Reducing index file size based on event attributes

    公开(公告)号:US11934418B2

    公开(公告)日:2024-03-19

    申请号:US17447620

    申请日:2021-09-14

    Applicant: Splunk Inc.

    CPC classification number: G06F16/248 G06F16/2228 G06F16/285 G06F16/21

    Abstract: Techniques and mechanisms are disclosed to optimize the size of index files to improve use of storage space available to indexers and other components of a data intake and query system. Index files of a data intake and query system may include, among other data, a keyword portion containing mappings between keywords and location references to event data containing the keywords. Optimizing an amount of storage space used by index files may include removing, modifying and/or recreating various components of index files in response to detecting one or more storage conditions related to the event data indexed by the index files. The optimization of index files generally may attempt to manage a tradeoff between an efficiency with which search requests can be processed using the index files and an amount of storage space occupied by the index files.

    Identifying an indexing node to process data using a resource catalog

    公开(公告)号:US11892996B1

    公开(公告)日:2024-02-06

    申请号:US16513365

    申请日:2019-07-16

    Applicant: Splunk Inc.

    Abstract: Systems and methods are described for monitoring indexing nodes, populating and maintaining a resource catalog with relevant information, receiving requests for indexing node availability or assignments, identifying indexing nodes that are available to process data, and/or communicating information relating to available indexing nodes. The system can maintain the resource catalog based on communications with each of the containerized indexing nodes. The system can receive, from a partition manager of a data intake and query system, a request for a containerized indexing node that the partition manager can assign to process data received by the partition manager. The system can identify an available containerized indexing node to process the data. The system can communicate, to the partition manager, an indexing node identifier associated with the available containerized indexing node.

    Reducing index file size based on event attributes

    公开(公告)号:US11138218B2

    公开(公告)日:2021-10-05

    申请号:US16259975

    申请日:2019-01-28

    Applicant: Splunk Inc.

    Abstract: Techniques and mechanisms are disclosed to optimize the size of index files to improve use of storage space available to indexers and other components of a data intake and query system. Index files of a data intake and query system may include, among other data, a keyword portion containing mappings between keywords and location references to event data containing the keywords. Optimizing an amount of storage space used by index files may include removing, modifying and/or recreating various components of index files in response to detecting one or more storage conditions related to the event data indexed by the index files. The optimization of index files generally may attempt to manage a tradeoff between an efficiency with which search requests can be processed using the index files and an amount of storage space occupied by the index files.

    DETERMINING AND SPAWNING A NUMBER AND TYPE OF ERP PROCESSES

    公开(公告)号:US20210042369A1

    公开(公告)日:2021-02-11

    申请号:US17080032

    申请日:2020-10-26

    Applicant: SPLUNK Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing realtime search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    UTILIZING A DUAL MODE SEARCH
    39.
    发明申请

    公开(公告)号:US20190278868A9

    公开(公告)日:2019-09-12

    申请号:US15885629

    申请日:2018-01-31

    Applicant: SPLUNK INC.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

Patent Agency Ranking