-
公开(公告)号:US11663212B2
公开(公告)日:2023-05-30
申请号:US17443811
申请日:2021-07-27
申请人: Splunk Inc.
发明人: Alexander Douglas James , Manu Jose , Sourav Pal , Christopher Madden Pride , Nicholas Robert Romito , Igor Braylovskiy , Arun Ramani , Ankit Jain
IPC分类号: G06F16/00 , G06F16/2453 , G06F16/242 , G06F16/9535 , G06F40/205 , G06F9/54
CPC分类号: G06F16/24542 , G06F16/2425 , G06F16/9535 , G06F40/205 , G06F9/547
摘要: Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system receives a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system parses the query and uses a metadata catalog to dynamically identify configuration parameters of datasets and/or rules associated with the query. The identified configuration parameters are communicated to a query processing component of the data intake and query system for use in executing the query.
-
公开(公告)号:US20220245093A1
公开(公告)日:2022-08-04
申请号:US17163047
申请日:2021-01-29
申请人: SPLUNK INC.
发明人: Alexandros Batsakis , Ankit Jain , Manu Jose , Jonah Pan , Hailun Yan
IPC分类号: G06F16/14 , G06F16/182
摘要: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, obtaining a search query from a user device. A determination may be made to execute a search, in association with the search query, via an external computing service. As such, the search query, or a variant thereof, can be provided to the external computing service, wherein the external computing service executes the search using data model summaries stored in a remote data store that is separate from a set of events from which the data model summaries were generated. A set of search results are received from the external computing service, and such search results are provided to the user device.
-
3.
公开(公告)号:US20210049150A1
公开(公告)日:2021-02-18
申请号:US17084965
申请日:2020-10-30
申请人: Splunk Inc.
发明人: Amritpal Singh Bath , Yuan Xu, Jr. , Bharath Aleti , Manu Jose
IPC分类号: G06F16/23 , G06F16/27 , G06F16/951 , G06F16/22 , G06F16/2458
摘要: The present disclosure provides solutions for determining the divergence (delta) between the current and previous reference data structures for mutable data in a search head. A method is provided that includes updating a pre-existing lookup table in a search head, generating a delta file that identifies the divergence between the updated and previous lookup table, and distributing the delta file to other components in the search environment. The compatibility of the delta file is checked with the local instance of the lookup table in each search component, and the lookup table is applied if compatibility is determined. However, if the delta file is determined to not be compatible with the current version of a local lookup table in an indexer, the entire lookup table sent to the requesting indexer instead.
-
公开(公告)号:US11892976B2
公开(公告)日:2024-02-06
申请号:US17163047
申请日:2021-01-29
申请人: SPLUNK INC.
发明人: Alexandros Batsakis , Ankit Jain , Manu Jose , Jonah Pan , Hailun Yan
IPC分类号: G06F16/00 , G06F16/14 , G06F16/182 , G06F16/738
CPC分类号: G06F16/144 , G06F16/156 , G06F16/1824 , G06F16/738
摘要: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, obtaining a search query from a user device. A determination may be made to execute a search, in association with the search query, via an external computing service. As such, the search query, or a variant thereof, can be provided to the external computing service, wherein the external computing service executes the search using data model summaries stored in a remote data store that is separate from a set of events from which the data model summaries were generated. A set of search results are received from the external computing service, and such search results are provided to the user device.
-
公开(公告)号:US20220156267A1
公开(公告)日:2022-05-19
申请号:US17586590
申请日:2022-01-27
申请人: Splunk Inc.
发明人: Alexander Douglas James , Scott Calvert , Manu Jose , Andrew Peters , Christopher Madden Pride , Arun Ramani
IPC分类号: G06F16/2457 , G06F16/907 , G06F16/2455 , G06F40/30
摘要: Systems and methods are disclosed for annotating a metadata catalog in a data intake and query system based on a query received by the data intake and query system. The metadata catalog can store information about datasets associated with the data intake and query system, including dataset configuration records of the datasets, which can be used to process queries for execution by the data intake and query system. The data intake and query system can receive a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system can parse the query to identify datasets and/or data fields associated with the query. Based on the identified datasets and/or fields, the data intake and query system can generate one or more annotations, and use the annotations to update the metadata catalog.
-
公开(公告)号:US11238049B1
公开(公告)日:2022-02-01
申请号:US16264019
申请日:2019-01-31
申请人: Splunk Inc.
发明人: Alexander Douglas James , Scott Calvert , Manu Jose , Andrew Peters , Christopher Madden Pride , Arun Ramani
IPC分类号: G06F16/00 , G06F16/2457 , G06F16/907 , G06F16/2455 , G06F40/30
摘要: Systems and methods are disclosed for annotating a metadata catalog in a data intake and query system based on a query received by the data intake and query system. The metadata catalog can store information about datasets associated with the data intake and query system, including dataset configuration records of the datasets, which can be used to process queries for execution by the data intake and query system. The data intake and query system can receive a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system can parse the query to identify datasets and/or data fields associated with the query. Based on the identified datasets and/or fields, the data intake and query system can generate one or more annotations, and use the annotations to update the metadata catalog.
-
公开(公告)号:US11093564B1
公开(公告)日:2021-08-17
申请号:US16147129
申请日:2018-09-28
申请人: Splunk Inc.
发明人: Alexander Douglas James , Manu Jose , Sourav Pal , Christopher Madden Pride , Nicholas Robert Romito , Igor Braylovskiy , Arun Ramani , Ankit Jain
IPC分类号: G06F16/00 , G06F16/9535 , G06F9/54 , G06F16/242 , G06F40/205
摘要: Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system receives a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system parses the query and uses a metadata catalog to dynamically identify configuration parameters of datasets and/or rules associated with the query. The identified configuration parameters are communicated to a query processing component of the data intake and query system for use in executing the query.
-
公开(公告)号:US20220245091A1
公开(公告)日:2022-08-04
申请号:US17163039
申请日:2021-01-29
申请人: SPLUNK INC.
发明人: Alexandros Batsakis , Ankit Jain , Manu Jose , Jonah Pan , Hailun Yan
IPC分类号: G06F16/13 , G06F16/182
摘要: Embodiments described herein facilitate enhancement of data model acceleration, including generating data model summaries and performing searches in an accelerated manner. In one implementation, a set of events are indexed, each of the events having a corresponding index time representing a time at which the event was indexed in an indexer. Index time parameters including an index earliest time indicating a first index time at which to begin generating a data model summary and an index latest time indicating a second index time at which to complete generating the data model summary are obtained. Thereafter, a data model summary is generated. Such a data model summary summarizes events having corresponding index times between the index earliest time and the index latest time. The data model summary is provided to a remote data store that is separate from the indexer at which at least a portion of the events were indexed.
-
公开(公告)号:US20210357470A1
公开(公告)日:2021-11-18
申请号:US17443811
申请日:2021-07-27
申请人: Splunk Inc.
发明人: Alexander Douglas James , Manu Jose , Sourav Pal , Christopher Madden Pride , Nicholas Robert Romito , Igor Braylovskiy , Arun Ramani , Ankit Jain
IPC分类号: G06F16/9535 , G06F9/54 , G06F16/242 , G06F40/205
摘要: Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system receives a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system parses the query and uses a metadata catalog to dynamically identify configuration parameters of datasets and/or rules associated with the query. The identified configuration parameters are communicated to a query processing component of the data intake and query system for use in executing the query.
-
公开(公告)号:US10891284B2
公开(公告)日:2021-01-12
申请号:US15582458
申请日:2017-04-28
申请人: SPLUNK INC.
发明人: Amritpal Singh Bath , Yuan Xu, Jr. , Bharath Aleti , Manu Jose
IPC分类号: G06F16/00 , G06F16/23 , G06F16/27 , G06F16/951 , G06F16/22 , G06F16/2458
摘要: The present disclosure provides solutions for determining the divergence (delta) between the current and previous reference data structures for mutable data in a search head. A method is provided that includes updating a pre-existing lookup table in a search head, generating a delta file that identifies the divergence between the updated and previous lookup table, and distributing the delta file to other components in the search environment. The compatibility of the delta file is checked with the local instance of the lookup table in each search component, and the lookup table is applied if compatibility is determined. However, if the delta file is determined to not be compatible with the current version of a local lookup table in an indexer, the entire lookup table sent to the requesting indexer instead.
-
-
-
-
-
-
-
-
-