IP Library Granted Patent US 8,694,450
Granted Patent B2
US 8,694,450 · App. 13/664,109 · Granted Apr 8, 2014

Machine data web

Inventors: Michael Joseph Baum (Ross, CA); R. David Carasso (San Rafael, CA); Robin Kumar Das (Healdsburg, CA); Bradley Hall (Palo Alto, CA); Brian Philip Murphy (London, GB); Stephen Phillip Sorkin (San Francisco, CA); Andre David Stechert (Brooklyn, NY); Erik M. Swan (Piedmont, CA); Rory Greene (San Francisco, CA); Nicholas Christian Mealy (Oakland, CA); Christina Frances Regina Noren (San Francisco, CA)
Assignee: Splunk Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,694,450
App. No.
13/664,109
Filed
Oct 30, 2012
Granted
Apr 8, 2014
Kind
B2
Art Unit
2194
USPC
707/736
Abstract

Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.

Claims (56)

1. A system, comprising:

a processor; and

a non-transitory machine-readable storage device containing instructions configured to cause the processor to perform operations including:

receiving machine data;

determining a rule for transforming the machine data into a plurality of events,

wherein an event includes one or more segments;

using the rule to transform the machine data into the plurality of events;

determining a pattern of event behavior in the plurality of events, wherein the pattern includes a relationship between a segment from a first event of the plurality of events and a segment from a second event of the plurality of events; and

determining a set of events included in the pattern of event behavior using the relationship in the pattern of event behavior.

2. The system of claim 1 , further comprising instructions configured to cause the processor to perform operations including:

determining that the pattern corresponds to an anomaly.

3. The system of claim 1 , wherein the pattern includes a sequential occurrence of events.

4. The system of claim 1 , wherein the pattern includes events that occur within a window of each other.

5. The system of claim 1 , wherein receiving the machine data includes collecting the machine data by two or more distributed modules that have access to the machine data.

6. The system of claim 1 , further comprising instructions configured to cause the processor to perform operations including:

determining that the pattern corresponds to a system activity.

7. The system of claim 1 , further comprising instructions configured to cause the processor to perform operations including:

determining a frequency of the pattern of event behavior.

8. The system of claim 1 , further comprising instructions configured to cause the processor to perform operations including:

generating a link using the determined set of events, wherein the link identifies a segment associated with the determined set of events.

9. A computer-implemented method, comprising:

receiving, at a computing system, machine data;

determining a rule for transforming the machine data into a plurality of events,

wherein an event includes one or more segments;

using the rule to transform the machine data into the plurality of events;

determining a pattern of event behavior in the plurality of events, wherein the pattern includes a relationship between a segment from a first event of the plurality of events and a segment from a second event of the plurality of events; and

determining a set of events included in the pattern of event behavior using the relationship in the pattern of event behavior.

10. The method of claim 9 , further comprising:

determining that the pattern corresponds to an anomaly.

11. The method of claim 9 , wherein the pattern includes a sequential occurrence of events.

12. The method of claim 9 , wherein the pattern includes events that occur within a window of each other.

13. The method of claim 9 , wherein receiving the machine data includes collecting the machine data by two or more distributed modules that have access to the machine data.

14. The method of claim 9 , further comprising:

determining that the pattern corresponds to a system activity.

15. The method of claim 9 , further comprising:

determining a frequency of the pattern of event behavior.

16. The method of claim 9 , further comprising:

generating a link using the determined set of events, wherein the link identifies a segment associated with the determined set of events.

17. A computer-program product, tangibly embodied in a non-transitory machine-readable storage device, including instructions configured to cause a data processing apparatus to:

receive machine data;

determine a rule for transforming the machine data into a plurality of events,

wherein an event includes one or more segments;

use the rule to transform the machine data into the plurality of events;

determine a pattern of event behavior in the plurality of events, wherein the pattern includes a relationship between a segment from a first event of the plurality of events and a segment from a second event of the plurality of events; and

determine a set of events included in the pattern of event behavior using the relationship in the pattern of event behavior.

18. The computer-program product of claim 17 , further comprising instructions configured to cause the data processing apparatus to:

determine that the pattern corresponds to an anomaly.

19. The computer-program product of claim 17 , wherein the pattern includes a sequential occurrence of events.

20. The computer-program product of claim 17 , wherein the pattern includes events that occur within a window of each other.

21. The computer-program product of claim 17 , wherein receiving the machine data includes collecting the machine data by two or more distributed modules that have access to the machine data.

22. The computer-program product of claim 17 , further comprising instructions configured to cause the data processing apparatus to:

determine that the pattern corresponds to a system activity.

23. The computer-program product of claim 17 , further comprising instructions configured to cause the data processing apparatus to:

determine a frequency of the pattern of event behavior.

24. The computer-program product of claim 17 , further comprising instructions configured to cause the data processing apparatus to:

generate a link using the determined set of events, wherein the link identifies a segment associated with the determined set of events.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2012
From: BAUM, MICHAEL JOSEPH; CARASSO, R. DAVID; DAS, ROBIN KUMAR; HALL, BRADLEY; MURPHY, BRIAN PHILIP; SORKIN, STEPHEN PHILLIP; STECHERT, ANDRE DAVID; SWAN, ERIK M.; GREENE, RORY; MEALY, NICHOLAS CHRISTIAN; NOREN, CHRISTINA
To: SPLUNK INC.
Reel/Frame 029213/0001 →
Continuity (4)
Continuation 13099268 · May 2, 2011
Continuation 11459632 · Jul 24, 2006
Provisional Application 60702496 · Jul 25, 2005
Related Publication 20130054596A1 · Feb 28, 2013