GENERATING A QUERY RESPONSE BY COMBINING PARTIAL RESULTS FROM SEPARATE PARTITIONS OF EVENT RECORDS

    公开(公告)号:US20220012221A1

    公开(公告)日:2022-01-13

    申请号:US17482781

    申请日:2021-09-23

    Applicant: SPLUNK INC.

    Abstract: Embodiments are directed are towards a method for generating a query response, which comprises creating two or more partitions of event records from raw data stored in a data store, wherein each event record in the two or more partitions of event records includes a portion of the raw data and is associated with a time stamp derived from the raw data. The method also comprises generating a summarization table for each partition of the two or more partitions that: (a) identifies a field value comprising a value that corresponds to an associated field extracted from a respective event record; and (b) for the field value, includes a posting value to the respective event record within a respective partition. The method further comprises generating partial results for a received query using summarization tables in the partitions and generating a response to the query by combining the partial results.

    Triggering generation of an accelerated data model summary for a data model

    公开(公告)号:US11144608B2

    公开(公告)日:2021-10-12

    申请号:US16900628

    申请日:2020-06-12

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.

    OPTIMIZING SEARCH OF AN ACCELERATED DATA MODEL BY ENABLING EMITTING OF STRUCTURED AND UNSTRUCTURED FIELDS FROM THE DATA MODEL

    公开(公告)号:US20210034623A1

    公开(公告)日:2021-02-04

    申请号:US16527719

    申请日:2019-07-31

    Applicant: Splunk Inc.

    Abstract: Embodiments of the present disclosure provide techniques for emitting structured and dynamic fields from an accelerated data model. The method comprises evaluating a query to search a data model, wherein the data model is defined by a set of events and at least one structured field from fields associated with the set of events. Each event comprises a time-stamped portion of raw machine data and is stored in a field searchable data store. A summarization table is associated with the data model and comprises a plurality of entries comprising reference values, wherein a respective summarization table entry comprises: the at least one structured field; a respective field value; and a reference value. The method further comprises accessing the set of events from the field searchable data store using the reference values in the summarization table and annotating the set of events with the at least one structured field and with at least one dynamic field from the fields associated with the set of events, wherein the at least one dynamic field is not defined in the data model.

    Facilitating data model acceleration in association with an external data system

    公开(公告)号:US10713314B2

    公开(公告)日:2020-07-14

    申请号:US15011361

    申请日:2016-01-29

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed to facilitating data model acceleration in association with an external data system. In some embodiments, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.

    GENERATING AND STORING SUMMARIZATION TABLES FOR SETS OF SEARCHABLE EVENTS

    公开(公告)号:US20180246918A1

    公开(公告)日:2018-08-30

    申请号:US15967400

    申请日:2018-04-30

    Applicant: SPLUNK, INC.

    Abstract: Embodiments are directed are towards the transparent summarization of events. Queries directed towards summarizing and reporting on event records may be received at a search head. Search heads may be associated with one more indexers containing event records. The search head may forward the query to the indexers the can resolve the query for concurrent execution. If a query is a collection query, indexers may generate summarization information based on event records located on the indexers. Event record fields included in the summarization information may be determined based on terms included in the collection query. If a query is a stats query, each indexer may generate a partial result set from previously generated summarization information, returning the partial result sets to the search head. Collection queries may be saved and scheduled to run and periodically update the summarization information.

Patent Agency Ranking