High availability scheduler for scheduling map-reduce searches based on a leader state

    公开(公告)号:US10698777B2

    公开(公告)日:2020-06-30

    申请号:US15964940

    申请日:2018-04-27

    Applicant: Splunk Inc.

    Inventor: Anirban Rahut

    Abstract: A high availability scheduler of tasks in a cluster of server devices is provided. A server device of the cluster of server devices enters a leader state based upon the results of an election process in which the server device participates with others of the cluster of server devices. Upon entering the leader state, the server device schedules one or more tasks by assigning each of the one or more tasks to a device, wherein the one or more tasks involve initiating a search of time stamped events.

    Clustered search head configurations synchronization with bloom filter

    公开(公告)号:US10606810B2

    公开(公告)日:2020-03-31

    申请号:US15401427

    申请日:2017-01-09

    Applicant: Splunk Inc.

    Inventor: Yuan Xu

    Abstract: Embodiments of the present disclosure provide techniques for efficiently and accurately performing propagation of search-head specific configuration customizations across multiple individual configuration files of search heads of a cluster for a consistent user experience. The cluster of search heads may be synchronized such that the search heads operate to receive the configuration or knowledge object customizations from one or more clients from a central or lead search head. To reduce the amount of data that is transferred during propagation, the list of configuration or knowledge object customizations maintained in each search head is filtered from the list of the lead search head until a divergence point is determined. Once determined and communicated to the lead search head, the lead search head sends the configuration and knowledge object customization data that is absent from the internal list of the member search head.

    Anonymizing machine data events
    306.
    发明授权

    公开(公告)号:US10592694B2

    公开(公告)日:2020-03-17

    申请号:US15798317

    申请日:2017-10-30

    Applicant: Splunk Inc.

    Inventor: David Carasso

    Abstract: Components of a system for generating anonymized data from timestamped event data are disclosed. The generation of anonymized data is performed in accordance with an anonymization configuration. The anonymization configuration includes information regarding the source of the event data, particulars about the anonymization process that transforms the clear event data from the source into an anonymized form, and particulars about the destination and characteristics for the output dataset. A graphical user interface permits development of anonymization configurations in an interactive, iterative way. The configured anonymizer employs methods and options to produce anonymized data with superior usability as a substitute for real world data, including a mode to effectively emulate live data streams.

    Batch searches in data fabric service system

    公开(公告)号:US10592563B2

    公开(公告)日:2020-03-17

    申请号:US15339853

    申请日:2016-10-31

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments include a technique to obtain search results from the application of transformation operations on partial search results obtained from across internal and/or external data sources. Examples of transformation operations include arithmetic operations such as an average, mean, count, or the like. Examples of reporting transformations include join operations, statistics, sort, top head. Hence, the search results of a search query can be derived from partial search result rather than include the actual partial search results. In this case, the ordering of the search results may be nonessential. An example of a search query that requires a transformation operation is a “batch” or “reporting” search query. The related disclosed techniques involve obtaining data stored in the bid data ecosystem, and returning that data or data derived from that data.

    Key indicators view
    310.
    发明授权

    公开(公告)号:US10574548B2

    公开(公告)日:2020-02-25

    申请号:US13956338

    申请日:2013-07-31

    Applicant: Splunk, Inc.

    Abstract: A system and computer-implemented is provided for displaying a configurable metric relating to an environment in a graphical display along with a value of the metric calculated over a configurable time period. The metric is used to identify events of interest in the environment based on processing real time machine data from one or more sources. The configurable metric is selected and a corresponding value is calculated based on the events of interest over the configurable time period. The value of the metric may be continuously updated in real time based on receiving additional real-time machine data and displayed in a graphical interface as time progresses. Statistical trends in the value of the metric may also be determined over the configurable time period and displayed in the graphical interface as well as an indication if the value of the metric exceeds a configurable threshold value. Further, a selection of one or more thresholds for the value of the metric may be applied and an indication displayed indicating if the threshold(s) have been exceeded.

Patent Agency Ranking