REPRODUCING DATASETS GENERATED BY ALERT-TRIGGERING SEARCH QUERIES

    公开(公告)号:US20200167311A1

    公开(公告)日:2020-05-28

    申请号:US16777357

    申请日:2020-01-30

    Applicant: Splunk Inc.

    Abstract: An example method for managing datasets produced by alert-triggering search queries may include producing a dataset by executing a search query on a portion of data associated with a time window defined relative to a current time. The method may further include responsive to determining that a portion of the dataset satisfies a condition defining an alert, generating an instance of the alert. The method may further include associating, by a memory data structure, the instance of the alert with an identifier of the query and a parameter specifying a time of execution of the query that has triggered the instance. The method may further include receiving a request for the dataset portion. The method may further include substituting, in a definition of the time window, the current time with the time parameter. The method may further include reproducing the dataset portion by re-executing the query using the time window.

    MANAGING DATASETS PRODUCED BY ALERT-TRIGGERING SEARCH QUERIES
    3.
    发明申请
    MANAGING DATASETS PRODUCED BY ALERT-TRIGGERING SEARCH QUERIES 审中-公开
    管理由ALERT-TRIGGERING搜索查询生成的数据

    公开(公告)号:US20160147830A1

    公开(公告)日:2016-05-26

    申请号:US14396367

    申请日:2014-07-09

    Applicant: SPLUNK INC.

    Abstract: Systems and methods for managing datasets produced by alert-triggering search queries in data aggregation and analysis systems. An example method may comprise: executing, by one or more processing devices, a search query on a portion of searchable data associated with a time window to produce a dataset comprising one or more results; responsive to determining that at least a portion of the dataset satisfies a triggering condition defining an alert associated with the search query, generating an instance of the alert; associating, by a memory data structure, the instance of the alert with an identifier of the search query and a time parameter specifying the time window; receiving, from a client computing device, a request for the portion of the dataset; and responsive to determining that the portion of the dataset is not stored in the memory in a manner associating it with the instance of the alert, reproducing the portion of the dataset by re-executing the search query in view of the time parameter.

    Abstract translation: 用于管理在数据聚合和分析系统中由警报触发搜索查询产生的数据集的系统和方法。 示例性方法可以包括:由一个或多个处理设备执行与时间窗口相关联的可搜索数据的一部分上的搜索查询,以产生包括一个或多个结果的数据集; 响应于确定所述数据集的至少一部分满足定义与所述搜索查询相关联的警报的触发条件,生成所述警报的实例; 通过存储器数据结构将警报的实例与搜索查询的标识符和指定时间窗口的时间参数相关联; 从客户端计算设备接收对所述数据集的所述部分的请求; 并且响应于确定所述数据集的所述部分未以与所述警报的实例相关联的方式存储在所述存储器中,通过根据所述时间参数重新执行所述搜索查询来再现所述数据集的所述部分。

    Managing datasets generated by search queries

    公开(公告)号:US12169471B2

    公开(公告)日:2024-12-17

    申请号:US17669156

    申请日:2022-02-10

    Applicant: Splunk Inc.

    Abstract: An example method for managing datasets produced by alert-triggering search queries may include producing a dataset by executing a search query on a portion of data associated with a time window defined relative to a current time. The method may further include responsive to determining that a portion of the dataset satisfies a condition defining an alert, generating an instance of the alert. The method may further include associating, by a memory data structure, the instance of the alert with an identifier of the query and a parameter specifying a time of execution of the query that has triggered the instance. The method may further include receiving a request for the dataset portion. The method may further include substituting, in a definition of the time window, the current time with the time parameter. The method may further include reproducing the dataset portion by re-executing the query using the time window.

    Presentation And Sorting Of Summaries Of Alert Instances Triggered By Search Questions
    5.
    发明申请
    Presentation And Sorting Of Summaries Of Alert Instances Triggered By Search Questions 审中-公开
    通过搜索问题触发的警报实例摘要的呈现和排序

    公开(公告)号:US20160253415A1

    公开(公告)日:2016-09-01

    申请号:US14396366

    申请日:2014-07-09

    Applicant: SPLUNK INC.

    Abstract: Systems and methods for presenting and sorting summaries of alerts triggered by search queries in data aggregation and analysis systems. An example method may comprise: causing, by one or more processing devices, one or more alert summaries to be displayed, each alert summary corresponding to an alert and representing one or more instances of the alert, the alert defined by a search query and a triggering condition; wherein an instance of the alert corresponds to a particular dataset that (i) is generated by executing the search query over time-series data falling within a particular time range in a set of time ranges over which the search query has been instructed to search, and (ii) satisfies the triggering condition for the alert; wherein an alert summary includes an indication of at least one of: a total count of alert instances generated by the alert, or a count of alert instances generated by the alert that have not been viewed by a user.

    Abstract translation: 用于呈现和排序数据汇总和分析系统中搜索查询触发的警报摘要的系统和方法。 示例性方法可以包括:通过一个或多个处理设备引起一个或多个警报摘要的显示,每个警报摘要对应于警报并且表示警报的一个或多个实例,由搜索查询和 触发条件; 其中所述警报的实例对应于特定数据集,所述特定数据集通过在搜索查询已被指示搜索的一组时间范围内的特定时间范围内的时间序列数据上执行搜索查询来生成, 和(ii)满足警报的触发条件; 其中警报摘要包括以下中的至少一个的指示:由所述警报产生的警报实例的总​​计数,或所述警报所生成的尚未被用户观看的警报实例的计数。

    MANAGING DATASETS GENERATED BY SEARCH QUERIES

    公开(公告)号:US20220171736A1

    公开(公告)日:2022-06-02

    申请号:US17669156

    申请日:2022-02-10

    Applicant: Splunk Inc.

    Abstract: An example method for managing datasets produced by alert-triggering search queries may include producing a dataset by executing a search query on a portion of data associated with a time window defined relative to a current time. The method may further include responsive to determining that a portion of the dataset satisfies a condition defining an alert, generating an instance of the alert. The method may further include associating, by a memory data structure, the instance of the alert with an identifier of the query and a parameter specifying a time of execution of the query that has triggered the instance. The method may further include receiving a request for the dataset portion. The method may further include substituting, in a definition of the time window, the current time with the time parameter. The method may further include reproducing the dataset portion by re-executing the query using the time window.

    Reproducing datasets generated by alert-triggering search queries

    公开(公告)号:US11288231B2

    公开(公告)日:2022-03-29

    申请号:US16777357

    申请日:2020-01-30

    Applicant: Splunk Inc.

    Abstract: An example method for managing datasets produced by alert-triggering search queries may include producing a dataset by executing a search query on a portion of data associated with a time window defined relative to a current time. The method may further include responsive to determining that a portion of the dataset satisfies a condition defining an alert, generating an instance of the alert. The method may further include associating, by a memory data structure, the instance of the alert with an identifier of the query and a parameter specifying a time of execution of the query that has triggered the instance. The method may further include receiving a request for the dataset portion. The method may further include substituting, in a definition of the time window, the current time with the time parameter. The method may further include reproducing the dataset portion by re-executing the query using the time window.

    Managing datasets produced by alert-triggering search queries

    公开(公告)号:US10585851B2

    公开(公告)日:2020-03-10

    申请号:US15461076

    申请日:2017-03-16

    Applicant: Splunk Inc.

    Abstract: An example method for managing datasets produced by alert-triggering search queries may include producing a dataset by executing a search query on a portion of data associated with a time window defined relative to a current time. The method may further include responsive to determining that a portion of the dataset satisfies a condition defining an alert, generating an instance of the alert. The method may further include associating, by a memory data structure, the instance of the alert with an identifier of the query and a parameter specifying a time of execution of the query that has triggered the instance. The method may further include receiving a request for the dataset portion. The method may further include substituting, in a definition of the time window, the current time with the time parameter. The method may further include reproducing the dataset portion by re-executing the query using the time window.

Patent Agency Ranking