ENHANCED SEARCH PERFORMANCE USING DATA MODEL SUMMARIES STORED IN A REMOTE DATA STORE

    公开(公告)号:US20220245093A1

    公开(公告)日:2022-08-04

    申请号:US17163047

    申请日:2021-01-29

    申请人: SPLUNK INC.

    IPC分类号: G06F16/14 G06F16/182

    摘要: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, obtaining a search query from a user device. A determination may be made to execute a search, in association with the search query, via an external computing service. As such, the search query, or a variant thereof, can be provided to the external computing service, wherein the external computing service executes the search using data model summaries stored in a remote data store that is separate from a set of events from which the data model summaries were generated. A set of search results are received from the external computing service, and such search results are provided to the user device.

    GENERATING AND DISTRIBUTING DELTA FILES ASSOCIATED WITH MUTABLE EVENTS IN A DISTRIBUTED SYSTEM

    公开(公告)号:US20210049150A1

    公开(公告)日:2021-02-18

    申请号:US17084965

    申请日:2020-10-30

    申请人: Splunk Inc.

    摘要: The present disclosure provides solutions for determining the divergence (delta) between the current and previous reference data structures for mutable data in a search head. A method is provided that includes updating a pre-existing lookup table in a search head, generating a delta file that identifies the divergence between the updated and previous lookup table, and distributing the delta file to other components in the search environment. The compatibility of the delta file is checked with the local instance of the lookup table in each search component, and the lookup table is applied if compatibility is determined. However, if the delta file is determined to not be compatible with the current version of a local lookup table in an indexer, the entire lookup table sent to the requesting indexer instead.

    REVISING CATALOG METADATA BASED ON PARSING QUERIES

    公开(公告)号:US20220156267A1

    公开(公告)日:2022-05-19

    申请号:US17586590

    申请日:2022-01-27

    申请人: Splunk Inc.

    摘要: Systems and methods are disclosed for annotating a metadata catalog in a data intake and query system based on a query received by the data intake and query system. The metadata catalog can store information about datasets associated with the data intake and query system, including dataset configuration records of the datasets, which can be used to process queries for execution by the data intake and query system. The data intake and query system can receive a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system can parse the query to identify datasets and/or data fields associated with the query. Based on the identified datasets and/or fields, the data intake and query system can generate one or more annotations, and use the annotations to update the metadata catalog.

    Revising catalog metadata based on parsing queries

    公开(公告)号:US11238049B1

    公开(公告)日:2022-02-01

    申请号:US16264019

    申请日:2019-01-31

    申请人: Splunk Inc.

    摘要: Systems and methods are disclosed for annotating a metadata catalog in a data intake and query system based on a query received by the data intake and query system. The metadata catalog can store information about datasets associated with the data intake and query system, including dataset configuration records of the datasets, which can be used to process queries for execution by the data intake and query system. The data intake and query system can receive a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system can parse the query to identify datasets and/or data fields associated with the query. Based on the identified datasets and/or fields, the data intake and query system can generate one or more annotations, and use the annotations to update the metadata catalog.

    FACILITATING GENERATION OF DATA MODEL SUMMARIES

    公开(公告)号:US20220245091A1

    公开(公告)日:2022-08-04

    申请号:US17163039

    申请日:2021-01-29

    申请人: SPLUNK INC.

    IPC分类号: G06F16/13 G06F16/182

    摘要: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, a set of events are indexed, each of the events having a corresponding index time representing a time at which the event was indexed in an indexer. Index time parameters including an index earliest time indicating a first index time at which to begin generating a data model summary and an index latest time indicating a second index time at which to complete generating the data model summary are obtained. Thereafter, a data model summary is generated. Such a data model summary summarizes events having corresponding index times between the index earliest time and the index latest time. The data model summary is provided to a remote data store that is separate from the indexer at which at least a portion of the events were indexed.

    Computing and replicating event deltas for mutable events in a distributed system

    公开(公告)号:US10891284B2

    公开(公告)日:2021-01-12

    申请号:US15582458

    申请日:2017-04-28

    申请人: SPLUNK INC.

    摘要: The present disclosure provides solutions for determining the divergence (delta) between the current and previous reference data structures for mutable data in a search head. A method is provided that includes updating a pre-existing lookup table in a search head, generating a delta file that identifies the divergence between the updated and previous lookup table, and distributing the delta file to other components in the search environment. The compatibility of the delta file is checked with the local instance of the lookup table in each search component, and the lookup table is applied if compatibility is determined. However, if the delta file is determined to not be compatible with the current version of a local lookup table in an indexer, the entire lookup table sent to the requesting indexer instead.