Dynamic resolution estimation for a detector

    公开(公告)号:US12013880B2

    公开(公告)日:2024-06-18

    申请号:US17721251

    申请日:2022-04-14

    Applicant: SPLUNK Inc.

    CPC classification number: G06F16/287 G06F16/24568 G06F16/2477 H04L43/08

    Abstract: Described are systems, methods, and techniques for collecting, analyzing, processing, and storing time series data and for evaluating and dynamically estimating a resolution of one or more streams of data points and updating an output resolution. Responsive to receiving a stream of data points, a data resolution can be derived and an output resolution can be set to a first value. When a change to the data resolution is detected, the output resolution can be changed, modifying a frequency at which output data points are generated and/or transmitted. In some instances, a detector can be implemented to trigger an alert responsive to ingested data points corresponding with triggering parameters. An output resolution for the detector can be dynamically modified based on dynamically detecting a change to the data resolution of the stream of data.

    GENERATION OF MODIFIED QUERIES USING A FIELD VALUE FOR DIFFERENT FIELDS

    公开(公告)号:US20240143612A1

    公开(公告)日:2024-05-02

    申请号:US18051458

    申请日:2022-10-31

    Applicant: Splunk Inc.

    CPC classification number: G06F16/248 G06F16/2425

    Abstract: Systems and methods are described for generation and execution of modified queries. An input can be received via a visualization of a user interface. The input may identify a first field value and a first field for execution of a query. A set of data for execution of the query can be identified based on the input. Alias data may identify a second field that is associated with the first field. Using the alias data, a modified query can be generated based on the query and the second field. The modified query can be executed to generate query results. The query results can be displayed via a visualization of the user interface based on the first field.

    Generation of queries using non-textual input

    公开(公告)号:US12298981B1

    公开(公告)日:2025-05-13

    申请号:US18441788

    申请日:2024-02-14

    Applicant: Splunk Inc.

    Abstract: Systems and methods are described for generation of a query using a non-textual input. For example, the query can be generated using a point and click input. A selection of a data source can be identified and an initial query can be automatically generated based on the selection of the data source. A graphical user interface can be displayed and populated with one or more selectable parameters based on the initial query. A selection of the one or more selectable parameters can be received as a non-textual input and a query can be automatically generated based on the selection. For example, a query for execution by a data intake and query system can be generated based on the selection. The query can be provided to the data intake and query system. The data intake and query system may then execute the query on a set of data.

    Optimized storage of metadata separate from time series data

    公开(公告)号:US12298980B1

    公开(公告)日:2025-05-13

    申请号:US16938807

    申请日:2020-07-24

    Applicant: Splunk Inc.

    Abstract: According to embodiments, a data stream including a plurality of time series data is received and metadata objects are extracted from the data stream. The metadata objects are associated with metrics time series (MTS) objects. The metadata objects and MTS objects are stored via separate in-memory data structures in a logical database. The in-memory data structures include information that correlates the metadata objects with the MTS objects. Any updates to the metadata objects will stay with the metadata objects and do not propagate to the MTS objects. A logical in-memory join may be performed to associate the metadata objects with the appropriate MTS object according to the in-memory data structures when a query for an MTS object is received.

    DYNAMIC RESOLUTION ESTIMATION FOR A DETECTOR

    公开(公告)号:US20230120313A1

    公开(公告)日:2023-04-20

    申请号:US17721251

    申请日:2022-04-14

    Applicant: SPLUNK Inc.

    Abstract: Described are systems, methods, and techniques for collecting, analyzing, processing, and storing time series data and for evaluating and dynamically estimating a resolution of one or more streams of data points and updating an output resolution. Responsive to receiving a stream of data points, a data resolution can be derived and an output resolution can be set to a first value. When a change to the data resolution is detected, the output resolution can be changed, modifying a frequency at which output data points are generated and/or transmitted. In some instances, a detector can be implemented to trigger an alert responsive to ingested data points corresponding with triggering parameters. An output resolution for the detector can be dynamically modified based on dynamically detecting a change to the data resolution of the stream of data.

    Real-time processing of data streams received from instrumented software

    公开(公告)号:US11194697B2

    公开(公告)日:2021-12-07

    申请号:US16546860

    申请日:2019-08-21

    Applicant: Splunk Inc.

    Abstract: An analysis system receives data streams generated by instances of instrumented software executing on external systems. The analysis system evaluates an expression using data values of the data streams over a plurality of time intervals. For example, the analysis system may aggregate data values of data streams for each time interval. The analysis system determines whether or not a data stream is considered for a time interval based on when the data value arrives during the time interval. The analysis system determines a maximum expected delay value for each data stream being processed. The analysis system evaluates the expression using data values that arrive before their maximum expected delay values. The analysis system also determines a failure threshold value for a data stream. If a data value of a data stream fails to arrive before the failure threshold value, the analysis system marks the data stream as dead.

    Combining data streams generated by instrumented software using metadata correlation

    公开(公告)号:US11093506B1

    公开(公告)日:2021-08-17

    申请号:US16427024

    申请日:2019-05-30

    Applicant: Splunk Inc.

    Abstract: A system processes data stream language expressions that combine result data streams from multiple data stream language sub-expressions. The system determines a set of fixed dimensions based on static analysis of the data stream language sub-expression. The system determines a union set representing a union of the sets of fixed dimensions. The system determines at execution time of the data stream language expression, a plurality of sets of data streams. Each set of data stream corresponds to a data stream language sub-expression from the plurality of data stream language expressions. The system correlates data streams across the plurality of sets of data streams based on the union set. The system determines result data streams for the data stream language expression by combining data values of correlated data streams.

Patent Agency Ranking