Identifying an indexing node to process data using a resource catalog

    公开(公告)号:US11892996B1

    公开(公告)日:2024-02-06

    申请号:US16513365

    申请日:2019-07-16

    Applicant: Splunk Inc.

    Abstract: Systems and methods are described for monitoring indexing nodes, populating and maintaining a resource catalog with relevant information, receiving requests for indexing node availability or assignments, identifying indexing nodes that are available to process data, and/or communicating information relating to available indexing nodes. The system can maintain the resource catalog based on communications with each of the containerized indexing nodes. The system can receive, from a partition manager of a data intake and query system, a request for a containerized indexing node that the partition manager can assign to process data received by the partition manager. The system can identify an available containerized indexing node to process the data. The system can communicate, to the partition manager, an indexing node identifier associated with the available containerized indexing node.

    BUCKET MERGING FOR A DATA INTAKE AND QUERY SYSTEM USING SIZE THRESHOLDS

    公开(公告)号:US20220261385A1

    公开(公告)日:2022-08-18

    申请号:US17661510

    申请日:2022-04-29

    Applicant: Splunk Inc.

    Abstract: Systems and methods are disclosed for scalable bucket merging in a data intake and query system. Various components of a bucket manager can be used to monitor recently-created buckets of data in common storage that are associated with a particular tenant and a particular index, apply a comprehensive bucket merge policy to determine groups of buckets that qualify for merging, merge those group of buckets into merged buckets to be stored in the common storage, and update any information associated with the merged buckets and pre-merged buckets. These components may be shared across multiple tenants, and some of these components may be dynamically scalable based on need. This approach may also provide many additional benefits, including improved search performance from merged buckets, efficient resource utilization associated with discriminate merging, and redundancy in case of component failure.

Patent Agency Ranking