MULTI-PHASED DATA EXECUTION IN A DATA PROCESSING SYSTEM

    公开(公告)号:US20180218045A1

    公开(公告)日:2018-08-02

    申请号:US15419883

    申请日:2017-01-30

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments include a method performed by a data intake and query system. The method includes receiving a search query by a search head, defining a search process for applying the search query to indexers, delegating a first portion of the search process to indexers and a second portion of the search process to intermediary node(s) communicatively coupled to the search head and the indexers. The first portion can define a search scope for obtaining partial search results of the indexers and the second portion can define operations for combining the partial search results by the intermediary node(s) to produce a combination of the partial search results. The search head then receives the combination of the partial search results, and outputs final search results for the search query, where the final search results are based on the combination of the partial search results.

    Efficient point-in-polygon indexing technique for processing queries over geographic data sets

    公开(公告)号:US10026204B2

    公开(公告)日:2018-07-17

    申请号:US14606396

    申请日:2015-01-27

    Applicant: Splunk Inc.

    Abstract: A system that displays geographic data is disclosed. During operation, the system receives a query to be processed, wherein the query is associated with a set of geographic regions. Next, the system uses a late-binding schema generated from the query to retrieve a set of data points from a set of events containing previously gathered data. Then, for each data point in a set of data points, the system identifies zero or more geographic regions in the set of geographic regions that the data point falls into. Finally, the system displays the set of geographic regions, wherein each polygon that defines a geographic region is marked to indicate a number of data points that fall into the polygon.

    Searching Raw Data From An External Data System Using A Dual Mode Search System

    公开(公告)号:US20180157755A1

    公开(公告)日:2018-06-07

    申请号:US15885629

    申请日:2018-01-31

    Applicant: SPLUNK INC.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Events Sets In A Visually Distinct Display Format

    公开(公告)号:US20180157705A1

    公开(公告)日:2018-06-07

    申请号:US15885538

    申请日:2018-01-31

    Applicant: SPLUNK INC.

    Abstract: A request is received to display at least a portion of a first events set and at least a portion of a second events set in an interleaved and visually distinct display format, where, in the interleaved and visually distinct display format, the at least a portion of the first events set is displayed in a visually distinct manner from the at least a portion of the second events set, and data from the at least a portion of the first events set is interleaved with data from the at least a portion of the second events set. In response to receiving the request, display is caused, on a user interface, of the at least a portion of the first events set and the at least a portion of the second events set in the interleaved and visually distinct display format.

    Machine Data Analysis in an Information Technology Environment

    公开(公告)号:US20180157404A1

    公开(公告)日:2018-06-07

    申请号:US15885799

    申请日:2018-01-31

    Applicant: Splunk Inc.

    Inventor: Cary Noel Ian Link

    CPC classification number: G06F3/04847 G06F16/00 G06Q10/063

    Abstract: Data values for various items are visualized in real-time or near real-time using radial-based techniques to produce data visualizations bearing some resemblance to, for example, pie charts, radial charts, etc. The data values are shown using indicators that encircle, or at least partially encircle, a central point. One or more characteristics of the indicator reflect the value that corresponds to the indicator. The characteristics may include, for instance, the color of the indicator and/or the distance of the indicator (or more specifically, a given point on the indicator) from the central point. The characteristics of the indicators change over time, in accordance with changes in the current values of the data items. A variety of indicators may be used, including, without limitation, points, icons, pie “wedges,” filled or partially-filled sectors of an ellipse or semi-circle, arcs or lines that span between the sides of such sectors, and so forth.

    Hybrid cluster-based data intake and query

    公开(公告)号:US09990423B2

    公开(公告)日:2018-06-05

    申请号:US14526493

    申请日:2014-10-28

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30705 G06F17/30631

    Abstract: Various embodiments describe multi-site cluster-based data intake and query systems, including cloud-based data intake and query systems. Using a hybrid search system that includes cloud-based data intake and query systems working in concert with so-called “on-premises” data intake and query systems can promote the scalability of search functionality. In addition, the hybrid search system can enable data isolation in a manner in which sensitive data is maintained “on premises” and information or data that is not sensitive can be moved to the cloud-based system. Further, the cloud-based system can enable efficient leveraging of data that may already exist in the cloud.

Patent Agency Ranking