DYNAMIC RESOLUTION ESTIMATION FOR A DETECTOR

    公开(公告)号:US20240346049A1

    公开(公告)日:2024-10-17

    申请号:US18666603

    申请日:2024-05-16

    申请人: SPLUNK Inc.

    摘要: Described are systems, methods, and techniques for collecting, analyzing, processing, and storing time series data and for evaluating and dynamically estimating a resolution of one or more streams of data points and updating an output resolution. Responsive to receiving a stream of data points, a data resolution can be derived and an output resolution can be set to a first value. When a change to the data resolution is detected, the output resolution can be changed, modifying a frequency at which output data points are generated and/or transmitted. In some instances, a detector can be implemented to trigger an alert responsive to ingested data points corresponding with triggering parameters. An output resolution for the detector can be dynamically modified based on dynamically detecting a change to the data resolution of the stream of data.

    Real-time processing of data streams received from instrumented software

    公开(公告)号:US11928046B1

    公开(公告)日:2024-03-12

    申请号:US17515272

    申请日:2021-10-29

    申请人: Splunk Inc.

    摘要: An analysis system receives data streams generated by instances of instrumented software executing on external systems. The analysis system evaluates an expression using data values of the data streams over a plurality of time intervals. For example, the analysis system may aggregate data values of data streams for each time interval. The analysis system determines whether or not a data stream is considered for a time interval based on when the data value arrives during the time interval. The analysis system determines a maximum expected delay value for each data stream being processed. The analysis system evaluates the expression using data values that arrive before their maximum expected delay values. The analysis system also determines a failure threshold value for a data stream. If a data value of a data stream fails to arrive before the failure threshold value, the analysis system marks the data stream as dead.

    Real-time reporting based on instrumentation of software

    公开(公告)号:US11010278B2

    公开(公告)日:2021-05-18

    申请号:US16542318

    申请日:2019-08-16

    申请人: Splunk Inc.

    IPC分类号: G06F11/36 G06F11/30 G06F11/34

    摘要: A data analysis system processes data generated by instrumented software. The data analysis system receives data streams generated by instances of instrumented software executing on systems. The data analysis system also receives metadata describing data streams. The data analysis system receives an expression based on the metadata. The data analysis system receives data of data streams for each time interval and computes the result of the expression based on the received data values. The data analysis system repeats these steps for each time interval. The data analysis system may quantize data values of data streams for each time interval by generating an aggregate value for the time interval based on data received for each data stream for that time interval. The data analysis system evaluates the expression using the quantized data for the time interval.

    Automatic generation of queries using non-textual input

    公开(公告)号:US11947528B1

    公开(公告)日:2024-04-02

    申请号:US17589677

    申请日:2022-01-31

    申请人: Splunk Inc.

    摘要: Systems and methods are described for generation of a query using a non-textual input. For example, the query can be generated using a point and click input. A selection of a data source can be identified and an initial query can be automatically generated based on the selection of the data source. A graphical user interface can be displayed and populated with one or more selectable parameters based on the initial query. A selection of the one or more selectable parameters can be received as a non-textual input and a query can be automatically generated based on the selection. For example, a query for execution by a data intake and query system can be generated based on the selection. The query can be provided to the data intake and query system. The data intake and query system may then execute the query on a set of data.

    Generation of queries for execution at a separate system

    公开(公告)号:US11899670B1

    公开(公告)日:2024-02-13

    申请号:US17589558

    申请日:2022-01-31

    申请人: Splunk Inc.

    摘要: Systems and methods are described for generation of queries for execution by a separate system. In order establish a connection with the separate system, credentials can be obtained. For example, the credentials may be based on a user identifier and/or a login identifier. Indices can be identified that correspond to the credentials and a query can be identified that includes a selection of at least one of the indices. For example, the query may identify a set of log data ingested and indexed by the separate system. A request that includes the query, the credentials, and a connection identifier can be communicated to the separate system. In response to the request, a set of data can be received from the separate system. The set of data can be provided to a computing device. For example, the set of data can be provided to a computing device providing the query.

    Dynamic resolution estimation for a detector

    公开(公告)号:US12013880B2

    公开(公告)日:2024-06-18

    申请号:US17721251

    申请日:2022-04-14

    申请人: SPLUNK Inc.

    摘要: Described are systems, methods, and techniques for collecting, analyzing, processing, and storing time series data and for evaluating and dynamically estimating a resolution of one or more streams of data points and updating an output resolution. Responsive to receiving a stream of data points, a data resolution can be derived and an output resolution can be set to a first value. When a change to the data resolution is detected, the output resolution can be changed, modifying a frequency at which output data points are generated and/or transmitted. In some instances, a detector can be implemented to trigger an alert responsive to ingested data points corresponding with triggering parameters. An output resolution for the detector can be dynamically modified based on dynamically detecting a change to the data resolution of the stream of data.

    GENERATION OF MODIFIED QUERIES USING A FIELD VALUE FOR DIFFERENT FIELDS

    公开(公告)号:US20240143612A1

    公开(公告)日:2024-05-02

    申请号:US18051458

    申请日:2022-10-31

    申请人: Splunk Inc.

    IPC分类号: G06F16/248 G06F16/242

    CPC分类号: G06F16/248 G06F16/2425

    摘要: Systems and methods are described for generation and execution of modified queries. An input can be received via a visualization of a user interface. The input may identify a first field value and a first field for execution of a query. A set of data for execution of the query can be identified based on the input. Alias data may identify a second field that is associated with the first field. Using the alias data, a modified query can be generated based on the query and the second field. The modified query can be executed to generate query results. The query results can be displayed via a visualization of the user interface based on the first field.