Ingest health monitoring
    21.
    发明授权

    公开(公告)号:US12061533B1

    公开(公告)日:2024-08-13

    申请号:US17877725

    申请日:2022-07-29

    Applicant: Splunk Inc.

    CPC classification number: G06F11/3476 G06F3/0619 G06F2201/81

    Abstract: Ingest health monitoring includes receiving an event stream of events in a data intake and query system to store on at least one storage system and obtaining an event from the event stream. Ingest health monitoring further includes transmitting the event to a selected ingest module queue for the event, updating an output rate indicator counter for the selected ingest module queue when failure to store the event in the ingest module queue occurs, obtaining the event from the selected ingest module queue, processing the event to generate a file for the event, and transmitting the file to the at least one storage system. Ingest health monitoring further includes updating the write failure indicator counter for a storage system of the at least one storage system when failure to transmit to the storage system occurs and updating the user interface based on the output rate indicator counter and the write failure indicator counter.

    Intelligent captain selection for disaster recovery of search head cluster

    公开(公告)号:US10956278B2

    公开(公告)日:2021-03-23

    申请号:US15582441

    申请日:2017-04-28

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present disclosure provide solutions for determining an elected search head captain is unqualified for the position, identifying a more qualified search head, and transferring the captain position to the more qualified search head. A method is provided that includes referencing qualification parameters in an elected search head captain, determining whether the newly elected search head captain is qualified for the position based on the parameters, identifying a more qualified search head to be the search head captain if the newly elected search head captain is determined to be unqualified for the position, and transferring the position of captain to the more qualified search head. The qualification parameters may include, for example, a pre-determined static flag set by an administrator of the search environment, and configuration replication status that corresponds to the most recent configuration state of the search head as recorded by the previous search head captain.

    Periodically processing data in files identified using checksums

    公开(公告)号:US10860537B2

    公开(公告)日:2020-12-08

    申请号:US15663652

    申请日:2017-07-28

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.

    INTELLIGENT CAPTAIN SELECTION FOR DISASTER RECOVERY OF SEARCH HEAD CLUSTER

    公开(公告)号:US20180314601A1

    公开(公告)日:2018-11-01

    申请号:US15582441

    申请日:2017-04-28

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present disclosure provide solutions for determining an elected search head captain is unqualified for the position, identifying a more qualified search head, and transferring the captain position to the more qualified search head. A method is provided that includes referencing qualification parameters in an elected search head captain, determining whether the newly elected search head captain is qualified for the position based on the parameters, identifying a more qualified search head to be the search head captain if the newly elected search head captain is determined to be unqualified for the position, and transferring the position of captain to the more qualified search head. The qualification parameters may include, for example, a pre-determined static flag set by an administrator of the search environment, and configuration replication status that corresponds to the most recent configuration state of the search head as recorded by the previous search head captain.

    SYSTEM AND METHOD FOR FAST FILE TRACKING AND CHANGE MONITORING
    27.
    发明申请
    SYSTEM AND METHOD FOR FAST FILE TRACKING AND CHANGE MONITORING 审中-公开
    用于快速跟踪和更改监控的系统和方法

    公开(公告)号:US20130060937A1

    公开(公告)日:2013-03-07

    申请号:US13662315

    申请日:2012-10-26

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/21 G06F16/1734

    Abstract: Embodiments are directed towards a dynamic change evaluation mechanism, whereby items having a detected possible change are scheduled for re-evaluation for possible changes at a higher frequency than items detected to not have previously changed, while those items detected as not to have changed are dynamically scheduled for re-evaluation based on an evaluation backlog that may be in turn based, in part, on a time from when an item is assigned an expiration time to when the item is evaluated. In one embodiment, a possibly changed item may be assigned a new expiration time independent of the evaluation backlog. In another embodiment, if no change is detected, then the item may be assigned a new expiration time as a function of a previous expiration time and on the evaluation backlog.

    Abstract translation: 实施例针对动态变化评估机制,由此调度具有检测到的可能变化的项目,以便以比检测到的未被改变的项目更高的频率重新评估可能的改变,而被检测为未改变的那些项目是动态的 计划根据评估积压进行重新评估,该评估积压部分可以部分地基于从物品被分配到期时间到评估物品的时间。 在一个实施例中,可以为可能改变的项目分配与评估积压无关的新的期满时间。 在另一个实施例中,如果没有检测到改变,则可以将该项目分配为作为先前的到期时间的函数的新的期满时间,以及评估积压。

    Filesystem destinations
    28.
    发明授权

    公开(公告)号:US12174797B1

    公开(公告)日:2024-12-24

    申请号:US18103323

    申请日:2023-01-30

    Applicant: Splunk Inc.

    Abstract: A method for file system destinations includes obtaining events for storage on one or more of the storage systems. For each event, the method includes extracting at least one field value from the event, comparing the at least one field value to configurations of the storage systems to identify at least one storage system of the plurality of storage systems having a matching configuration, transmitting the event to an ingest module queue for the at least one storage system, selecting a partition for the event based on the at least one field value to obtain a selected partition, mapping the selected partition to a file using a partition mapping, and appending the event to the file on the at least one storage system.

    Detecting and resolving computer system errors using fast file change monitoring

    公开(公告)号:US11042515B2

    公开(公告)日:2021-06-22

    申请号:US16141913

    申请日:2018-09-25

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.

Patent Agency Ranking