Searching Raw Data From An External Data System Using A Dual Mode Search System

    公开(公告)号:US20180157755A1

    公开(公告)日:2018-06-07

    申请号:US15885629

    申请日:2018-01-31

    Applicant: SPLUNK INC.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Searching raw data from an external data system using a dual mode search system

    公开(公告)号:US09916385B2

    公开(公告)日:2018-03-13

    申请号:US15339951

    申请日:2016-11-01

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    PROCESSING A SYSTEM SEARCH REQUEST INCLUDING EXTERNAL DATA SOURCES
    23.
    发明申请
    PROCESSING A SYSTEM SEARCH REQUEST INCLUDING EXTERNAL DATA SOURCES 有权
    处理包括外部数据源的系统搜索请求

    公开(公告)号:US20140344256A1

    公开(公告)日:2014-11-20

    申请号:US14449144

    申请日:2014-07-31

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

    PROCESSING A SYSTEM SEARCH REQUEST ACROSS DISPARATE DATA COLLECTION SYSTEMS
    24.
    发明申请
    PROCESSING A SYSTEM SEARCH REQUEST ACROSS DISPARATE DATA COLLECTION SYSTEMS 审中-公开
    处理不同数据收集系统的系统搜索请求

    公开(公告)号:US20140330815A1

    公开(公告)日:2014-11-06

    申请号:US14266832

    申请日:2014-05-01

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

    Processing a system search request by retrieving results from both a native index and a virtual index
    25.
    发明授权
    Processing a system search request by retrieving results from both a native index and a virtual index 有权
    通过从本机索引和虚拟索引检索结果来处理系统搜索请求

    公开(公告)号:US08738587B1

    公开(公告)日:2014-05-27

    申请号:US13951273

    申请日:2013-07-25

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

    Rule-based data stream processing
    26.
    发明授权

    公开(公告)号:US11669551B2

    公开(公告)日:2023-06-06

    申请号:US17072833

    申请日:2020-10-16

    Applicant: Splunk Inc.

    Abstract: Systems and methods for rule-based data stream processing by data collection, indexing, and visualization systems. An example method includes: receiving, by the computer system, an input data stream comprising raw machine data; processing the raw machine data by a data processing pipeline that produces transformed machine data, wherein the data processing pipeline comprises an ordered plurality of pipeline stages, wherein a pipeline stage of the ordered plurality of pipeline stages applies a rule of a set of rules to an input of the pipeline stage, wherein the rule specifies an action to be performed on the input of the pipeline stage responsive to evaluating a conditional expression applied to the input of the pipeline stage, wherein the action generates an output of the pipeline stage, and wherein the rule is selected based on a source type associated with the input data stream; and supplying the transformed machine data to a data collection, indexing, and visualization system.

    OPTIMIZING SEARCH OF AN ACCELERATED DATA MODEL BY ENABLING EMITTING OF STRUCTURED AND UNSTRUCTURED FIELDS FROM THE DATA MODEL

    公开(公告)号:US20210034623A1

    公开(公告)日:2021-02-04

    申请号:US16527719

    申请日:2019-07-31

    Applicant: Splunk Inc.

    Abstract: Embodiments of the present disclosure provide techniques for emitting structured and dynamic fields from an accelerated data model. The method comprises evaluating a query to search a data model, wherein the data model is defined by a set of events and at least one structured field from fields associated with the set of events. Each event comprises a time-stamped portion of raw machine data and is stored in a field searchable data store. A summarization table is associated with the data model and comprises a plurality of entries comprising reference values, wherein a respective summarization table entry comprises: the at least one structured field; a respective field value; and a reference value. The method further comprises accessing the set of events from the field searchable data store using the reference values in the summarization table and annotating the set of events with the at least one structured field and with at least one dynamic field from the fields associated with the set of events, wherein the at least one dynamic field is not defined in the data model.

    Clustering events based on extraction rules

    公开(公告)号:US10909140B2

    公开(公告)日:2021-02-02

    申请号:US15276693

    申请日:2016-09-26

    Applicant: SPLUNK INC.

    Abstract: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

Patent Agency Ranking