EXTERNALLY DISTRIBUTED BUCKETS FOR EXECUTION OF QUERIES

    公开(公告)号:US20250028698A1

    公开(公告)日:2025-01-23

    申请号:US18414157

    申请日:2024-01-16

    Applicant: Splunk Inc.

    Abstract: A data intake and query system can manage the search of data stored at an external location relative to the data intake and query system using one or more indexers. The data intake and query system can receive data stored at the external location. The data intake and query system can process the data and generate an index using the one or more indexers. The data intake and query system can discard the data and store the index and a location identifier of the external location in one or more buckets. In response to a query, the data intake and query system can identify that at least a subset of the data is responsive to the query using the index and can obtain the at least the subset of the data from the external location using the location identifier.

    QUERY EXECUTION USING A DATA PROCESSING SCHEME OF A SEPARATE DATA PROCESSING SYSTEM

    公开(公告)号:US20250028714A1

    公开(公告)日:2025-01-23

    申请号:US18428405

    申请日:2024-01-31

    Applicant: Splunk Inc.

    Abstract: A query coordinator can receive a query. The query coordinator can determine one or more data semantics of a first data processing system. The data semantics of the first data processing system may be based on execution of one or more queries by the first data processing system. The query coordinator can define a query processing scheme for obtaining and processing data based on the query. The query processing scheme may include instructions for a second data processing system to execute at least a portion of the query according to the data semantics of the first data processing system. The query coordinator can provide the query processing scheme to the second data processing system and obtain query results from the second data processing system.

    MANAGEMENT OF DISTRIBUTED COMPUTING FRAMEWORK COMPONENTS IN A DATA FABRIC SERVICE SYSTEM

    公开(公告)号:US20210117425A1

    公开(公告)日:2021-04-22

    申请号:US16657899

    申请日:2019-10-18

    Applicant: Splunk Inc.

    Abstract: Systems and methods are described for establishing and managing components of a distributed computing framework implemented in a data intake and query system. The distributed computing framework may include a master and a plurality of worker nodes. The master may selectively operate on a search head captain that is chosen from the search heads of the data intake and query system. The search head captain may distribute configuration information for the master and the distributed computing framework to the other search heads, which in turn, may distribute that configuration information to indexers of the data intake and query system. Worker nodes may be selectively activated for operation on the indexers based on the configuration information, and the worker nodes may additionally use the configuration information to contact the master and join the distributed computing framework. This approach may provide numerous benefits, including improved security, flexibility in the selection of worker nodes, and redundancy for failures of physical components of the data intake and query system.

Patent Agency Ranking