-
公开(公告)号:US11663244B2
公开(公告)日:2023-05-30
申请号:US17448196
申请日:2021-09-20
Applicant: Splunk Inc.
Inventor: Michael Joseph Baum , R. David Carasso , Robin Kumar Das , Bradley Hall , Brian Philip Murphy , Stephen Phillip Sorkin , Andre David Stechert , Erik M. Swan , Rory Greene , Nicholas Christian Mealy , Christina Frances Regina Noren
CPC classification number: G06F16/285 , G06F9/54 , G06F9/541 , G06F9/542
Abstract: Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.
-
公开(公告)号:US11561952B2
公开(公告)日:2023-01-24
申请号:US17125807
申请日:2020-12-17
Applicant: Splunk Inc.
Inventor: Michael Joseph Baum , R. David Carasso , Robin Kumar Das , Rory Greene , Bradley Hall , Nicholas Christian Mealy , Brian Philip Murphy , Stephen Phillip Sorkin , Andre David Stechert , Erik M. Swan
IPC: G06F16/00 , G06F16/22 , G06F16/248 , G06F16/951 , G06F16/23 , G06F16/2458 , G06F16/2455 , G06F16/2457
Abstract: Methods and apparatus consistent with the invention provide the ability to organize, index, search, and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is stored as discrete events time stamps. A search is received and relevant event information is retrieved based in whole or in part on the time stamp, a keyword indexing mechanism, or statistical indices calculated at the time of the search.
-
公开(公告)号:US11537585B2
公开(公告)日:2022-12-27
申请号:US17243966
申请日:2021-04-29
Applicant: Splunk Inc.
Inventor: Michael Joseph Baum , R. David Carasso , Robin Kumar Das , Rory Greene , Bradley Hall , Nicholas Christian Mealy , Brian Philip Murphy , Stephen Phillip Sorkin , Andre David Stechert , Erik M. Swan
IPC: G06F16/00 , G06F16/22 , G06F16/248 , G06F16/951 , G06F16/23 , G06F16/2458 , G06F16/2455 , G06F16/2457
Abstract: Methods and apparatus consistent with the invention provide the ability to organize, index, search, and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is stored as discrete events time stamps. A search is received and relevant event information is retrieved based in whole or in part on the time stamp, a keyword indexing mechanism, or statistical indices calculated at the time of the search.
-
公开(公告)号:US20210248123A1
公开(公告)日:2021-08-12
申请号:US17243967
申请日:2021-04-29
Applicant: Splunk Inc.
Inventor: Michael Joseph Baum , R. David Carasso , Robin Kumar Das , Rory Greene , Bradley Hall , Nicholas Christian Mealy , Brian Philip Murphy , Stephen Phillip Sorkin , Andre David Stechert , Erik M. Swan
IPC: G06F16/22 , G06F16/23 , G06F16/2457 , G06F16/951 , G06F16/2458 , G06F16/2455 , G06F16/248
Abstract: Methods and apparatus consistent with the invention provide the ability to organize, index, search, and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is stored as discrete events time stamps. A search is received and relevant event information is retrieved based in whole or in part on the time stamp, a keyword indexing mechanism, or statistical indices calculated at the time of the search.
-
公开(公告)号:US11030229B2
公开(公告)日:2021-06-08
申请号:US15582670
申请日:2017-04-29
Applicant: SPLUNK INC.
Inventor: R. David Carasso , Micah James Delfino , Johnvey Hwang
IPC: G06F7/00 , G06F16/34 , G06F16/242 , G06F16/2458 , G06F40/40 , G06F40/166 , G06F40/174 , G06F3/0484 , H04L29/08
Abstract: Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.
-
公开(公告)号:US11010214B2
公开(公告)日:2021-05-18
申请号:US16264638
申请日:2019-01-31
Applicant: Splunk Inc.
Inventor: Michael Joseph Baum , R. David Carasso , Robin Kumar Das , Bradley Hall , Brian Philip Murphy , Stephen Phillip Sorkin , Andre David Stechert , Erik M. Swan , Rory Greene , Nicholas Christian Mealy , Christina Frances Regina Noren
IPC: G06F9/54
Abstract: Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.
-
公开(公告)号:US20210004205A1
公开(公告)日:2021-01-07
申请号:US17028755
申请日:2020-09-22
Applicant: SPLUNK INC.
Inventor: R. David Carasso , Micah James Delfino , Johnvey Hwang
IPC: G06F7/24 , G06F16/2458
Abstract: Embodiments are directed towards real time display of event records with an indication of previously provided extraction rules. A plurality of extraction rules may be provided to the system, such as automatically generated and/or user created extraction rules. These extraction rules may include regular expressions. A plurality of event records may be displayed to the user, such that text in a field defined by an extraction rule is emphasized in the display of the event record. The same emphasis may be provided for text in overlapping fields, or the emphasis may be somewhat different for different fields. The user interface may enable a user to select a portion of text of an event record, such as by rolling-over or clicking on an emphasized part of the event record. By selecting the portion of the event record, the interface may display each extraction rule associated with the selected portion.
-
公开(公告)号:US10831804B2
公开(公告)日:2020-11-10
申请号:US15582671
申请日:2017-04-29
Applicant: SPLUNK, Inc.
Inventor: R. David Carasso , Micah James Delfino , Johnvey Hwang
IPC: G06F16/34 , G06F16/242 , G06F16/2458 , G06F3/0484 , H04L29/08 , G06F40/40 , G06F40/166 , G06F40/174 , G06F17/24 , G06F17/28
Abstract: Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.
-
公开(公告)号:US20200159741A1
公开(公告)日:2020-05-21
申请号:US16751063
申请日:2020-01-23
Applicant: SPLUNK INC.
Inventor: R. David Carasso , Micah James Delfino
IPC: G06F16/25 , G06F16/28 , G06F3/0482 , G06F7/24 , G06F16/904
Abstract: Embodiments are directed towards generating a representative sampling as a subset from a larger dataset that includes unstructured data. A graphical user interface enables a user to provide various data selection parameters, including specifying a data source and one or more subset types desired, including one or more of latest records, earliest records, diverse records, outlier records, and/or random records. Diverse and/or outlier subset types may be obtained by generating clusters from an initial selection of records obtained from the larger dataset. An iteration analysis is performed to determine whether a sufficient number of clusters and/or cluster types have been generated that exceed at least one threshold and when not exceeded, additional clustering is performed on additional records. From the resultant clusters, and/or other subtype results, a subset of records is obtained as the representative sampling subset.
-
公开(公告)号:US20190251099A1
公开(公告)日:2019-08-15
申请号:US16398104
申请日:2019-04-29
Applicant: Splunk Inc.
Inventor: Michael Joseph Baum , R. David Carasso , Robin Kumar Das , Bradley Hall , Brian Philip Murphy , Stephen Phillip Sorkin , Andre David Stechert , Erik M. Swan , Rory Greene , Nicholas Christian Mealy , Christina Frances Regina Noren
IPC: G06F16/28 , G06F16/2457 , G06K9/62 , G06F17/27 , G06F16/2455 , G06F16/2458 , G06F16/23 , G06F16/31 , G06F16/35 , H04L29/06
CPC classification number: G06F16/285 , G06F11/3476 , G06F16/2358 , G06F16/2455 , G06F16/24564 , G06F16/24573 , G06F16/2477 , G06F16/288 , G06F16/316 , G06F16/3331 , G06F16/35 , G06F17/2785 , G06F2216/03 , G06K9/6217 , H04L63/1425 , H04L63/20
Abstract: Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.
-
-
-
-
-
-
-
-
-