Facilitating generation of data model summaries

    公开(公告)号:US11841827B2

    公开(公告)日:2023-12-12

    申请号:US17163039

    申请日:2021-01-29

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/13 G06F16/1824

    Abstract: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, a set of events are indexed, each of the events having a corresponding index time representing a time at which the event was indexed in an indexer. Index time parameters including an index earliest time indicating a first index time at which to begin generating a data model summary and an index latest time indicating a second index time at which to complete generating the data model summary are obtained. Thereafter, a data model summary is generated. Such a data model summary summarizes events having corresponding index times between the index earliest time and the index latest time. The data model summary is provided to a remote data store that is separate from the indexer at which at least a portion of the events were indexed.

    ENHANCED SEARCH PERFORMANCE USING DATA MODEL SUMMARIES STORED IN A REMOTE DATA STORE

    公开(公告)号:US20220245093A1

    公开(公告)日:2022-08-04

    申请号:US17163047

    申请日:2021-01-29

    Applicant: SPLUNK INC.

    Abstract: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, obtaining a search query from a user device. A determination may be made to execute a search, in association with the search query, via an external computing service. As such, the search query, or a variant thereof, can be provided to the external computing service, wherein the external computing service executes the search using data model summaries stored in a remote data store that is separate from a set of events from which the data model summaries were generated. A set of search results are received from the external computing service, and such search results are provided to the user device.

    Query translation for an external data system

    公开(公告)号:US12141137B1

    公开(公告)日:2024-11-12

    申请号:US17816132

    申请日:2022-07-29

    Applicant: Splunk Inc.

    Abstract: A computing device can receive a query in a first query language that identifies a set of data to be processed and determine that at least a portion of the set of data resides in an external data system that uses a different query language. The query system can translate the query in the first query language in to a second query language for the external data system. In translating the query, the computing device may translate one or more time-based query commands into the second query language.

    FACILITATING GENERATION OF DATA MODEL SUMMARIES

    公开(公告)号:US20220245091A1

    公开(公告)日:2022-08-04

    申请号:US17163039

    申请日:2021-01-29

    Applicant: SPLUNK INC.

    Abstract: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, a set of events are indexed, each of the events having a corresponding index time representing a time at which the event was indexed in an indexer. Index time parameters including an index earliest time indicating a first index time at which to begin generating a data model summary and an index latest time indicating a second index time at which to complete generating the data model summary are obtained. Thereafter, a data model summary is generated. Such a data model summary summarizes events having corresponding index times between the index earliest time and the index latest time. The data model summary is provided to a remote data store that is separate from the indexer at which at least a portion of the events were indexed.

    EXTERNALLY DISTRIBUTED BUCKETS FOR EXECUTION OF QUERIES

    公开(公告)号:US20250028698A1

    公开(公告)日:2025-01-23

    申请号:US18414157

    申请日:2024-01-16

    Applicant: Splunk Inc.

    Abstract: A data intake and query system can manage the search of data stored at an external location relative to the data intake and query system using one or more indexers. The data intake and query system can receive data stored at the external location. The data intake and query system can process the data and generate an index using the one or more indexers. The data intake and query system can discard the data and store the index and a location identifier of the external location in one or more buckets. In response to a query, the data intake and query system can identify that at least a subset of the data is responsive to the query using the index and can obtain the at least the subset of the data from the external location using the location identifier.

Patent Agency Ranking