-
公开(公告)号:US20170220685A1
公开(公告)日:2017-08-03
申请号:US15011361
申请日:2016-01-29
Applicant: Splunk Inc.
Inventor: Hailun Yan , Ledion Bitincka , Kishore Reddy Ramasayam , Elizabeth Lin , David Ryan Marquardt
IPC: G06F17/30
Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.
-
公开(公告)号:US11416505B2
公开(公告)日:2022-08-16
申请号:US17080067
申请日:2020-10-26
Applicant: SPLUNK Inc.
Inventor: Elizabeth Lin , Nils Petter Eriksson , Ledion Bitincka
IPC: G06F16/30 , G06F16/2458
Abstract: In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.
-
公开(公告)号:US20180157719A1
公开(公告)日:2018-06-07
申请号:US15885521
申请日:2018-01-31
Applicant: SPLUNK INC.
Inventor: Elizabeth Lin , Nils Petter Eriksson , Ledion Bitincka
IPC: G06F17/30
CPC classification number: G06F16/2471
Abstract: In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.
-
公开(公告)号:US10956362B1
公开(公告)日:2021-03-23
申请号:US16177358
申请日:2018-10-31
Applicant: SPLUNK INC.
Inventor: Clint Sharp , Petter Eriksson , Ledion Bitincka , Jason Szeto , Elizabeth Lin , Nima Haddadkaveh
Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.
-
公开(公告)号:US20210042306A1
公开(公告)日:2021-02-11
申请号:US17080067
申请日:2020-10-26
Applicant: SPLUNK Inc.
Inventor: Elizabeth Lin , Nils Petter Eriksson , Ledion Bitincka
IPC: G06F16/2458
Abstract: In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.
-
公开(公告)号:US20200334309A1
公开(公告)日:2020-10-22
申请号:US16900628
申请日:2020-06-12
Applicant: SPLUNK INC.
Inventor: Hailun Yan , Ledion Bitincka , Kishore Reddy Ramasayam , Elizabeth Lin , David Ryan Marquardt
IPC: G06F16/9535 , G06F16/28 , G06F16/2455
Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.
-
公开(公告)号:US10152480B2
公开(公告)日:2018-12-11
申请号:US14611225
申请日:2015-01-31
Applicant: Splunk Inc.
Inventor: Clint Sharp , Petter Eriksson , Ledion Bitincka , Jason Szeto , Elizabeth Lin , Nima Haddadkaveh
IPC: G06F17/30
Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.
-
公开(公告)号:US20160224570A1
公开(公告)日:2016-08-04
申请号:US14611225
申请日:2015-01-31
Applicant: Splunk Inc.
Inventor: Clint Sharp , Petter Eriksson , Ledion Bitincka , Jason Szeto , Elizabeth Lin , Nima Haddadkaveh
IPC: G06F17/30
CPC classification number: G06F17/30073 , G06F17/30336 , G06F17/30427
Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.
Abstract translation: 分布式服务器中的原始数据被划分为称为存储桶的数据组,其中包含具有落在特定时间范围内的时间戳的原始数据。 当桶变为不活动时,服务器可以将存储桶存储到外部存储系统。 可以在搜索查询中指定包含归档数据的外部存储系统。 获取,处理来自外部存储系统的存档数据,并使用搜索查询对已处理归档数据执行搜索。
-
公开(公告)号:US11144608B2
公开(公告)日:2021-10-12
申请号:US16900628
申请日:2020-06-12
Applicant: SPLUNK INC.
Inventor: Hailun Yan , Ledion Bitincka , Kishore Reddy Ramasayam , Elizabeth Lin , David Ryan Marquardt
IPC: G06F16/9535 , G06F16/28 , G06F16/2455
Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.
-
公开(公告)号:US10860596B2
公开(公告)日:2020-12-08
申请号:US15885521
申请日:2018-01-31
Applicant: SPLUNK INC.
Inventor: Elizabeth Lin , Nils Petter Eriksson , Ledion Bitincka
IPC: G06F16/30 , G06F16/2458
Abstract: In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.
-
-
-
-
-
-
-
-
-