PARALLELIZATION OF COLLECTION QUERIES
    52.
    发明申请

    公开(公告)号:US20190332590A1

    公开(公告)日:2019-10-31

    申请号:US16451450

    申请日:2019-06-25

    Applicant: SPLUNK INC.

    Abstract: Embodiments are directed are towards the parallelization of collection queries. A method of parallelizing collection queries comprises providing a field searchable data store comprising a plurality of field searchable time stamped event records. The method further comprises receiving, at a search head, a collection query that references a field name that identifies portions of one or more event records to be summarized. Further, the method comprises determining if the collection query can be concurrently executed on a first plurality of indexers, wherein the search head is configured to communicate with the first plurality of indexers, and wherein each indexer of the first plurality of indexers comprises one or more field searchable time stamped event records. Responsive to an affirmative determination, the method also comprises determining a second plurality of indexers relevant to the collection query and executing the collection query to generate a respective summarization table at each indexer.

    Collection query driven generation of summarization information for raw machine data

    公开(公告)号:US10387396B2

    公开(公告)日:2019-08-20

    申请号:US15705875

    申请日:2017-09-15

    Applicant: SPLUNK INC.

    Abstract: Embodiments are directed are towards the transparent summarization of events. Queries directed towards summarizing and reporting on event records may be received at a search head. Search heads may be associated with one more indexers containing event records. The search head may forward the query to the indexers the can resolve the query for concurrent execution. If a query is a collection query, indexers may generate summarization information based on event records located on the indexers. Event record fields included in the summarization information may be determined based on terms included in the collection query. If a query is a stats query, each indexer may generate a partial result set from previously generated summarization information, returning the partial result sets to the search head. Collection queries may be saved and scheduled to run and periodically update the summarization information.

    Generating and storing summarization tables for sets of searchable events

    公开(公告)号:US09990386B2

    公开(公告)日:2018-06-05

    申请号:US14815973

    申请日:2015-08-01

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed are towards the transparent summarization of events. Queries directed towards summarizing and reporting on event records may be received at a search head. Search heads may be associated with one more indexers containing event records. The search head may forward the query to the indexers the can resolve the query for concurrent execution. If a query is a collection query, indexers may generate summarization information based on event records located on the indexers. Event record fields included in the summarization information may be determined based on terms included in the collection query. If a query is a stats query, each indexer may generate a partial result set from previously generated summarization information, returning the partial result sets to the search head. Collection queries may be saved and scheduled to run and periodically update the summarization information.

    Generating and Storing Summarization Tables for Sets of Searchable Events
    58.
    发明申请
    Generating and Storing Summarization Tables for Sets of Searchable Events 有权
    生成和存储可搜索事件集合的汇总表

    公开(公告)号:US20160004750A1

    公开(公告)日:2016-01-07

    申请号:US14815973

    申请日:2015-08-01

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed are towards the transparent summarization of events. Queries directed towards summarizing and reporting on event records may be received at a search head. Search heads may be associated with one more indexers containing event records. The search head may forward the query to the indexers the can resolve the query for concurrent execution. If a query is a collection query, indexers may generate summarization information based on event records located on the indexers. Event record fields included in the summarization information may be determined based on terms included in the collection query. If a query is a stats query, each indexer may generate a partial result set from previously generated summarization information, returning the partial result sets to the search head. Collection queries may be saved and scheduled to run and periodically update the summarization information.

    Abstract translation: 实施例针对事件的透明总结。 可以在搜索头收到针对事件记录的总结和报告的查询。 搜索头可能与一个包含事件记录的索引器相关联。 搜索头可以将查询转发给索引器,可以解析用于并发执行的查询。 如果查询是集合查询,则索引器可以基于位于索引器上的事件记录生成摘要信息。 包含在汇总信息中的事件记录字段可以基于收集查询中包含的项来确定。 如果查询是统计查询,则每个索引器可以从先前生成的摘要信息生成部分结果集,将部分结果集返回到搜索头。 收集查询可以保存并计划运行,并定期更新摘要信息。

    Supplementing a high performance analytics store with evaluation of individual events to respond to an event query
    59.
    发明授权
    Supplementing a high performance analytics store with evaluation of individual events to respond to an event query 有权
    补充高性能分析商店,评估各种事件以响应事件查询

    公开(公告)号:US09128985B2

    公开(公告)日:2015-09-08

    申请号:US14170159

    申请日:2014-01-31

    Applicant: SPLUNK INC.

    Abstract: Embodiments are directed are towards the transparent summarization of events. Queries directed towards summarizing and reporting on event records may be received at a search head. Search heads may be associated with one more indexers containing event records. The search head may forward the query to the indexers the can resolve the query for concurrent execution. If a query is a collection query, indexers may generate summarization information based on event records located on the indexers. Event record fields included in the summarization information may be determined based on terms included in the collection query. If a query is a stats query, each indexer may generate a partial result set from previously generated summarization information, returning the partial result sets to the search head. Collection queries may be saved and scheduled to run and periodically update the summarization information.

    Abstract translation: 实施例针对事件的透明总结。 可以在搜索头收到针对事件记录的总结和报告的查询。 搜索头可能与一个包含事件记录的索引器相关联。 搜索头可以将查询转发给索引器,可以解析用于并发执行的查询。 如果查询是集合查询,则索引器可以基于位于索引器上的事件记录生成摘要信息。 包含在汇总信息中的事件记录字段可以基于收集查询中包含的项来确定。 如果查询是统计查询,则每个索引器可以从先前生成的摘要信息生成部分结果集,将部分结果集返回到搜索头。 收集查询可以保存并计划运行,并定期更新摘要信息。

    FLEXIBLE SCHEMA COLUMN STORE
    60.
    发明申请
    FLEXIBLE SCHEMA COLUMN STORE 有权
    灵活的样板柱

    公开(公告)号:US20130311438A1

    公开(公告)日:2013-11-21

    申请号:US13662984

    申请日:2012-10-29

    Applicant: SPLUNK INC.

    Abstract: Embodiments are directed towards receiving and processing search queries directed towards relatively large sets of data. The data is stored in a record based datastore. From the stored data, field names, corresponding field values, and posting values may be determined. Posting values may be employed to locate records in the datastore that include the field names and field values. The field names, field values, and posting values may be employed to generate a lexicon. If queries are received, a lexicon query processor may employ the lexicon separate from the datastore to generate responses to the received queries. Queries may include clauses that may be processed using the lexicon separate from the datastore, such as, where clause expressions, group-by clause expressions, aggregation functions, or the like. A time values array may be used to enable queries to process group-by-time expressions that may return results grouped into sub-sets based on time ranges.

    Abstract translation: 实施例旨在接收和处理针对相对大的数据集的搜索查询。 数据存储在基于记录的数据存储中。 从存储的数据可以确定字段名称,对应的字段值和过帐值。 可以使用发布值来定位数据存储中包含字段名称和字段值的记录。 可以使用字段名称,字段值和发布值来生成词典。 如果接收到查询,则词典查询处理器可以使用与数据存储区分开的词典来生成对所接收的查询的响应。 查询可以包括可以使用从数据存储区分开的词典来处理的子句,例如where子句表达式,分组子句表达式,聚合函数等。 时间值数组可用于使查询能够处理按时间范围分组成子集的结果的逐个逐句表达式。

Patent Agency Ranking