HTTP events with custom fields
    3.
    发明授权

    公开(公告)号:US11093476B1

    公开(公告)日:2021-08-17

    申请号:US15276781

    申请日:2016-09-26

    Applicant: Splunk Inc.

    Abstract: A data intake and query system receives a message including raw machine via an internet protocol (IP) such as the hypertext transfer protocol (HTTP). The message includes a distinct payload portion and a distinct custom field portion. The payload portion includes raw machine data, while the custom field portion includes values for fields. An event that includes the raw machine data and the values is generated from the payload portion and the values are extracted from the custom field portion. The event is then stored such that the values are associated with the event.

    CENTRAL REPOSITORY FOR STORING CONFIGURATION FILES OF A DISTRIBUTED COMPUTER SYSTEM

    公开(公告)号:US20170317882A1

    公开(公告)日:2017-11-02

    申请号:US15143472

    申请日:2016-04-29

    Applicant: Splunk Inc.

    Abstract: In a computer-implemented method for configuring a distributed computer system comprising a plurality of nodes of a plurality of node classes, configuration files for a plurality of nodes of each of the plurality of node classes are stored in a central repository. The configuration files include information representing a desired system state of the distributed computer system, and the distributed computer system operates to keep an actual system state of the distributed computer system consistent with the desired system state. The plurality of node classes includes forwarder nodes for receiving data from an input source, indexer nodes for indexing the data, and search head nodes for searching the data. Responsive to receiving changes to the configuration files, the changes are propagated to nodes of the plurality of nodes impacted by the changes based on a node class of the nodes impacted by the changes.

    MANAGING SITE-BASED SEARCH CONFIGURATION DATA
    7.
    发明申请
    MANAGING SITE-BASED SEARCH CONFIGURATION DATA 有权
    管理基于站点的搜索配置数据

    公开(公告)号:US20150339308A1

    公开(公告)日:2015-11-26

    申请号:US14815880

    申请日:2015-07-31

    Applicant: Splunk Inc.

    Abstract: Techniques are described for managing data within a multi-site clustered data intake and query system. A data intake and query system as described herein generally refers to a system for collecting, retrieving, and analyzing data. In this context, a clustered data intake and query system generally refers to a system environment that is configured to provide data redundancy and other features that improve the availability of data stored by the system. For example, a clustered data intake and query system may be configured to store multiple copies of data stored by the system across multiple components such that recovery from a failure of one or more of the components is possible by using copies of the data stored elsewhere in the cluster.

    Abstract translation: 描述了用于管理多站点群集数据采集和查询系统中的数据的技术。 本文所述的数据采集和查询系统通常是指用于收集,检索和分析数据的系统。 在这种情况下,集群数据采集和查询系统通常是指被配置为提供数据冗余和提高系统存储的数据的可用性的其他特征的系统环境。 例如,集群数据采集和查询系统可以被配置为存储由多个组件存储的系统的多个副本,以便可以通过使用其他地方存储的数据的副本来从一个或多个组件的故障中恢复 集群。

    File Update Tracking
    8.
    发明申请
    File Update Tracking 有权
    文件更新跟踪

    公开(公告)号:US20150154217A1

    公开(公告)日:2015-06-04

    申请号:US14611156

    申请日:2015-01-30

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30144 G06F17/3015 G06F17/30286

    Abstract: Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.

    Abstract translation: 实施例涉及管理和跟踪多个项目的项目识别以确定项目是否是新的或现有的项目,其中已经预先处理了现有项目。 在一些实施例中,可以生成两个或多个项目标识符。 在一个实施例中,生成两个或多个项目标识符可以包括使用小项目尺寸特征,压缩项目或标识符冲突来分析项目。 可以使用两个或更多个项目标识符来确定该项目是新的还是现有的项目。 在一个实施例中,两个或多个项目标识符可以与关于现有项目的记录进行比较,以确定该项目是新项目还是现有项目。 如果项目是现有项目,则可以进一步处理该项目以确定现有项目是否已经实际改变。

    File identification management and tracking
    9.
    发明授权
    File identification management and tracking 有权
    文件识别管理和跟踪

    公开(公告)号:US08977638B2

    公开(公告)日:2015-03-10

    申请号:US14034220

    申请日:2013-09-23

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30144 G06F17/3015 G06F17/30286

    Abstract: Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.

    Abstract translation: 实施例涉及管理和跟踪多个项目的项目识别以确定项目是否是新的或现有的项目,其中已经预先处理了现有项目。 在一些实施例中,可以生成两个或多个项目标识符。 在一个实施例中,生成两个或多个项目标识符可以包括使用小项目尺寸特征,压缩项目或标识符冲突来分析项目。 可以使用两个或更多个项目标识符来确定该项目是新的还是现有的项目。 在一个实施例中,两个或多个项目标识符可以与关于现有项目的记录进行比较,以确定该项目是新项目还是现有项目。 如果项目是现有项目,则可以进一步处理该项目以确定现有项目是否已经实际改变。

Patent Agency Ranking