IP Library Granted Patent US 9,128,916
Granted Patent B2
US 9,128,916 · App. 14/170,228 · Granted Sep 8, 2015

Machine data web

Inventors: Michael Joseph Baum (Ross, CA); R. David Carasso (San Rafael, CA); Robin Kumar Das (Healdsburg, CA); Bradley Hall (Palo Alto, CA); Brian Phillip Murphy (London, GB); Stephen Phillip Sorkin (San Francisco, CA); Andre David Stechert (Brooklyn, NY); Erik M. Swan (Piedmont, CA); Rory Greene (San Francisco, CA); Nicholas Christian Mealy (Oakland, CA); Christina Frances Regina Noren (San Francisco, CA)
Assignee: Splunk Inc.
G06F17/2235G06F17/30082G06F17/30595G06F17/30619G06F17/30705G06K9/6217G06F11/3476
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,128,916
App. No.
14/170,228
Filed
Jan 31, 2014
Granted
Sep 8, 2015
Kind
B2
Art Unit
2194
USPC
707/736
Abstract

Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.

Claims (64)

1. A method, comprising:

organizing into a plurality of events machine data from a plurality of diverse sources, wherein there is no obvious common structure shared among the machine data from the plurality of diverse sources, and wherein machine data included in each event in the plurality of events retains its original structure;

extracting IP addresses from the plurality of events;

performing a search on the plurality of events;

wherein the method is performed by one or more computing devices.

2. The method as recited in claim 1 , further comprising:

determining a time stamp for each event in the plurality of events.

3. The method as recited in claim 1 , further comprising:

automatically identifying boundaries of events within the machine data.

4. The method as recited in claim 1 , further comprising:

generating statistical information based on extracted event information.

5. The method as recited in claim 1 , wherein extracting IP addresses further comprises:

applying regular expressions to the plurality of events to extract the IP addresses from the plurality of events.

6. The method as recited in claim 1 , wherein extracting IP addresses further comprises:

applying search trees to the plurality of events to extract the IP addresses from the plurality of events.

7. The method as recited in claim 1 , further comprising:

automatically identifying boundaries of events within the machine data.

8. The method as recited in claim 1 , wherein organizing machine data into a plurality of events further comprises:

automatically creating rules for identifying boundaries of events within the machine data;

storing the rules in at least one storage device;

applying the rules to the machine data to define each event in the plurality of events.

9. The method as recited in claim 1 , wherein an event is comprised of at least a portion of one or more lines of data within the machine data.

10. An apparatus, comprising:

a machine data organization subsystem, implemented at least partially in hardware, that organizes into a plurality of events machine data from a plurality of diverse sources, wherein there is no obvious common structure shared among the machine data from the plurality of diverse sources, and wherein machine data included in each event in the plurality of events retains its original structure;

an IP extraction subsystem, implemented at least partially in hardware, that extracts IP addresses from the plurality of events;

an event search subsystem, implemented at least partially in hardware, that performs a search on the plurality of events.

11. The apparatus as recited in claim 10 , further comprising:

a time stamp subsystem, implemented at least partially in hardware, that determines a time stamp for each event in the plurality of events.

12. The apparatus as recited in claim 10 , further comprising:

a boundary identification subsystem, implemented at least partially in hardware, that automatically identifies boundaries of events within the machine data.

13. The apparatus as recited in claim 10 , further comprising:

a statistical generation subsystem, implemented at least partially in hardware, that generates statistical information based on extracted event information.

14. The apparatus as recited in claim 10 , wherein the IP extraction subsystem further comprises:

a subsystem, implemented at least partially in hardware, that applies regular expressions to the plurality of events to extract the IP addresses from the plurality of events.

15. The apparatus as recited in claim 10 , wherein the IP extraction subsystem further comprises:

a subsystem, implemented at least partially in hardware, that applies search trees to the plurality of events to extract the IP addresses from the plurality of events.

16. The apparatus as recited in claim 10 , further comprising:

a boundary identification subsystem, implemented at least partially in hardware, that automatically identifies boundaries of events within the machine data.

17. The apparatus as recited in claim 10 , wherein the machine data organization organizing subsystem further comprises:

a subsystem, implemented at least partially in hardware, that automatically creates rules for identifying boundaries of events within the machine data;

a subsystem, implemented at least partially in hardware, that stores the rules in at least one storage device;

a subsystem, implemented at least partially in hardware, that applies the rules to the machine data to define each event in the plurality of events.

18. The apparatus as recited in claim 10 , wherein an event is comprised of at least a portion of one or more lines of data within the machine data.

19. A non-transitory computer-readable medium storing one or more sequences of instructions, wherein execution of the one or more sequences of instructions by one or more processors causes the one or more processors to perform:

organizing into a plurality of events machine data from a plurality of diverse sources, wherein there is no obvious common structure shared among the machine data from the plurality of diverse sources, and wherein machine data included in each event in the plurality of events retains its original structure;

extracting IP addresses from the plurality of events;

performing a search on the plurality of events.

20. The non-transitory computer-readable medium as recited in claim 19 , wherein execution of the one or more sequences of instructions by the one or more processors causes the one or more processors to further perform:

determining a time stamp for each event in the plurality of events.

21. The non-transitory computer-readable medium as recited in claim 19 , wherein execution of the one or more sequences of instructions by the one or more processors causes the one or more processors to further perform:

automatically identifying boundaries of events within the machine data.

22. The non-transitory computer-readable medium as recited in claim 19 , wherein execution of the one or more sequences of instructions by the one or more processors causes the one or more processors to further perform:

generating statistical information based on extracted event information.

23. The non-transitory computer-readable medium as recited in claim 19 , wherein extracting IP addresses further comprises:

applying regular expressions to the plurality of events to extract the IP addresses from the plurality of events.

24. The non-transitory computer-readable medium as recited in claim 19 , wherein extracting IP addresses further comprises:

applying search trees to the plurality of events to extract the IP addresses from the plurality of events.

25. The non-transitory computer-readable medium as recited in claim 19 , wherein execution of the one or more sequences of instructions by the one or more processors causes the one or more processors to further perform:

automatically identifying boundaries of events within the machine data.

26. The non-transitory computer-readable medium as recited in claim 19 , wherein organizing machine data into a plurality of events further comprises:

automatically creating rules for identifying boundaries of events within the machine data;

storing the rules in at least one storage device;

applying the rules to the machine data to define each event in the plurality of events.

27. The non-transitory computer-readable medium as recited in claim 19 , wherein an event is comprised of at least a portion of one or more lines of data within the machine data.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2015
From: BAUM, MICHAEL JOSEPH; CARASSO, R. DAVID; DAS, ROBIN KUMAR; HALL, BRADLEY; MURPHY, BRIAN PHILIP; SORKIN, STEPHEN PHILLIP; STECHERT, ANDRE DAVID; SWAN, ERIK M.; GREENE, RORY; MEALY, NICHOLAS CHRISTIAN; NOREN, CHRISTINA
To: SPLUNK INC.
Reel/Frame 036630/0001 →
Continuity (5)
Continuation 13664109 · Oct 30, 2012
Continuation 13099268 · May 2, 2011
Continuation 11459632 · Jul 24, 2006
Provisional Application 60702496 · Jul 25, 2005
Related Publication 20140149438A1 · May 29, 2014