PROCESSING A SYSTEM SEARCH REQUEST INCLUDING EXTERNAL DATA SOURCES
    11.
    发明申请
    PROCESSING A SYSTEM SEARCH REQUEST INCLUDING EXTERNAL DATA SOURCES 有权
    处理包括外部数据源的系统搜索请求

    公开(公告)号:US20140344256A1

    公开(公告)日:2014-11-20

    申请号:US14449144

    申请日:2014-07-31

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

    PROCESSING A SYSTEM SEARCH REQUEST ACROSS DISPARATE DATA COLLECTION SYSTEMS
    12.
    发明申请
    PROCESSING A SYSTEM SEARCH REQUEST ACROSS DISPARATE DATA COLLECTION SYSTEMS 审中-公开
    处理不同数据收集系统的系统搜索请求

    公开(公告)号:US20140330815A1

    公开(公告)日:2014-11-06

    申请号:US14266832

    申请日:2014-05-01

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

    Processing a system search request by retrieving results from both a native index and a virtual index
    13.
    发明授权
    Processing a system search request by retrieving results from both a native index and a virtual index 有权
    通过从本机索引和虚拟索引检索结果来处理系统搜索请求

    公开(公告)号:US08738587B1

    公开(公告)日:2014-05-27

    申请号:US13951273

    申请日:2013-07-25

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

    Generating search queries based on query formats for disparate data collection systems

    公开(公告)号:US10860665B2

    公开(公告)日:2020-12-08

    申请号:US16032890

    申请日:2018-07-11

    Applicant: SPLUNK INC.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing realtime search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Processing a system search request across disparate data collection systems

    公开(公告)号:US10049160B2

    公开(公告)日:2018-08-14

    申请号:US14266832

    申请日:2014-05-01

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    COLLECTION QUERY DRIVEN GENERATION OF INVERTED INDEX FOR RAW MACHINE DATA

    公开(公告)号:US20170139996A1

    公开(公告)日:2017-05-18

    申请号:US15421236

    申请日:2017-01-31

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present disclosure provide a method for generating an inverted index in accordance with a user generated collection query. The method comprises providing a field searchable data store that comprises a plurality of event records, each event record comprising a time-stamped portion of raw machine data. The method further comprises receiving a collection query that references a field name. Further, responsive to the collection query, an inverted index is generated by: a) determining an extraction rule associated with the field name; b) extracting a field value corresponding to the field name from one or more event records in the field searchable data store using the extraction rule; and c) populating the inverted index responsive to each extracted field value, wherein each entry comprises the field name, the corresponding field value and a reference value that identifies a location in the field searchable data store where an associated event record is stored

    SEARCHING RAW DATA FROM AN EXTERNAL DATA SYSTEM USING A DUAL MODE SEARCH SYSTEM
    17.
    发明申请
    SEARCHING RAW DATA FROM AN EXTERNAL DATA SYSTEM USING A DUAL MODE SEARCH SYSTEM 有权
    使用双模式搜索系统从外部数据系统搜索RAW数据

    公开(公告)号:US20170046433A1

    公开(公告)日:2017-02-16

    申请号:US15339951

    申请日:2016-11-01

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

    Processing a system search request including external data sources and mixed modes
    18.
    发明授权
    Processing a system search request including external data sources and mixed modes 有权
    处理包括外部数据源和混合模式的系统搜索请求

    公开(公告)号:US08793225B1

    公开(公告)日:2014-07-29

    申请号:US13886692

    申请日:2013-05-03

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30545

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

    External Result Provided process for retrieving data stored using a different configuration or protocol
    19.
    发明授权
    External Result Provided process for retrieving data stored using a different configuration or protocol 有权
    外部结果提供使用不同配置或协议存储的数据的进程

    公开(公告)号:US08738629B1

    公开(公告)日:2014-05-27

    申请号:US13886737

    申请日:2013-05-03

    Applicant: Splunk Inc.

    Abstract: A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

    Abstract translation: 通过分析所接收的搜索请求来识别在搜索支持系统的计算机处接收的搜索请求,以识别请求参数并连接到在请求参数中引用的搜索支持系统的系统索引。 启动外部结果提供程序(ERP)进程,在搜索支持系统和搜索支持系统外部的数据源之间建立通信,为请求参数中引用的虚拟索引。 因此,ERP过程提供了搜索支持系统和外部数据源之间的接口,如第三方。 ERP流程可以以流模式运行(以最少的处理提供实时搜索结果)和/或报告模式(提供更大的延迟和处理范围的结果),并且可以在模式之间切换。 从连接的系统索引和引用的虚拟索引接收搜索请求结果。

Patent Agency Ranking