-
公开(公告)号:US20170315796A1
公开(公告)日:2017-11-02
申请号:US15143438
申请日:2016-04-29
Applicant: Splunk, Inc.
Inventor: Grigori Melnik , David Searle Noble , Itay Alfred Neeman , Cecelia Campbell
Abstract: An application development and deployment system allows an application developer to develop applications for a distributed data intake and query system. The application may include information that associates portions of the application with particular server groups of the distributed data intake and query system. The application may be partitioned to generate target application packages for each of the server groups of the data intake and query system.
-
公开(公告)号:US09807192B1
公开(公告)日:2017-10-31
申请号:US15582542
申请日:2017-04-28
Applicant: Splunk Inc.
Inventor: Tristan Fletcher , Brian Bingham
CPC classification number: H04L67/2861 , G06F9/4881 , G06F9/5005 , G06F9/5011 , G06F9/5033 , G06F9/505 , G06F9/54 , G06F17/30619 , G06F17/30675 , H04L63/08
Abstract: A scheduler manages execution of a plurality of data-collection jobs, assigns individual jobs to specific forwarders in a set of forwarders, and generates and transmits tokens (e.g., pairs of data-collection tasks and target sources) to assigned forwarders. The forwarder uses the tokens, along with stored information applicable across jobs, to collect data from the target source and forward it onto an indexer for processing. For example, the indexer can then break a data stream into discrete events, extract a timestamp from each event and index (e.g., store) the event based on the timestamp. The scheduler can monitor forwarders' job performance, such that it can use the performance to influence subsequent job assignments. Thus, data-collection jobs can be efficiently assigned to and executed by a group of forwarders, where the group can potentially be diverse and dynamic in size.
-
公开(公告)号:US20170286525A1
公开(公告)日:2017-10-05
申请号:US15143563
申请日:2016-04-30
Applicant: Splunk Inc.
Inventor: Li Li , Gang Tao , Yongxin Su , Junqing Hao , Ting Wang , John Robert Coates , Elias Haddad , Guodong Wang
IPC: G06F17/30 , G06F3/0484
CPC classification number: G06F16/287 , G06F16/2477
Abstract: The operation of an automatic data input and query system is controlled by well-defined control data. Certain control data may relate to data schemas and direct operations performed by the system to extract fields from machine data. Automatic methods may determine proper field extraction control information by analyzing a sample of data from a source, breaking the sample data into event segments, classifying the segments into groups based on a measure of similarity, determining an operable extraction rule for each group, and storing the resulting extraction model. Data patterns known by the system can be leveraged to perform the event breaking and field identification for the classifying. Embodiments may provide a user interface to view, interact with, and approve the computer-generated extraction model.
-
公开(公告)号:US09762455B2
公开(公告)日:2017-09-12
申请号:US15296030
申请日:2016-10-17
Applicant: Splunk Inc.
IPC: G06F15/16 , H04L12/24 , H04L29/08 , G06F3/0482 , G06F3/0484 , H04L12/26 , G06Q10/06
CPC classification number: H04L41/5032 , G06F3/0482 , G06F3/04842 , G06Q10/06393 , H04L29/08072 , H04L41/0213 , H04L41/12 , H04L41/22 , H04L41/5006 , H04L41/5009 , H04L43/04 , H04L43/045 , H04L43/16 , H04L67/16 , H04L67/2809
Abstract: One or more processing devices derive values indicative of various aspects of how a particular service in an information technology (IT) environment is performing at a point in time or for a period of time. The values are derived by a search query over machine data associated with the one or more entities that provide the service. The one or more processing devices determine a value for an aggregate key performance indicator (KPI) for the service to indicate or characterize the service overall from values for each of the various aspects.
-
公开(公告)号:US09762443B2
公开(公告)日:2017-09-12
申请号:US14253753
申请日:2014-04-15
Applicant: Splunk Inc.
Inventor: Michael Dickey
CPC classification number: H04L43/04 , H04L41/046 , H04L41/0816 , H04L41/0856 , H04L43/106
Abstract: The disclosed embodiments provide a method and system for processing network data. During operation, the system obtains, at a remote capture agent, configuration information for the remote capture agent from a configuration server over a network. Next, the system uses the configuration information to configure the generation of event data from network data obtained from network packets at the remote capture agent. The system then uses the configuration information to configure transformation of the event data or the network data into transformed event data at the remote capture agent.
-
公开(公告)号:US09760240B2
公开(公告)日:2017-09-12
申请号:US14859233
申请日:2015-09-18
Applicant: Splunk Inc.
Inventor: Sonal Maheshwari , Manish Sainani , Leonid Alekseyev , Alan Hardin , Jacob Barton Leverich , Adam Jamison Oliner , Brian Reyes , Alok Anant Bhide
IPC: G06F15/16 , G06F3/0481 , G06T11/20 , G06F17/30 , H04L29/08
CPC classification number: G06F3/0481 , G06F3/04812 , G06F17/30548 , G06F17/30554 , G06Q10/00 , G06T11/206 , H04L67/1095
Abstract: Techniques are disclosed for providing a graphical user interface (GUI) for displaying and configuring adaptive or static thresholds for Key Performance Indicators (KPIs). The GUI may include one or more presentation schedules that may display threshold information associated with time policies. Each presentation schedule may include multiple time slots and span a portion of one or more time cycles. Some of the time slots may be associated with a specific time policy and may have a unifying appearance that distinguishes the time slots from timeslots associated with other time policies. The presentation schedules may arrange the time slots in a time grid arrangement (e.g., calendar grid view) or a graph arrangement with depictions (e.g., points, lines) that may illustrate KPI values and threshold markers that may illustrate the threshold values.
-
公开(公告)号:US20170255601A1
公开(公告)日:2017-09-07
申请号:US15582668
申请日:2017-04-29
Applicant: SPLUNK, Inc.
Inventor: R. David Carasso , Micah James Delfino , Johnvey Hwang
CPC classification number: G06F16/287 , G06F3/0482 , G06F3/04842 , G06F16/248 , G06F16/332 , G06F16/334 , G06F16/338 , G06F16/34 , G06F16/93 , G06F16/951 , G06F17/24 , G06F17/241 , G06F17/243 , G06Q10/00 , G06Q10/0637 , Y04S10/54
Abstract: Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.
-
公开(公告)号:US09754395B2
公开(公告)日:2017-09-05
申请号:US14801721
申请日:2015-07-16
Applicant: Splunk Inc.
Inventor: Tristan Fletcher , Cary Glen Noel
IPC: G06T11/20
CPC classification number: G06T11/206
Abstract: The disclosed embodiments relate to a system that displays performance data for a computing environment. During operation, the system first determines values for a performance metric for a plurality of entities that comprise the computing environment. Next, the system displays the computing environment as a set of nodes representing the plurality of entities. While displaying the nodes, the system displays a chart with a line illustrating how a value of the performance metric for the selected node varies over time, wherein the line is displayed against a background illustrating how a distribution of the performance metric for a reference subset of the set of nodes varies over time.
-
公开(公告)号:US09747152B2
公开(公告)日:2017-08-29
申请号:US14697427
申请日:2015-04-27
Applicant: SPLUNK INC.
Inventor: Konstantinos Polychronis
CPC classification number: G06F11/079 , G06Q20/32 , G06Q20/382 , G06Q20/4016 , G06Q20/407
Abstract: Various methods and systems for tracking incomplete purchases in correlation with application performance, such as application errors or crashes, are provided. In this regard, aspects of the invention facilitate monitoring transaction and application error events and analyzing data associated therewith to identify data indicating an impact of incomplete purchases in relation to an error(s) such that application performance can be improved. In various implementations, application data associated with an application installed on a mobile device is received. The application data is used to determine that an error that occurred in association with the application installed on the mobile device correlates with an incomplete monetary transaction initiated via the application. Based on the error correlating with the incomplete monetary transaction, a transaction attribute associated with the error is determined.
-
公开(公告)号:US20170223030A1
公开(公告)日:2017-08-03
申请号:US15011414
申请日:2016-01-29
Applicant: Splunk Inc.
Inventor: Munawar Monzy Merza
IPC: H04L29/06
CPC classification number: H04L63/1416 , H04L63/02
Abstract: In a method, a plurality of events is accessed, wherein an event of the plurality of events includes a portion of raw-machine data from a data source of a plurality of data sources. For at least one event of the plurality of events, a transaction phase of a computer security transaction is correlated with the at least one event based at least in part on a data source associated with the at least one event. The transaction phase of the at least one event is correlated with a particular asset of a plurality of assets.
-
-
-
-
-
-
-
-
-