Optimizing search of an accelerated data model by enabling emitting of structured and unstructured fields from the data model

    公开(公告)号:US11429608B2

    公开(公告)日:2022-08-30

    申请号:US16527719

    申请日:2019-07-31

    Applicant: Splunk Inc.

    Abstract: Embodiments of the present disclosure provide techniques for emitting structured and dynamic fields from an accelerated data model. The method comprises evaluating a query to search a data model, wherein the data model is defined by a set of events and at least one structured field from fields associated with the set of events. Each event comprises a time-stamped portion of raw machine data and is stored in a field searchable data store. A summarization table is associated with the data model and comprises a plurality of entries comprising reference values, wherein a respective summarization table entry comprises: the at least one structured field; a respective field value; and a reference value. The method further comprises accessing the set of events from the field searchable data store using the reference values in the summarization table and annotating the set of events with the at least one structured field and with at least one dynamic field from the fields associated with the set of events, wherein the at least one dynamic field is not defined in the data model.

    OPTIMIZING SEARCH OF AN ACCELERATED DATA MODEL BY ENABLING EMITTING OF STRUCTURED AND UNSTRUCTURED FIELDS FROM THE DATA MODEL

    公开(公告)号:US20210034623A1

    公开(公告)日:2021-02-04

    申请号:US16527719

    申请日:2019-07-31

    Applicant: Splunk Inc.

    Abstract: Embodiments of the present disclosure provide techniques for emitting structured and dynamic fields from an accelerated data model. The method comprises evaluating a query to search a data model, wherein the data model is defined by a set of events and at least one structured field from fields associated with the set of events. Each event comprises a time-stamped portion of raw machine data and is stored in a field searchable data store. A summarization table is associated with the data model and comprises a plurality of entries comprising reference values, wherein a respective summarization table entry comprises: the at least one structured field; a respective field value; and a reference value. The method further comprises accessing the set of events from the field searchable data store using the reference values in the summarization table and annotating the set of events with the at least one structured field and with at least one dynamic field from the fields associated with the set of events, wherein the at least one dynamic field is not defined in the data model.

Patent Agency Ranking