Intelligent search-time determination and usage of fields extracted at index-time

    公开(公告)号:US12038926B1

    公开(公告)日:2024-07-16

    申请号:US17163220

    申请日:2021-01-29

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/2455 G06F16/2228

    Abstract: A computer-implemented method of determining indexed fields at query time comprises mapping data from a first source type to indexed fields in batch form using a wildcard specifier. The method also comprises receiving a query to execute on a data set comprising data from the first source type and data from a second source type. Further, the method comprises transforming the query to execute on the data from the first source type separately from the data from the second source type. Additionally, the method comprises executing the query to operate on the data from the first source type using information associated with the indexed fields and to separately operate on the data from the second source type.

    Report acceleration using intermediate results in a distributed indexer system

    公开(公告)号:US11030173B1

    公开(公告)日:2021-06-08

    申请号:US16920187

    申请日:2020-07-02

    Applicant: Splunk Inc.

    Abstract: A method and system for managing searches of a data set that is partitioned based on a plurality of events. A structure of a search query may be analyzed to determine if logical computational actions performed on the data set is reducible. Data in each partition is analyzed to determine if at least a portion of the data in the partition is reducible. In response to a subsequent or reoccurring search request, intermediate summaries of reducible data and reducible search computations may be aggregated for each partition. Next, a search result may be generated based on at least one of the aggregated intermediate summaries, the aggregated reducible search computations, and a query of adhoc non-reducible data arranged in at least one of the plurality of partitions for the data set.

    Report acceleration using intermediate summaries

    公开(公告)号:US10255310B2

    公开(公告)日:2019-04-09

    申请号:US14530678

    申请日:2014-10-31

    Applicant: Splunk Inc.

    Abstract: A method and system for managing searches of a data set that is partitioned based on a plurality of events. A structure of a search query may be analyzed to determine if logical computational actions performed on the data set is reducible. Data in each partition is analyzed to determine if at least a portion of the data in the partition is reducible. In response to a subsequent or reoccurring search request, intermediate summaries of reducible data and reducible search computations may be aggregated for each partition. Next, a search result may be generated based on at least one of the aggregated intermediate summaries, the aggregated reducible search computations, and a query of adhoc non-reducible data arranged in at least one of the plurality of partitions for the data set.

Patent Agency Ranking