
发明人: Alexandros Batsakis , Sourav Pal , Sai Krishna Sajja , Igor Stojanovski , Tameem Anwar , Eric Woo , Steve Wong
IPC分类号: G06F16/901 , G06F3/06 , G06F16/23 , G06F16/903
摘要: Systems and methods are disclosed for processing and executing queries in a data intake and query system. An indexing system of the data intake and query system receives data from an ingestion buffer that includes a marker that indicates data that is made available to the indexing system. The data intake and query system stores at least a portion of the data in buckets and stores the buckets in a shared storage system. Based on the storage of the buckets in the shared storage system, the indexing system indicates to the ingestion buffer that the marker can be updated.
-
18.
公开(公告)号:US11003714B1
公开(公告)日:2021-05-11
申请号:US15967590
申请日:2018-04-30
申请人: Splunk Inc.
发明人: Alexandros Batsakis , Ashish Mathew , Christopher Madden Pride , Bharath Kishore Reddy Aleti , Sourav Pal , Arindam Bhattacharjee , James Monschke
IPC分类号: G06F16/901 , G06F16/2458 , G06F16/903
摘要: Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system receives a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system uses a search node catalog to identify search nodes that are available to execute the query and uses a bucket catalog to identify buckets to be searched. The data intake and query system executes the query using the identified bucket and search nodes.
-
19.
公开(公告)号:US10984044B1
公开(公告)日:2021-04-20
申请号:US15967591
申请日:2018-04-30
申请人: Splunk Inc.
发明人: Alexandros Batsakis , Ashish Mathew , Christopher Madden Pride , Bharath Kishore Reddy Aleti , Sourav Pal , Arindam Bhattacharjee , James Monschke
IPC分类号: G06F16/901 , G06F16/903 , G06F16/907 , G06F3/06
摘要: Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system maintains a catalog of buckets stored in a remote shared storage system. The buckets store raw machine data associated with a timestamp. The data intake and query receives a query identifying a set of data to be processed and a manner of processing the set of data, and executes the query based on the catalog of buckets.
-
公开(公告)号:US10776355B1
公开(公告)日:2020-09-15
申请号:US15967578
申请日:2018-04-30
申请人: Splunk Inc.
发明人: Alexandros Batsakis , Ashish Mathew , Christopher Madden Pride , Bharath Kishore Reddy Aleti , Sourav Pal , Arindam Bhattacharjee , James Monschke , Karthikeyan Sabhanatarajan
IPC分类号: G06F16/2453 , G06F16/901 , G06F16/903
摘要: Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system receives a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system uses one or more containerized search nodes to execute the query and stores the results in a data store for combination with additional query results.
-
-
-
-
-
-
-
-
-