Data stream generation based on sourcetypes associated with messages

    公开(公告)号:US11853303B1

    公开(公告)日:2023-12-26

    申请号:US17411357

    申请日:2021-08-25

    Applicant: SPLUNK Inc.

    Abstract: As described herein, a portion of machine data of a message may be analyzed to infer, using an inference model, a sourcetype of the message. The portion of machine data may be generated by one or more components in an information technology environment. Based on the inference, a set of extraction rules associated with the sourcetype may be selected. Each extraction rule may define criteria for identifying a sub-portion of text from the portion of machine data of the message to produce a value. The set of extraction rules may be applied to the portion of machine data of the message to produce a result set that indicates a number of values identified using the set of extraction rules. Based on the result set, at least one action may be performed on one or more of inference data associated with the inference model and one or more messages.

    Feedback on inferred sourcetypes
    22.
    发明授权

    公开(公告)号:US11748358B2

    公开(公告)日:2023-09-05

    申请号:US16175642

    申请日:2018-10-30

    Applicant: Splunk, Inc.

    Abstract: As described herein, a portion of machine data of a message may be analyzed to infer, using an inference model, a sourcetype of the message. The portion of machine data may be generated by one or more components in an information technology environment. Based on the inference, a set of extraction rules associated with the sourcetype may be selected. Each extraction rule may define criteria for identifying a sub-portion of text from the portion of machine data of the message to produce a value. The set of extraction rules may be applied to the portion of machine data of the message to produce a result set that indicates a number of values identified using the set of extraction rules. Based on the result set, at least one action may be performed on one or more of inference data associated with the inference model and one or more messages.

    Distributed data processing for machine learning

    公开(公告)号:US10922625B2

    公开(公告)日:2021-02-16

    申请号:US15885395

    申请日:2018-01-31

    Applicant: Splunk Inc.

    Abstract: Embodiments of the present invention are directed to facilitating distributed data processing for machine learning. In accordance with aspects of the present disclosure, a set of commands in a query to process at an external computing service is identified. For each command in the set of commands, at least one compute unit including at least one operation to perform at the external computing service is identified. Each of the at least one compute unit associated with each command is analyzed to identify an optimized manner in which to execute the set of commands at the external computing service. An indication of the optimized manner in which to execute the set of commands and a corresponding set of data is provided to the external computing service to utilize for executing the set of commands at the external computing service.

    Metric forecasting interface with alert prediction

    公开(公告)号:US10726079B2

    公开(公告)日:2020-07-28

    申请号:US15884090

    申请日:2018-01-30

    Applicant: SPLUNK INC.

    Abstract: Operational machine components of an information technology (IT) or other microprocessor- or microcontroller-permeated environment generate disparate forms of machine data. Network connections are established between these components and processors of an automatic data intake and query system (DIQS). The DIQS conducts network transactions on a periodic and/or continuous basis with the machine components to receive the disparate data and ingest certain of the data as measurement entries of a DIQS metrics datastore that is searchable for DIQS query processing. The DIQS may receive search queries to process against the received and ingested data via an exposed network interface. In one example embodiment, a query building component conducts a user interface using a network attached client device. The query building component may elicit search criteria via the user interface using a natural language interface, construct a proper query therefrom, and present new information based on results returned from the DIQS.

    ANOMALY DETECTION BASED ON PREDICTED TEXTUAL CHARACTERS

    公开(公告)号:US20200090027A1

    公开(公告)日:2020-03-19

    申请号:US16692144

    申请日:2019-11-22

    Applicant: SPLUNK INC.

    Abstract: Described herein is a technology that facilitates the production of and the use of automated datagens for event-based systems. A datagen (i.e., data-generator or data generation system) is a component, module, or subsystem of computer systems that searches, monitors, and analyzes machine data. Existing datagens are not capable of detecting an anomaly in machine data. An anomaly is a variance in the input data stream that exceeds some acceptable amount of deviation from the norm (i.e., standard, expectation, etc.). An embodiment of datagen, in accordance with the technology described herein, detects anomalies in the input machine data.

Patent Agency Ranking