FACILITATING DATA MODEL ACCELERATION IN ASSOCIATION WITH AN EXTERNAL DATA SYSTEM

    公开(公告)号:US20170220685A1

    公开(公告)日:2017-08-03

    申请号:US15011361

    申请日:2016-01-29

    Applicant: Splunk Inc.

    Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.

    Querying an archive for a data store

    公开(公告)号:US11416505B2

    公开(公告)日:2022-08-16

    申请号:US17080067

    申请日:2020-10-26

    Applicant: SPLUNK Inc.

    Abstract: In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.

    EMPLOYING EXTERNAL DATA STORES TO SERVICE DATA REQUESTS

    公开(公告)号:US20180157719A1

    公开(公告)日:2018-06-07

    申请号:US15885521

    申请日:2018-01-31

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/2471

    Abstract: In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.

    Searching archived data
    4.
    发明授权

    公开(公告)号:US10956362B1

    公开(公告)日:2021-03-23

    申请号:US16177358

    申请日:2018-10-31

    Applicant: SPLUNK INC.

    Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.

    QUERYING AN ARCHIVE FOR A DATA STORE

    公开(公告)号:US20210042306A1

    公开(公告)日:2021-02-11

    申请号:US17080067

    申请日:2020-10-26

    Applicant: SPLUNK Inc.

    Abstract: In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.

    TRIGGERING GENERATION OF AN ACCELERATED DATA MODEL SUMMARY FOR A DATA MODEL

    公开(公告)号:US20200334309A1

    公开(公告)日:2020-10-22

    申请号:US16900628

    申请日:2020-06-12

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.

    Archiving indexed data
    7.
    发明授权

    公开(公告)号:US10152480B2

    公开(公告)日:2018-12-11

    申请号:US14611225

    申请日:2015-01-31

    Applicant: Splunk Inc.

    Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.

    ARCHIVING INDEXED DATA
    8.
    发明申请
    ARCHIVING INDEXED DATA 审中-公开
    归档索引数据

    公开(公告)号:US20160224570A1

    公开(公告)日:2016-08-04

    申请号:US14611225

    申请日:2015-01-31

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30073 G06F17/30336 G06F17/30427

    Abstract: Raw data in distributed servers is divided into groups of data called buckets containing raw data that have timestamps that fall within a specific time range. When a bucket becomes inactive a server can archive the bucket to an external storage system. The external storage system containing archived data may be specified in a search query. Archived data from the external storage system is obtained, processed, and a search performed on the processed archived data using the search query.

    Abstract translation: 分布式服务器中的原始数据被划分为称为存储桶的数据组,其中包含具有落在特定时间范围内的时间戳的原始数据。 当桶变为不活动时,服务器可以将存储桶存储到外部存储系统。 可以在搜索查询中指定包含归档数据的外部存储系统。 获取,处理来自外部存储系统的存档数据,并使用搜索查询对已处理归档数据执行搜索。

    Triggering generation of an accelerated data model summary for a data model

    公开(公告)号:US11144608B2

    公开(公告)日:2021-10-12

    申请号:US16900628

    申请日:2020-06-12

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present invention are directed to facilitating data model acceleration in association with an external data system. In accordance with aspects of the present disclosure, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields, that are of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.

    Employing external data stores to service data requests

    公开(公告)号:US10860596B2

    公开(公告)日:2020-12-08

    申请号:US15885521

    申请日:2018-01-31

    Applicant: SPLUNK INC.

    Abstract: In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.

Patent Agency Ranking