MONITORING CHANGES TO DATA ITEMS USING ASSOCIATED METADATA

    公开(公告)号:US20210042269A1

    公开(公告)日:2021-02-11

    申请号:US17080416

    申请日:2020-10-26

    Applicant: SPLUNK INC.

    Abstract: Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.

    Computing and replicating event deltas for mutable events in a distributed system

    公开(公告)号:US10891284B2

    公开(公告)日:2021-01-12

    申请号:US15582458

    申请日:2017-04-28

    Applicant: SPLUNK INC.

    Abstract: The present disclosure provides solutions for determining the divergence (delta) between the current and previous reference data structures for mutable data in a search head. A method is provided that includes updating a pre-existing lookup table in a search head, generating a delta file that identifies the divergence between the updated and previous lookup table, and distributing the delta file to other components in the search environment. The compatibility of the delta file is checked with the local instance of the lookup table in each search component, and the lookup table is applied if compatibility is determined. However, if the delta file is determined to not be compatible with the current version of a local lookup table in an indexer, the entire lookup table sent to the requesting indexer instead.

    COMPUTING AND REPLICATING EVENT DELTAS FOR MUTABLE EVENTS IN A DISTRIBUTED SYSTEM

    公开(公告)号:US20180314726A1

    公开(公告)日:2018-11-01

    申请号:US15582458

    申请日:2017-04-28

    Applicant: SPLUNK INC.

    Abstract: The present disclosure provides solutions for determining the divergence (delta) between the current and previous reference data structures for mutable data in a search head. A method is provided that includes updating a pre-existing lookup table in a search head, generating a delta file that identifies the divergence between the updated and previous lookup table, and distributing the delta file to other components in the search environment. The compatibility of the delta file is checked with the local instance of the lookup table in each search component, and the lookup table is applied if compatibility is determined. However, if the delta file is determined to not be compatible with the current version of a local lookup table in an indexer, the entire lookup table sent to the requesting indexer instead.

    Adaptive monitoring and processing of new data files and changes to existing data files

    公开(公告)号:US10083190B2

    公开(公告)日:2018-09-25

    申请号:US14014059

    申请日:2013-08-29

    Applicant: Splunk Inc.

    CPC classification number: G06F16/21 G06F16/1734

    Abstract: Embodiments are directed towards a dynamic change evaluation mechanism, whereby items having a detected possible change are scheduled for re-evaluation for possible changes at a higher frequency than items detected to not have previously changed, while those items detected as not to have changed are dynamically scheduled for re-evaluation based on an evaluation backlog that may be in turn based, in part, on a time from when an item is assigned an expiration time to when the item is evaluated. In one embodiment, a possibly changed item may be assigned a new expiration time independent of the evaluation backlog. In another embodiment, if no change is detected, then the item may be assigned a new expiration time as a function of a previous expiration time and on the evaluation backlog.

    File update detection and processing

    公开(公告)号:US09767112B2

    公开(公告)日:2017-09-19

    申请号:US15224649

    申请日:2016-07-31

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30144 G06F17/3015 G06F17/30286

    Abstract: Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.

    Filesystem destinations
    27.
    发明授权

    公开(公告)号:US12174797B1

    公开(公告)日:2024-12-24

    申请号:US18103323

    申请日:2023-01-30

    Applicant: Splunk Inc.

    Abstract: A method for file system destinations includes obtaining events for storage on one or more of the storage systems. For each event, the method includes extracting at least one field value from the event, comparing the at least one field value to configurations of the storage systems to identify at least one storage system of the plurality of storage systems having a matching configuration, transmitting the event to an ingest module queue for the at least one storage system, selecting a partition for the event based on the at least one field value to obtain a selected partition, mapping the selected partition to a file using a partition mapping, and appending the event to the file on the at least one storage system.

    Detecting and resolving computer system errors using fast file change monitoring

    公开(公告)号:US11042515B2

    公开(公告)日:2021-06-22

    申请号:US16141913

    申请日:2018-09-25

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.

    QUALIFICATION PARAMETERS FOR CAPTAIN SELECTION IN A SEARCH HEAD CLUSTER

    公开(公告)号:US20210149773A1

    公开(公告)日:2021-05-20

    申请号:US17161480

    申请日:2021-01-28

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present disclosure provide solutions for determining an elected search head captain is unqualified for the position, identifying a more qualified search head, and transferring the captain position to the more qualified search head. A method is provided that includes referencing qualification parameters in an elected search head captain, determining whether the newly elected search head captain is qualified for the position based on the parameters, identifying a more qualified search head to be the search head captain if the newly elected search head captain is determined to be unqualified for the position, and transferring the position of captain to the more qualified search head. The qualification parameters may include, for example, a pre-determined static flag set by an administrator of the search environment, and configuration replication status that corresponds to the most recent configuration state of the search head as recorded by the previous search head captain.

Patent Agency Ranking