-
公开(公告)号:US11726990B2
公开(公告)日:2023-08-15
申请号:US17451300
申请日:2021-10-18
Applicant: Splunk Inc.
Inventor: Akash Dwivedi , Himanshu Gupta , Eric Tschetter
IPC: G06F16/23 , G06F16/248 , G06F9/54 , G06F16/2458 , G06F16/25 , G06F16/22
CPC classification number: G06F16/2379 , G06F9/54 , G06F16/221 , G06F16/248 , G06F16/2477 , G06F16/258
Abstract: Systems and methods are disclosed for efficiently storing information identifying journey instances within unstructured event data of a data intake and processing system. Each journey instance is illustratively associated with a series of events within the unstructured event data occurring over a journey duration. Because the unstructured event data may be constantly updated, any given inspection of the event data may yield both complete and incomplete instances. Storage of instance data over time can require updating of prior incomplete journey instances with complete versions of such instance detected at a later point in time. However, a data store of the unstructured event data may be unsuited for such updating, as the store may maintain version information for deleted data to reduce possibility of data loss. To address this issue, a separate structured data store, such as a columnar time series data store, is provided to efficiently store instance information.
-
公开(公告)号:US11151125B1
公开(公告)日:2021-10-19
申请号:US16735520
申请日:2020-01-06
Applicant: Splunk Inc.
Inventor: Akash Dwivedi , Himanshu Gupta , Eric Tschetter
IPC: G06F16/23 , G06F16/248 , G06F9/54 , G06F16/2458 , G06F16/25 , G06F16/22
Abstract: Systems and methods are disclosed for efficiently storing information identifying journey instances within unstructured event data of a data intake and processing system. Each journey instance is illustratively associated with a series of events within the unstructured event data occurring over a journey duration. Because the unstructured event data may be constantly updated, any given inspection of the event data may yield both complete and incomplete instances. Storage of instance data over time can require updating of prior incomplete journey instances with complete versions of such instance detected at a later point in time. However, a data store of the unstructured event data may be unsuited for such updating, as the store may maintain version information for deleted data to reduce possibility of data loss. To address this issue, a separate structured data store, such as a columnar time series data store, is provided to efficiently store instance information.
-
公开(公告)号:US11741131B1
公开(公告)日:2023-08-29
申请号:US17162300
申请日:2021-01-29
Applicant: Splunk Inc.
Inventor: Akash Dwivedi , Himanshu Gupta , Eric Tschetter , Rahul Gidwani
IPC: G06F16/22 , G06F16/248 , G06F16/28 , G06F16/2455
CPC classification number: G06F16/287 , G06F16/22 , G06F16/248 , G06F16/24553 , G06F16/288
Abstract: Systems and methods are disclosed for efficiently uploading event data of a data intake and processing system and building journey instances using the uploaded event data in a distributed manner. Each journey instance is illustratively associated with a series of events within the event data occurring over a journey duration. For example, a cloud-based hosting system can implement a cloud-based distributed system that receives fragmented uploads of event data from the data intake and query system. Once received, the cloud-based hosting system can combine the event data from one or more uploads and re-stitch portions of the uploaded event data using a set of worker nodes to build journey instances.
-
-