TRIGGERING GENERATION OF AN ACCELERATED DATA MODEL SUMMARY FOR A DATA MODEL

    公开(公告)号:US20200334309A1

    公开(公告)日:2020-10-22

    申请号:US16900628

    申请日:2020-06-12

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.

    Configuring nodes of distributed systems

    公开(公告)号:US10798148B2

    公开(公告)日:2020-10-06

    申请号:US16202990

    申请日:2018-11-28

    Applicant: SPLUNK INC.

    Abstract: In a computer-implemented method for configuring a distributed computer system comprising a plurality of nodes of a plurality of node classes, configuration files for a plurality of nodes of each of the plurality of node classes are stored in a central repository. The configuration files include information representing a desired system state of the distributed computer system, and the distributed computer system operates to keep an actual system state of the distributed computer system consistent with the desired system state. The plurality of node classes includes forwarder nodes for receiving data from an input source, indexer nodes for indexing the data, and search head nodes for searching the data. Responsive to receiving changes to the configuration files, the changes are propagated to nodes of the plurality of nodes impacted by the changes based on a node class of the nodes impacted by the changes.

    UTILIZING A DUAL MODE SEARCH
    43.
    发明申请

    公开(公告)号:US20190278868A9

    公开(公告)日:2019-09-12

    申请号:US15885629

    申请日:2018-01-31

    Applicant: SPLUNK INC.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Report acceleration using intermediate summaries

    公开(公告)号:US10255310B2

    公开(公告)日:2019-04-09

    申请号:US14530678

    申请日:2014-10-31

    Applicant: Splunk Inc.

    Abstract: A method and system for managing searches of a data set that is partitioned based on a plurality of events. A structure of a search query may be analyzed to determine if logical computational actions performed on the data set is reducible. Data in each partition is analyzed to determine if at least a portion of the data in the partition is reducible. In response to a subsequent or reoccurring search request, intermediate summaries of reducible data and reducible search computations may be aggregated for each partition. Next, a search result may be generated based on at least one of the aggregated intermediate summaries, the aggregated reducible search computations, and a query of adhoc non-reducible data arranged in at least one of the plurality of partitions for the data set.

    Archiving indexed data
    45.
    发明授权

    公开(公告)号:US10152480B2

    公开(公告)日:2018-12-11

    申请号:US14611225

    申请日:2015-01-31

    Applicant: Splunk Inc.

    Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.

    ARCHIVING INDEXED DATA
    48.
    发明申请
    ARCHIVING INDEXED DATA 审中-公开
    归档索引数据

    公开(公告)号:US20160224570A1

    公开(公告)日:2016-08-04

    申请号:US14611225

    申请日:2015-01-31

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30073 G06F17/30336 G06F17/30427

    Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.

    Abstract translation: 分布式服务器中的原始数据被划分为称为存储桶的数据组,其中包含具有落在特定时间范围内的时间戳的原始数据。 当桶变为不活动时,服务器可以将存储桶存储到外部存储系统。 可以在搜索查询中指定包含归档数据的外部存储系统。 获取,处理来自外部存储系统的存档数据,并使用搜索查询对已处理归档数据执行搜索。

    Report acceleration using intermediate results in a distributed indexer system for searching events
    49.
    发明授权
    Report acceleration using intermediate results in a distributed indexer system for searching events 有权
    在分布式索引器系统中使用中间结果报告加速度,用于搜索事件

    公开(公告)号:US09177002B2

    公开(公告)日:2015-11-03

    申请号:US14168738

    申请日:2014-01-30

    Applicant: SPLUNK INC.

    Abstract: A method and system for managing searches of a data set that is partitioned based on a plurality of events. A structure of a search query may be analyzed to determine if logical computational actions performed on the data set is reducible. Data in each partition is analyzed to determine if at least a portion of the data in the partition is reducible. In response to a subsequent or reoccurring search request, intermediate summaries of reducible data and reducible search computations may be aggregated for each partition. Next, a search result may be generated based on at least one of the aggregated intermediate summaries, the aggregated reducible search computations, and a query of adhoc non-reducible data arranged in at least one of the plurality of partitions for the data set.

    Abstract translation: 一种用于管理基于多个事件划分的数据集的搜索的方法和系统。 可以分析搜索查询的结构以确定对数据集执行的逻辑计算动作是否可减少。 分析每个分区中的数据以确定分区中的数据的至少一部分是否可缩减。 响应于随后或重复出现的搜索请求,可以针对每个分区聚合可缩减数据和可缩减搜索计算的中间摘要。 接下来,可以基于聚合中间摘要,聚合可缩减搜索计算以及排列在用于数据集的多个分区中的至少一个分区中的adhoc不可还原数据的查询中的至少一个来生成搜索结果。

    Generating search results based on intermediate summaries

    公开(公告)号:US11914562B1

    公开(公告)日:2024-02-27

    申请号:US18166326

    申请日:2023-02-08

    Applicant: SPLUNK INC.

    Abstract: A method and system for managing searches of a data set that is partitioned based on a plurality of events. A structure of a search query may be analyzed to determine if logical computational actions performed on the data set is reducible. Data in each partition is analyzed to determine if at least a portion of the data in the partition is reducible. In response to a subsequent or reoccurring search request, intermediate summaries of reducible data and reducible search computations may be aggregated for each partition. Next, a search result may be generated based on at least one of the aggregated intermediate summaries, the aggregated reducible search computations, and a query of adhoc non-reducible data arranged in at least one of the plurality of partitions for the data set.

Patent Agency Ranking