PREVIEWING PARSED RAW DATA USING A GRAPHICAL USER INTERFACE
    23.
    发明申请
    PREVIEWING PARSED RAW DATA USING A GRAPHICAL USER INTERFACE 有权
    使用图形用户界面预览分色的RAW数据

    公开(公告)号:US20160055214A1

    公开(公告)日:2016-02-25

    申请号:US14929332

    申请日:2015-10-31

    申请人: Splunk Inc.

    摘要: Embodiments are directed towards previewing results generated from indexing data raw data before the corresponding index data is added to an index store. Raw data may be received from a preview data source. After an initial set of configuration information may be established, the preview data may be submitted to an index processing pipeline. A previewing application may generate preview results based on the preview index data and the configuration information. The preview results may enable previewing how the data is being processed by the indexing application. If the preview results are not acceptable, the configuration information may be modified. The preview application enables modification of the configuration information until the generated preview results may be acceptable. If the configuration information is acceptable, the preview data may be processed and indexed in one or more index stores.

    摘要翻译: 实施例针对在将对应的索引数据添加到索引存储之前预览从索引数据原始数据生成的结果。 可以从预览数据源接收原始数据。 在可以建立一组初始配置信息之后,可以将预览数据提交给索引处理流水线。 预览应用可以基于预览索引数据和配置信息生成预览结果。 预览结果可能可以预览索引应用程序如何处理数据。 如果预览结果不可接受,则可以修改配置信息。 预览应用程序可以修改配置信息,直到生成的预览结果可以接受。 如果配置信息是可接受的,则预览数据可以在一个或多个索引存储中被处理和索引。

    GENERATION OF A DATA MODEL APPLIED TO OBJECT QUERIES
    24.
    发明申请
    GENERATION OF A DATA MODEL APPLIED TO OBJECT QUERIES 有权
    适用于对象查询的数据模型的生成

    公开(公告)号:US20150339344A1

    公开(公告)日:2015-11-26

    申请号:US14815884

    申请日:2015-07-31

    申请人: Splunk Inc.

    IPC分类号: G06F17/30

    摘要: Embodiments include generating data models that may give semantic meaning for unstructured or structured data that may include data generated and/or received by search engines, including a time series engine. A method includes generating a data model for data stored in a repository. Generating the data model includes generating an initial query string, executing the initial query string on the data, generating an initial result set based on the initial query string being executed on the data, determining one or more candidate fields from one or results of the initial result set, generating a candidate data model based on the one or more candidate fields, iteratively modifying the candidate data model until the candidate data model models the data, and using the candidate data model as the data model.

    摘要翻译: 实施例包括生成可以给非结构化或结构化数据赋予语义意义的数据模型,其可以包括由搜索引擎(包括时间序列引擎)生成和/或接收的数据。 一种方法包括为存储在存储库中的数据生成数据模型。 生成数据模型包括生成初始查询字符串,对数据执行初始查询字符串,基于对数据执行的初始查询字符串生成初始结果集,从一个或多个初始查询字符串的结果确定一个或多个候选字段 生成基于一个或多个候选字段的候选数据模型,迭代地修改候选数据模型,直到候选数据模型对数据建模,并使用候选数据模型作为数据模型。

    Scalable Interactive Display Of Distributed Data
    27.
    发明申请
    Scalable Interactive Display Of Distributed Data 有权
    分布式数据的可扩展交互式显示

    公开(公告)号:US20140317111A1

    公开(公告)日:2014-10-23

    申请号:US14266838

    申请日:2014-05-01

    申请人: Splunk Inc.

    IPC分类号: G06F17/30

    摘要: A method, system, and processor-readable storage medium are directed towards generating a report derived from data, such as event data, stored on a plurality of distributed nodes. In one embodiment the analysis is generated using a “divide and conquer” algorithm, such that each distributed node analyzes locally stored event data while an aggregating node combines these analysis results to generate the report. In one embodiment, each distributed node also transmits a list of event data references associated with the analysis result to the aggregating node. The aggregating node may then generate a global ordered list of data references based on the list of event data references received from each distributed node. Subsequently, in response to a user selection of a range of global event data, the report may dynamically retrieve event data from one or more distributed nodes for display according to the global order.

    摘要翻译: 方法,系统和处理器可读存储介质被引导为生成从存储在多个分布式节点上的诸如事件数据的数据导出的报告。 在一个实施例中,使用“分割和征服”算法生成分析,使得每个分布式节点分析本地存储的事件数据,而聚合节点组合这些分析结果以生成报告。 在一个实施例中,每个分布式节点还将与分析结果相关联的事件数据引用的列表发送到聚合节点。 然后,聚合节点可以基于从每个分布式节点接收的事件数据参考的列表来生成数据引用的全局有序列表。 随后,响应于用户选择一系列全局事件数据,报告可以动态地从一个或多个分布式节点检索事件数据,以便根据全局顺序进行显示。

    DISTRIBUTED LICENSE MANAGEMENT FOR A DATA LIMITED APPLICATION
    28.
    发明申请
    DISTRIBUTED LICENSE MANAGEMENT FOR A DATA LIMITED APPLICATION 审中-公开
    数据有限应用程序的分销许可管理

    公开(公告)号:US20140229490A1

    公开(公告)日:2014-08-14

    申请号:US14052563

    申请日:2013-10-11

    申请人: Splunk Inc.

    IPC分类号: G06F17/30

    摘要: The invention is directed towards enabling data volume and data type based licensing of software in a distributed system of a plurality of remote and/or local nodes. The invention enables measuring and optionally restricting the use of software based on one or more provided licenses that restrict the amount and type of data that may be processed by the software. New and older licenses may be added together for a single, bulk entitlement for a given volume of data processing for one or all types of data. Different users in the same enterprise may combine license entitlements too. Also, a new license can be acquired repeatedly, without requiring the issuance of combined licenses by the issuing authority and/or the revocation of prior licenses.

    摘要翻译: 本发明旨在实现在多个远程和/或本地节点的分布式系统中的软件的基于数据量和数据类型的许可。 本发明能够测量和可选地限制基于限制软件可能处理的数据的数量和类型的一个或多个所提供的许可证的软件的使用。 新一代和更旧的许可证可以一起添加,用于针对一种或所有类型的数据的给定数据量处理的单个批量权利。 同一企业的不同用户也可以组合许可证授权。 此外,可以重复获得新的许可证,而不需要发证机构签发合并的许可证和/或撤销先前的许可证。

    DATA MODEL FOR MACHINE DATA FOR SEMANTIC SEARCH
    29.
    发明申请
    DATA MODEL FOR MACHINE DATA FOR SEMANTIC SEARCH 有权
    用于语义搜索的机器数据的数据模型

    公开(公告)号:US20140074817A1

    公开(公告)日:2014-03-13

    申请号:US13662369

    申请日:2012-10-26

    申请人: SPLUNK INC.

    IPC分类号: G06F17/30

    摘要: Embodiments are directed towards generating data models that may give semantic meaning for unstructured data or structured data that may include data generated and/or received by search engines, including a time series engine. Data models also may be generated to provide semantic meaning to structured data. A data model may be composed of a hierarchical data model objects analogous to an object-oriented programming class hierarchy. Users may employ a data modeling application to produce reports using search objects that may be part of, or associated with the data model. The data modeling application may employ the search object and the data model to generate a query string for searching a data repository to produce a result set. A data modeling application may map the result set data to data model objects that may be used to generate reports.

    摘要翻译: 实施例涉及生成可能给非结构化数据或结构化数据提供语义意义的数据模型,这些结构化数据或结构化数据可能包括由搜索引擎(包括时间序列引擎)生成和/或接收的数据。 也可以生成数据模型以为结构化数据提供语义。 数据模型可以由类似于面向对象的编程类层次结构的分层数据模型对象组成。 用户可以使用数据建模应用程序来生成使用可能是数据模型的一部分或与数据模型相关联的搜索对象的报告。 数据建模应用程序可以使用搜索对象和数据模型来生成用于搜索数据存储库以产生结果集的查询字符串。 数据建模应用程序可将结果集数据映射到可用于生成报告的数据模型对象。

    CLUSTERING FOR HIGH AVAILABILITY AND DISASTER RECOVERY
    30.
    发明申请
    CLUSTERING FOR HIGH AVAILABILITY AND DISASTER RECOVERY 有权
    聚集高可用性和灾难恢复

    公开(公告)号:US20130311427A1

    公开(公告)日:2013-11-21

    申请号:US13648116

    申请日:2012-10-09

    申请人: SPLUNK INC.

    IPC分类号: G06F17/30

    摘要: Embodiments are directed towards managing within a cluster environment having a plurality of indexers for data storage using redundancy the data being managed using a generation identifier, such that a primary indexer is designated for a given generation of data. When a master device for the cluster fails, data may continue to be stored using redundancy, and data searches performed may still be performed.

    摘要翻译: 实施例旨在在具有多个索引器的集群环境内管理,用于使用生成标识符来管理数据的冗余来进行数据存储,从而为指定的生成数据指定主索引器。 当集群的主设备发生故障时,可以继续使用冗余来存储数据,并且仍然可以执行数据搜索。