Graphically Selectable Filter Parameters for Field Data in a Set of Machine Data
    1.
    发明申请
    Graphically Selectable Filter Parameters for Field Data in a Set of Machine Data 审中-公开
    一组机器数据中的场数据的图形可选滤波器参数

    公开(公告)号:US20160321369A1

    公开(公告)日:2016-11-03

    申请号:US15143579

    申请日:2016-04-30

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

    Search result replication management in a search head cluster

    公开(公告)号:US11704341B2

    公开(公告)日:2023-07-18

    申请号:US16159893

    申请日:2018-10-15

    Applicant: Splunk Inc.

    CPC classification number: G06F16/285 G06F16/27 G06F16/951

    Abstract: Systems and methods for search result replication in a search head cluster of a data aggregation and analysis system. An example method may comprise maintaining a replication count in a data store associated with at least one of the plurality of search heads, the replication count corresponding to how many of the replicas of the search result are stored in the search head cluster, determining that the replication count is greater than a target replication count, based on determining that the replication count is greater than the target replication count, initiating a deletion of at least one replica of the replicas of the search result from a target search head of the plurality of search heads storing the replicas, receiving an indication that the deletion is complete, and based on receiving the indication that the deletion is complete, decreasing the replication count corresponding to the search result.

    Generating Reports from Unstructured Data
    5.
    发明申请
    Generating Reports from Unstructured Data 审中-公开
    从非结构化数据生成报告

    公开(公告)号:US20150019537A1

    公开(公告)日:2015-01-15

    申请号:US14503335

    申请日:2014-09-30

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

    Replication of summary data in a clustered computing environment

    公开(公告)号:US10387448B2

    公开(公告)日:2019-08-20

    申请号:US14929089

    申请日:2015-10-30

    Applicant: Splunk Inc.

    Abstract: Techniques and mechanisms are disclosed to increase the availability of summary data within a clustered data intake and query system by replicating the summary data within the cluster. In general, summary data may store “pre-computed” results for one or more search queries and can be used by indexers of a cluster to process subsequent instances of the same search queries. At a high level, replication of summary data within a cluster may include ensuring that each instance of summary data created by an indexer of a cluster is replicated to other indexers within the cluster that store copies of the same grouped subset(s) of data to which the summary data relates. In this manner, if one or more indexers of an indexer cluster fail, other indexers of the cluster can make immediate use of replicated copies of the summary data without re-creating it.

    Graphical Display of Event Data Using Pull-Down Menus
    10.
    发明申请
    Graphical Display of Event Data Using Pull-Down Menus 审中-公开
    使用下拉菜单图形显示事件数据

    公开(公告)号:US20160140743A1

    公开(公告)日:2016-05-19

    申请号:US15007180

    申请日:2016-01-26

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

Patent Agency Ranking