SEARCHING NON-TEXT MACHINE DATA
    441.
    发明申请

    公开(公告)号:US20180032558A1

    公开(公告)日:2018-02-01

    申请号:US15664991

    申请日:2017-07-31

    Applicant: SPLUNK, Inc.

    Inventor: ADAM OLINER

    CPC classification number: G06F16/43 G06F16/438

    Abstract: Described herein are technologies that facilitate effective use (e.g., indexing and searching) of non-text machine data (e.g., audio/visual data) in an event-based machine-data intake and query system.

    PRIORITY-BASED PROCESSING OF MESSAGES FROM MULTIPLE SERVERS

    公开(公告)号:US20180007180A1

    公开(公告)日:2018-01-04

    申请号:US15703209

    申请日:2017-09-13

    Applicant: Splunk Inc.

    Abstract: Systems and methods for priority-based processing of messages received from multiple servers. An example method comprises: receiving a plurality of network packets from one or more servers; processing the plurality of network packets to produce a first message associated with a first timestamp and a second message associated with a second timestamp; writing the first message to a first message queue of a plurality of message queues; writing the second message to a second message queue of the plurality of message queues; and retrieving, from the plurality of message queues, the first message and the second message in an order of their respective associated timestamps.

    Security compliance for cloud-based machine data acquisition and search system

    公开(公告)号:US09853946B2

    公开(公告)日:2017-12-26

    申请号:US14806510

    申请日:2015-07-22

    Applicant: Splunk Inc.

    Abstract: Disclosed herein are a method, apparatus and system that authenticate a first data forwarder, of a distributed machine data acquisition and search system (MDASS), to a node that regulates traversal of a firewall that protects a protected environment within which the data forwarder operates. The authentication may be performed by using a SOCKS5 authentication process. The method further includes, only after successful completion of the SOCKS5 authentication process, establishing a first connection, through a network, between the first data forwarder and a first indexer of the distributed MDASS, where the first indexer operates outside the protected environment, and sending machine data acquired by the first data forwarder from a machine data source, to the first indexer via the first connection.

    Three-dimensional point-in-polygon operation to facilitate displaying three-dimensional structures

    公开(公告)号:US09842432B2

    公开(公告)日:2017-12-12

    申请号:US15421290

    申请日:2017-01-31

    Applicant: SPLUNK INC.

    Abstract: A system, a method and instructions embodied on a non-transitory computer-readable storage medium that solve a 3D point-in-polygon (PIP) problem is presented. This system projects polygons that comprise a set of polyhedra onto projected polygons in a reference plane. Next, the system projects a data point onto the reference plane, and performs a 2D PIP operation in the reference plane to determine which projected polygons the projected data point falls into. For each projected polygon the projected data point falls into, the system performs a 3D crossing number operation by counting intersections between a ray projected from the corresponding data point in a direction orthogonal to the reference plane and polyhedral faces corresponding to projected polygons, to identify polyhedra the data point falls into. The system then generates a visual representation of the set of polyhedra, wherein each polyhedron is affected by data points that fall into it.

    Central registry for binding features using dynamic pointers

    公开(公告)号:US09836336B2

    公开(公告)日:2017-12-05

    申请号:US14962970

    申请日:2015-12-08

    Applicant: Splunk Inc.

    Inventor: Itay A. Neeman

    Abstract: A first feature (e.g., chart or table) includes a reference to a dynamic pointer. Independently, the pointer is defined to point to a second feature (e.g., a query). The first feature is automatically updated to reflect a current value of the second feature. The reference to the pointer and pointer definition are recorded in a central registry, and changes to the pointer or second feature automatically cause the first feature to be updated to reflect the change. A mapping between features can be generated using the registry and can identify interrelationships to a developer. Further, changes in the registry can be tracked, such that a developer can view changes pertaining to a particular time period and/or feature of interest (e.g., corresponding to an operation problem).

    CORRELATING APPLICATION ERRORS WITH INCOMPLETE TRANSACTIONS

    公开(公告)号:US20170329662A1

    公开(公告)日:2017-11-16

    申请号:US15663513

    申请日:2017-07-28

    Applicant: Splunk Inc.

    Abstract: Various methods and systems for tracking incomplete purchases in correlation with application performance, such as application errors or crashes, are provided. In this regard, aspects of the invention facilitate monitoring transaction and application error events and analyzing data associated therewith to identify data indicating an impact of incomplete purchases in relation to an error(s) such that application performance can be improved. In various implementations, application data associated with an application installed on a mobile device is received. The application data is used to determine that an error that occurred in association with the application installed on the mobile device correlates with an incomplete monetary transaction initiated via the application. Based on the error correlating with the incomplete monetary transaction, a transaction attribute associated with the error is determined.

    Generating and storing summarization tables for searchable events

    公开(公告)号:US09817854B2

    公开(公告)日:2017-11-14

    申请号:US15007185

    申请日:2016-01-26

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed are towards the transparent summarization of events. Queries directed towards summarizing and reporting on event records may be received at a search head. Search heads may be associated with one more indexers containing event records. The search head may forward the query to the indexers the can resolve the query for concurrent execution. If a query is a collection query, indexers may generate summarization information based on event records located on the indexers. Event record fields included in the summarization information may be determined based on terms included in the collection query. If a query is a stats query, each indexer may generate a partial result set from previously generated summarization information, returning the partial result sets to the search head. Collection queries may be saved and scheduled to run and periodically update the summarization information.

Patent Agency Ranking