MODIFYING EVENT GENERATION RULES RESPONSIVE TO DETECTED SCHEMA CHANGES

    公开(公告)号:US20210191909A1

    公开(公告)日:2021-06-24

    申请号:US17191436

    申请日:2021-03-03

    Applicant: Splunk Inc.

    Inventor: Gleb ESMAN

    Abstract: A schema consistency mechanism monitors data ingested by a data intake and query system for changes to the structure, or data schema, associated with the data. A schema consistency monitor obtains data from a data source (or, more generally, from any number of separate data sources) at a plurality of points in time. The data is analyzed to determine whether a first portion of the data received at a first point in time conforms to a first data schema and that a second portion of the data received at a second point in time conforms to a second data schema that is different from the first data schema (thereby indicating a change to the associated data schema). A graphical user interface (GUI) can be generated that includes indications of identified changes to one or more data schemas associated with data.

    AUTOMATIC REASSIGNMENT OF TASKS TO DIFFERENT VIRTUAL MACHINES

    公开(公告)号:US20210173683A1

    公开(公告)日:2021-06-10

    申请号:US17153033

    申请日:2021-01-20

    Applicant: SPLUNK Inc.

    Abstract: The disclosed embodiments relate to a system for monitoring a virtual-machine environment. During operation, the system assigns a task, corresponding with a task request, to a first virtual machine. The performance of the task at the first virtual machine is monitored. Based on the monitoring, it is determined whether the performance of the task at the first virtual machine is unsatisfactory. If so, the task is automatically reassigned to a second virtual machine.

    Automatic rule modification
    255.
    发明授权

    公开(公告)号:US11030229B2

    公开(公告)日:2021-06-08

    申请号:US15582670

    申请日:2017-04-29

    Applicant: SPLUNK INC.

    Abstract: Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.

    Converting and modifying a subquery for an external data system

    公开(公告)号:US11023463B2

    公开(公告)日:2021-06-01

    申请号:US16146990

    申请日:2018-09-28

    Applicant: Splunk Inc.

    Abstract: Systems and methods are disclosed for receiving, at a data intake and query system, a query that includes a subquery that is to be executed at an external data system that supports a different query language than the data intake and query system. The data intake and query system converts the subquery from the query language supported by the external data system to the query language supported by the data intake and query system. The data intake and query system then processes the query including the translated subquery. The translated subquery is then translated back to the language supported by the external data system including any processing or optimizations performed with respect to the subquery.

    Processing data streams received from instrumented software using incremental finite window double exponential smoothing

    公开(公告)号:US11023280B2

    公开(公告)日:2021-06-01

    申请号:US16129494

    申请日:2018-09-12

    Applicant: Splunk Inc.

    Inventor: Joseph Ari Ross

    Abstract: A system receives a time series of data values from instrumented software executing on an external system. Each data value corresponds to a metric of the external system. The system stores a level value representing a current estimate of the time series and a trend value representing a trend in the time series. The level and trend values are based on data in a window having a trailing value. In response to receiving a most recent value, the system updates the level value and the trend value to add an influence of the most recent value and remove an influence of the trailing value. The system forecasts based on the updated level and trend values, and in response to determining that the forecast indicates the potential resource shortage event, takes action.

    TERMINATING DATA SERVER NODES
    259.
    发明申请

    公开(公告)号:US20210152489A1

    公开(公告)日:2021-05-20

    申请号:US17158435

    申请日:2021-01-26

    Applicant: SPLUNK Inc.

    Abstract: A system of terminating data server nodes based on insufficient processing of messages. In embodiments, a plurality of time-stamped, searchable events from machine data are created. A plurality of data server nodes that service messages across one or more portions of the plurality of time-stamped, searchable events, are executed in parallel. For each message received, the message is sent to a data server node, of the plurality of data server nodes, to cause the receiving data server node to perform a data operation associated with the received message. A determination can then be made that a particular data server node insufficiently processes messages sent to the particular data server node. Thereafter, termination of the particular data server node is initiated to terminate processes or threads executed by the particular data server node.

    CLUSTERING EVENTS WHILE EXCLUDING EXTRACTED VALUES

    公开(公告)号:US20210149912A1

    公开(公告)日:2021-05-20

    申请号:US17158880

    申请日:2021-01-26

    Applicant: SPLUNK INC.

    Abstract: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

Patent Agency Ranking