IP Library Granted Patent US 9,514,183
Granted Patent B1
US 9,514,183 · App. 13/907,826 · Granted Dec 6, 2016

Indexing and searching of large amounts of machine generated data collected from disparate sources

Inventor: Sridhar Alla (Carlisle, MA)
Assignee: EiQ Networks, Inc.
G06F17/30424G06F17/30321G06F17/30598
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,514,183
App. No.
13/907,826
Granted
Dec 6, 2016
Kind
B1
Abstract

A computer-implemented method of searching large amounts of machine generated data collected from disparate sources, comprises steps of: receiving data from the disparate sources into a multi-level system of storage blocks; high-speed searching at a broad level for groups of the storage blocks containing records of interest; nested searching at an intermediate level to determine specific storage blocks containing the records of interest, within the groups of the storage blocks; distributed searching at a fine level to identify the records of interest, within the specific storage blocks; and displaying the records of interest to a user. In a computer data storage device, a data structure comprises: plural data files each holding a data group from a large data set, wherein the data groups are permitted to contain overlapping data; and plural index trees within each data file, each index tree representing a key into a data group; wherein an absence of a key in one data file results in an absence of a corresponding index tree in the one data file. A computer storage medium has stored thereon instructions for a computer to perform the method described above.

Claims (38)

1. A computer-implemented method of searching large amounts of machine generated data collected from disparate sources, comprising steps of:

receiving data from the disparate sources into a multi-level system of storage blocks;

high-speed searching at a broad level for groups of the storage blocks containing records of interest;

nested searching at an intermediate level in which the multi-level system of storage blocks are iteratively searched to determine specific storage blocks containing the records of interest, within the groups of the storage blocks;

distributed searching in which searching resources are load balanced among the specific storage blocks at a fine level to identify the records of interest, within the specific storage blocks; and

indexing the data received using plural index databases corresponding to plural keys into the data received;

managing each index database as a separate index tree;

grouping the data received into sets defined by time periods; and

performing indexing and managing within one set separately from within another set, so the one set can be separately searched from the another set;

indexing on any field within the data received;

adding to one of the plural index databases a new field when found in the data received; and

removing from one of the plural index databases a filed no longer used in the data received;

displaying the records of interest to a user.

2. The method of claim 1 , wherein high-speed searching further comprises:

applying a first search criterion by which a distribution of the records of interest amongst the groups of storage blocks is identified.

3. The method of claim 2 , wherein nested searching further comprises:

creating and adjusting a time range filter to include in the specific storage blocks, only those storage blocks covering a time range when the records of interest are created.

4. The method of claim 1 , wherein displaying further comprises:

arranging the records of interest in time sequence.

5. A non-transitory computer storage medium on which are stored instructions for a computer to perform a method of searching large amounts of machine generated data collected from disparate sources, comprising steps of:

receiving data from the disparate sources into a multi-level system of storage blocks;

high-speed searching at a broad level for groups of the storage blocks containing records of interest;

nested searching at an intermediate level in which the multi-level system of storage blocks are iteratively searched to determine specific storage blocks containing the records of interest, within the groups of the storage blocks;

distributed searching in which searching resources are load balanced among the specific storage blocks at a fine level to identify the records of interest, within the specific storage blocks; and

indexing the data received using plural index databases corresponding to plural keys into the data received;

managing each index database as a separate index tree;

grouping the data received into sets defined by time periods; and

performing indexing and managing within one set separately from within another set, so the one set can be separately searched from the another set;

indexing on any field within the data received;

adding to one of the plural index databases a new field when found in the data received; and

removing from one of the plural index databases a filed no longer used in the data received;

displaying the records of interest to a user.

6. The storage medium of claim 5 , wherein high-speed searching further comprises:

applying a first search criterion by which a distribution of the records of interest amongst the groups of storage blocks is identified.

7. The storage medium of claim 6 , wherein nested searching further comprises:

creating and adjusting a time range filter to include in the specific storage blocks, only those storage blocks covering a time range when the records of interest are created.

8. The storage medium of claim 5 , wherein displaying further comprises:

arranging the records of interest in time sequence.

Assignments (4)
CHANGE OF NAME Recorded Feb 18, 2019
From: EIQNETWORKS, INC.
To: EIQ NETWORKS, INC.
Reel/Frame 048359/0622 →
CHANGE OF NAME Recorded Feb 18, 2019
From: EIQ NETWORKS, INC.
To: CYGILANT, INC.
Reel/Frame 048359/0693 →
CHANGE OF NAME Recorded Feb 18, 2019
From: EIQ NETWORKS, INC.
To: EIQNETWORKS, INC.
Reel/Frame 048359/0698 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2013
From: ALLA, SRIDHAR
To: EIQNETWORKS, INC.
Reel/Frame 031504/0898 →
Continuity (1)
Provisional Application 61654567 · Jun 1, 2012