Managing datasets generated by search queries

    公开(公告)号:US12169471B2

    公开(公告)日:2024-12-17

    申请号:US17669156

    申请日:2022-02-10

    Applicant: Splunk Inc.

    Abstract: An example method for managing datasets produced by alert-triggering search queries may include producing a dataset by executing a search query on a portion of data associated with a time window defined relative to a current time. The method may further include responsive to determining that a portion of the dataset satisfies a condition defining an alert, generating an instance of the alert. The method may further include associating, by a memory data structure, the instance of the alert with an identifier of the query and a parameter specifying a time of execution of the query that has triggered the instance. The method may further include receiving a request for the dataset portion. The method may further include substituting, in a definition of the time window, the current time with the time parameter. The method may further include reproducing the dataset portion by re-executing the query using the time window.

    Schedule modification of data collection requests sent to external data sources

    公开(公告)号:US10678805B2

    公开(公告)日:2020-06-09

    申请号:US15966279

    申请日:2018-04-30

    Applicant: Splunk Inc.

    Abstract: Techniques and mechanisms are disclosed that enable a data collection system to adaptively control collection of data from one or more external data sources. At a high level, adaptively controlling collection of data from external data sources may include collecting performance information related to one or more data collection nodes and, in response to analyzing the collected performance information, adapting rates at which the data collection nodes send data collection requests to external data sources. Data collection performance information generally may include, but is not limited to, network traffic data, error messages generated by external data sources and/or data collection nodes, computing device performance information, and any other types of information related to a data collection node's ability to collect data from external data sources.

    Adaptive control of data collection requests sent to external data sources

    公开(公告)号:US10007710B2

    公开(公告)日:2018-06-26

    申请号:US15011525

    申请日:2016-01-30

    Applicant: Splunk Inc.

    CPC classification number: G06F16/248 H04L43/024 H04L43/0817

    Abstract: Techniques and mechanisms are disclosed that enable a data collection system to adaptively control collection of data from one or more external data sources. At a high level, adaptively controlling collection of data from external data sources may include collecting performance information related to one or more data collection nodes and, in response to analyzing the collected performance information, adapting rates at which the data collection nodes send data collection requests to external data sources. Data collection performance information generally may include, but is not limited to, network traffic data, error messages generated by external data sources and/or data collection nodes, computing device performance information, and any other types of information related to a data collection node's ability to collect data from external data sources.

    Presentation And Sorting Of Summaries Of Alert Instances Triggered By Search Questions
    16.
    发明申请
    Presentation And Sorting Of Summaries Of Alert Instances Triggered By Search Questions 审中-公开
    通过搜索问题触发的警报实例摘要的呈现和排序

    公开(公告)号:US20160253415A1

    公开(公告)日:2016-09-01

    申请号:US14396366

    申请日:2014-07-09

    Applicant: SPLUNK INC.

    Abstract: Systems and methods for presenting and sorting summaries of alerts triggered by search queries in data aggregation and analysis systems. An example method may comprise: causing, by one or more processing devices, one or more alert summaries to be displayed, each alert summary corresponding to an alert and representing one or more instances of the alert, the alert defined by a search query and a triggering condition; wherein an instance of the alert corresponds to a particular dataset that (i) is generated by executing the search query over time-series data falling within a particular time range in a set of time ranges over which the search query has been instructed to search, and (ii) satisfies the triggering condition for the alert; wherein an alert summary includes an indication of at least one of: a total count of alert instances generated by the alert, or a count of alert instances generated by the alert that have not been viewed by a user.

    Abstract translation: 用于呈现和排序数据汇总和分析系统中搜索查询触发的警报摘要的系统和方法。 示例性方法可以包括:通过一个或多个处理设备引起一个或多个警报摘要的显示,每个警报摘要对应于警报并且表示警报的一个或多个实例,由搜索查询和 触发条件; 其中所述警报的实例对应于特定数据集,所述特定数据集通过在搜索查询已被指示搜索的一组时间范围内的特定时间范围内的时间序列数据上执行搜索查询来生成, 和(ii)满足警报的触发条件; 其中警报摘要包括以下中的至少一个的指示:由所述警报产生的警报实例的总​​计数,或所述警报所生成的尚未被用户观看的警报实例的计数。

    Technology add-on interface
    17.
    发明授权

    公开(公告)号:US12265863B2

    公开(公告)日:2025-04-01

    申请号:US17565181

    申请日:2021-12-29

    Applicant: Splunk Inc.

    Abstract: The operation of an automatic data input and query system is controlled by well-defined control data. The system exposes user interfaces enabling an administrator to interact with control data to modify the ongoing operation of the system. Certain control data determines the collection and treatment of data from various technology sources. A robust control interface is provided enabling the efficient and reliable adding on of new technology data sources. Once established, control data for a new technology data source may be packaged in a form for archiving or distribution. The system may support the export and import of such packages. Such packages may be created independently of the system.

    TECHNOLOGY ADD-ON INTERFACE
    18.
    发明申请

    公开(公告)号:US20220121410A1

    公开(公告)日:2022-04-21

    申请号:US17565181

    申请日:2021-12-29

    Applicant: Splunk Inc.

    Abstract: The operation of an automatic data input and query system is controlled by well-defined control data. The system exposes user interfaces enabling an administrator to interact with control data to modify the ongoing operation of the system. Certain control data determines the collection and treatment of data from various technology sources. A robust control interface is provided enabling the efficient and reliable adding on of new technology data sources. Once established, control data for a new technology data source may be packaged in a form for archiving or distribution. The system may support the export and import of such packages. Such packages may be created independently of the system.

    REPRODUCING DATASETS GENERATED BY ALERT-TRIGGERING SEARCH QUERIES

    公开(公告)号:US20200167311A1

    公开(公告)日:2020-05-28

    申请号:US16777357

    申请日:2020-01-30

    Applicant: Splunk Inc.

    Abstract: An example method for managing datasets produced by alert-triggering search queries may include producing a dataset by executing a search query on a portion of data associated with a time window defined relative to a current time. The method may further include responsive to determining that a portion of the dataset satisfies a condition defining an alert, generating an instance of the alert. The method may further include associating, by a memory data structure, the instance of the alert with an identifier of the query and a parameter specifying a time of execution of the query that has triggered the instance. The method may further include receiving a request for the dataset portion. The method may further include substituting, in a definition of the time window, the current time with the time parameter. The method may further include reproducing the dataset portion by re-executing the query using the time window.

    Automatically adjusting timestamps from remote systems based on time zone differences

    公开(公告)号:US10567557B2

    公开(公告)日:2020-02-18

    申请号:US14889764

    申请日:2014-10-31

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that processes data received from a remote system. During operation, the system sends, from a computer system to a remote system, a request for a local time at the remote system and records a time of transmission of the request. Next, the system obtains, from the remote system, a response to the request, wherein the response includes the local time of the remote system. The system then computes a difference between the time of transmission and the local time of the remote system to determine a time offset that accounts for a time difference between the computer system and the remote system. Finally, the system uses the time offset to standardize timestamps in time-series data received from the remote system, wherein standardizing the timestamps associated with the time-series data comprises adjusting the timestamps to conform to a time standard.

Patent Agency Ranking