CONFIGURING THE GENERATION OF EPHEMERAL EVENT STREAMS BY REMOTE CAPTURE AGENTS

    公开(公告)号:US20200067790A1

    公开(公告)日:2020-02-27

    申请号:US16670816

    申请日:2019-10-31

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display, on a computer system, a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for managing one or more ephemeral event streams that contain temporarily generated time-series event data from the network packets, wherein managing the one or more ephemeral event streams comprises modifying an end time for terminating the capture of time-series event data in an ephemeral event stream. The system then updates the configuration information based on input received through the first set of user-interface elements.

    SELECTIVE EVENT STREAM DATA STORAGE BASED ON HISTORICAL STREAM DATA

    公开(公告)号:US20200014593A1

    公开(公告)日:2020-01-09

    申请号:US16573937

    申请日:2019-09-17

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements containing a set of statistics associated with one or more event streams that comprise the time-series event data. The system then causes for display, in the GUI, one or more graphs comprising one or more values from the set of statistics. Finally, the system causes for display, in the GUI, a value of a statistic from the set of statistics based on a position of a cursor over the one or more graphs.

    Service monitoring interface
    44.
    发明授权
    Service monitoring interface 有权
    业务监控界面

    公开(公告)号:US09590877B2

    公开(公告)日:2017-03-07

    申请号:US14933919

    申请日:2015-11-05

    Applicant: Splunk Inc.

    Abstract: Services in an operating environment are represented by stored service definitions that identify entities that perform the service. Entity definitions identify machine data pertaining to the entity. A key performance indicator (KPI) of the service characterizes the service on the whole or some aspect of it. Each KPI is defined by a search query that derives a value from machine data identified in the entity definitions. Processing devices cause display of a service-monitoring page having a services summary region and a services aspects region. The summary region displays interactive summary tiles that each correspond to a service and present information about an aggregate KPI that characterizes the service. The aspects region displays interactive aspect tiles that each correspond to a KPI characterizing some aspect of an associated service. Additional information may be included in the service-monitoring page and interaction features enable a user to navigate to enhanced information displays.

    Abstract translation: 操作环境中的服务由标识执行服务的实体的存储的服务定义来表示。 实体定义识别与实体有关的机器数据。 该服务的关键性能指标(KPI)表示服务的整体或某个方面。 每个KPI由搜索查询定义,该搜索查询从实体定义中标识的机器数据中导出值。 处理设备导致显示具有服务摘要区域和服务方面区域的服务监视页面。 摘要区域显示每个对应于服务的交互式摘要图块,并显示关于表征服务的聚合KPI的信息。 方面区域显示交互式方面图块,其各自对应于表征相关联服务的某些方面的KPI。 附加信息可能包含在服务监控页面中,交互功能使用户能够浏览到增强的信息显示。

    Service Detail Monitoring Console
    45.
    发明申请
    Service Detail Monitoring Console 审中-公开
    服务细节监控控制台

    公开(公告)号:US20160294606A1

    公开(公告)日:2016-10-06

    申请号:US15088087

    申请日:2016-03-31

    Applicant: Splunk Inc.

    CPC classification number: H04L41/0695 G06Q10/06393 H04L43/04 H04L67/22

    Abstract: An automatic service monitor in an information-technology environment performs regular search queries against generated machine data to derive performance measurements. The information technology environment is defined in terms of services provided by entities, and the performance measurements are defined as key performance indicators (KPIs) of the services. Generated machine data used by the search queries pertain to the entities performing the service. Definitional information for the services, entities, and KPIs is administered by a user to control the operation of the service monitor. Various aspects of such definitional information as well as related performance measurement information may be presented in a unified console display tailored to, and organized around, a particular service. The console display may serve as a central launch point by supporting user interaction to navigate to other specialized monitoring interfaces.

    Abstract translation: 信息技术环境中的自动服务监视器针对生成的机器数据执行定期搜索查询以导出性能测量。 信息技术环境根据实体提供的服务来定义,性能测量被定义为服务的关键绩效指标(KPI)。 搜索查询使用的生成的机器数据与执行服务的实体有关。 服务,实体和KPI的定义信息由用户管理以控制服务监视器的操作。 这种定义信息的各个方面以及相关的性能测量信息可以被呈现在针对特定服务定制并组织的统一的控制台显示中。 控制台显示可以通过支持用户交互来导航到其他专门的监控接口,作为中心发射点。

    Service monitoring interface
    46.
    发明授权
    Service monitoring interface 有权
    业务监控界面

    公开(公告)号:US09210056B1

    公开(公告)日:2015-12-08

    申请号:US14611216

    申请日:2015-01-31

    Applicant: Splunk Inc.

    Abstract: One or more processing devices cause display of a service-monitoring page having a services summary region and a services aspects region. The services summary region contains an ordered plurality of interactive summary tiles, each summary tile corresponding to a respective service and providing a character or graphical representation of at least one value for an aggregate key performance indicator (KPI) characterizing the respective service as a whole. The services aspects region contains an ordered plurality of interactive aspect tiles, each aspect tile corresponding to a respective aspect KPI and providing a character or graphical representation of one or more values for the respective aspect KPI, each aspect KPI having an associated service and typifying performance for an aspect of the associated service. Each KPI is associated with a service having a service definition, each service definition has one or more entity definitions, each entity definition having information to identity machine data related to the entity, each KPI has a definition including a search query that produces a value derived from machine data identified using one or more of the entity definitions included in the service definition, and each value is indicative of how the service in whole or part is performing at a point in time or during a period of time.

    Abstract translation: 一个或多个处理装置引起显示具有服务摘要区域和服务方面区域的服务监视页面。 服务摘要区域包含有序的多个交互式摘要瓦片,每个概要瓦片对应于相应的服务,并且提供表征作为整体的各个服务的聚合密钥性能指标(KPI)的至少一个值的字符或图形表示。 服务方面区域包含有序的多个交互方面瓦片,每个方面瓦片对应于相应的方面KPI并且提供用于各个方面KPI的一个或多个值的字符或图形表示,每个方面KPI具有相关联的服务和代表性能 对于相关服务的一个方面。 每个KPI与具有服务定义的服务相关联,每个服务定义具有一个或多个实体定义,每个实体定义具有用于识别与该实体相关的机器数据的信息,每个KPI具有包括产生一个值的搜索查询的定义 来自使用服务定义中包括的一个或多个实体定义来识别的机器数据,并且每个值指示整个或部分服务如何在时间点或一段时间内执行。

    GROUPING AND MANAGING EVENT STREAMS GENERATED FROM CAPTURED NETWORK DATA
    47.
    发明申请
    GROUPING AND MANAGING EVENT STREAMS GENERATED FROM CAPTURED NETWORK DATA 审中-公开
    从捕获的网络数据生成的事件流的分组和管理

    公开(公告)号:US20150295780A1

    公开(公告)日:2015-10-15

    申请号:US14610457

    申请日:2015-01-30

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display, on a computer system, a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for managing one or more ephemeral event streams that contain temporarily generated time-series event data from the network packets, wherein managing the one or more ephemeral event streams comprises modifying an end time for terminating the capture of time-series event data in an ephemeral event stream. The system then updates the configuration information based on input received through the first set of user-interface elements.

    Abstract translation: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,系统导致在计算机系统上显示用于从由一个或多个远程捕获代理捕获的网络分组生成时间序列事件数据的配置信息的图形用户界面(GUI)。 接下来,系统导致在GUI中显示第一组用户界面元素,用于管理从网络分组中包含临时生成的时间序列事件数据的一个或多个临时事件流,其中管理一个或多个短暂事件 流包括修改用于终止在短暂事件流中捕获时间序列事件数据的结束时间。 然后,系统基于通过第一组用户界面元素接收的输入来更新配置信息。

    Creating entity definition from a file
    48.
    发明授权
    Creating entity definition from a file 有权
    从文件创建实体定义

    公开(公告)号:US09130832B1

    公开(公告)日:2015-09-08

    申请号:US14611190

    申请日:2015-01-31

    Applicant: Splunk Inc.

    Abstract: Processing devices receive a file having entries having data items separated by delimiters. Each data item has an ordinal position. The processing device(s) cause display of a table, having rows and columns, in a graphical user interface. Each data items of a particular entry appears in a respective column of the same row. Each column corresponds to the ordinal position of its respective data item. User input is received designating, for each respective column, a field name and an entity definition component type to which the respective column pertains, and stores for each of the data items of the particular entry a value of an element of an entity definition. The element has the element name designated for the respective column in which the data item appeared, and is associated with an entity definition component having the type designated for the respective column in which the data item appeared.

    Abstract translation: 处理设备接收具有由分隔符分隔的数据项的条目的文件。 每个数据项都有一个序数位置。 处理设备使得在图形用户界面中显示具有行和列的表。 特定条目的每个数据项出现在同一行的相应列中。 每列对应于其相应数据项的序数位置。 接收到用户输入,为每个相应列指定相应列所属的字段名称和实体定义组件类型,并且为特定条目的每个数据项存储实体定义的元素的值。 元素具有为数据项出现的相应列指定的元素名称,并且与具有指定数据项出现的相应列的类型的实体定义组件相关联。

Patent Agency Ranking