Queries based on selected subsets of textual representations of events

    公开(公告)号:US11741086B2

    公开(公告)日:2023-08-29

    申请号:US17121935

    申请日:2020-12-15

    申请人: SPLUNK Inc.

    摘要: A search interface is displayed in a table format that includes one or more columns, each column including data items of an event attribute, the data items being of a set of events, and a plurality of rows forming cells with the one or more columns, each cell displaying a textual representation of at least one of the data items of the event attribute of a corresponding column. Based on a user selecting a portion of the textual representation in a corresponding cell, a list of options is displayed that corresponds to the selected portion of the textual representation. Furthermore, one or more commands are added to a search query that corresponds to the set of events, the one or more commands being based on at least an option that is selected from the list of options and the selected portion of the textual representation in the corresponding cell.

    Secure update of dashboard properties

    公开(公告)号:US11736452B1

    公开(公告)日:2023-08-22

    申请号:US17246536

    申请日:2021-04-30

    申请人: SPLUNK INC.

    IPC分类号: H04L9/40

    摘要: In various embodiments, a computer-implemented method comprises determining that a first property associated with a dashboard is modified at a first device, determining that the dashboard is accessible at a second device, where the first device and the second device are coupled via a trusted tunnel bridge, and in a real-time response to determining that the first property was modified, transmitting, to the second device via the trusted tunnel bridge, an update that causes the second device modify the dashboard based on the modified first property.

    Online data decomposition
    85.
    发明授权

    公开(公告)号:US11729074B1

    公开(公告)日:2023-08-15

    申请号:US17069693

    申请日:2020-10-13

    申请人: SPLUNK Inc.

    摘要: Embodiments of the present invention are directed to facilitating performing online data decomposition. In accordance with aspects of the present disclosure, an incoming data point of a time series data set is obtained. Thereafter, an iterative process of estimating trend and seasonality is performed to decompose the incoming data point to a set of data components based on a particular set of previous data points of the time series data set and corresponding data components. Generally, the set of data components for the incoming data point include a trend component, a seasonality component, and a residual component. The set of data components is provided for analysis of the incoming data point, such as, for example, to identify data anomalies.

    Low-latency streaming analytics
    86.
    发明授权

    公开(公告)号:US11727039B2

    公开(公告)日:2023-08-15

    申请号:US17811849

    申请日:2022-07-11

    申请人: Splunk Inc.

    摘要: Systems and methods are disclosed for implementing a low-latency data stream monitoring system. The data stream monitoring system may obtain raw data from a data source as soon after the data is generated, and may classify the data according to different topics. The topics may be published in a publish-subscribe messaging model, and data enrichment systems may subscribe to the topics to receive data for enrichment. The data enrichment systems may supplement or replace the raw data with additional information, and may further classify or reclassify the enriched data into different topics. The enriched data may then be published to an alert generation system, which may apply various criteria to the enriched data to determine that alerts should be generated, generate the alerts, and publish or transmit the alerts to client devices. Individual data streams, topics, enrichments, criteria, and alarms may be added, removed, or modified as required.

    DISTRIBUTED ALERT AND SUPPRESSION MANAGEMENT IN A CLUSTER COMPUTING SYSTEM

    公开(公告)号:US20230244660A1

    公开(公告)日:2023-08-03

    申请号:US17588079

    申请日:2022-01-28

    申请人: Splunk Inc.

    IPC分类号: G06F16/245

    CPC分类号: G06F16/245

    摘要: A first processing node of a cluster of processing nodes issues a first alert when first event data satisfies a trigger condition, and sends, to an alert data store external to the cluster, a first alert record of the first alert and suppression information based at least in part on the first alert. A second processing node of the cluster determines that second event data satisfies the trigger condition, obtains, from the alert data store, the suppression information indicating that an expiration time for suppressing the first alert is unexpired, and sends, to the alert data store, a second alert record of a second alert without issuing the second alert.