IP Library Granted Patent US 9,922,114
Granted Patent B2
US 9,922,114 · App. 14/610,704 · Granted Mar 20, 2018

Systems and methods for distributing indexer configurations

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,922,114
App. No.
14/610,704
Granted
Mar 20, 2018
Kind
B2
Abstract

Provided are systems and methods for causing display of an index management graphical user interface (GUI). In one embodiment, a method can be provided. The method can include causing display of an index management GUI including one or more user editable fields for specifying one or more index settings; receiving, via the one or more user editable fields of the index management GUI, one or more user specified index settings; generating an index definition corresponding to the one or more user specified index settings; and distributing the index definition to one or more indexers of a data processing system. The one or more indexers are able to manage storage of data in one or more indexes based at least in part on the index definition.

Claims (48)

1. A computer-implemented method comprising:

in response to a request, displaying, by a server computer, an index management graphical user interface (GUI) comprising one or more user editable interactive elements for receiving one or more user specified index settings for managing storage of indexed machine data in one or more indexes of a machine data processing system;

receiving, by the server computer via the one or more user editable interactive elements of the index management GUI, the one or more user specified index settings;

generating, by the server computer, an index configuration file including an index definition comprising a user specified manner in which to index incoming raw machine data that is subsequently received by the machine data processing system to generate indexed machine data that is searchable data in the one or more indexes of the machine data processing system, the user specified manner corresponding to the one or more user specified index settings; and

automatically causing, by the server computer via a network, distributing of the index configuration file in a hierarchical manner to two or more indexers of the machine data processing system that causes the index definition to be synchronized on the two or more indexers, wherein the distributing of the index configuration file is a single distribution of the index definition that effectuates a first change in association with a first indexer of the two or more indexers and a second change in association with a second indexer of the two or more indexers, and causes the two or more indexers to index the raw machine data in accordance with the index definition to generate the indexed machine data, wherein the distributing comprises pushing the index configuration file to a master node of at least one of the first indexer and the second indexer, the master node being part of the machine data processing system.

2. The method of claim 1 , wherein the user specified manner specifies a maximum storage size for an index the two or more indexers.

3. The method of claim 1 , wherein the single distribution causes the two or more indexers to index the raw machine data according to the user specified manner.

4. The method of claim 1 , wherein the pushing of the index configuration file is to a first master node of the first indexer and a second master node of the second indexer, the first master node, the second master node, and the server computer each being part of the machine data processing system.

5. The method of claim 1 , wherein the distributing of the index configuration file comprises providing the index configuration file to a first cluster of indexers comprising the first indexer and a second cluster of indexers comprising the second indexer.

6. The method of claim 1 , wherein the distributing of the index configuration file is to a master node indexer of a cluster comprising the first indexer, and the master node indexer distributes the configuration file to a plurality of nodes of the cluster.

7. The method of claim 1 , wherein the distributing of the index configuration file causes a search head of a cluster of indexers comprising the first indexer to use the index definition to distribute search tasks on the indexed machine data to at least some of the indexers of the cluster and merge search results of the search tasks from the at least some of the indexers.

8. The method of claim 1 , wherein the one or more user specified index settings edit at least an existing index of the two or more indexers, and the user specified manner comprises at least one of a maximum storage size for the existing index, a retention policy for the existing index, and an access policy for the existing index, and at least one of the one or more user editable interactive elements is pre-populated with a current index setting for the existing index.

9. The method of claim 1 , wherein the one or more user specified index settings edit at least an existing index of the two or more indexers, and the index management GUI comprises a count of events stored in the existing index, a time of an earliest event in the existing index, and a time of a latest event in the existing index.

10. The method of claim 1 , wherein the one or more user specified index settings create at least a new index by at least one of the two or more indexers, and at least one of the one or more user editable interactive elements is pre-populated with a default index setting for the new index.

11. The method of claim 1 , wherein the user specified manner defines when data in an index is to be discarded based on an age of the data and a time that is user provided to the one or more user editable interactive elements.

12. The method of claim 1 , further comprising causing display of an index overview GUI comprising:

user selectable interactive elements to navigate to the index management GUI; and

a listing of existing indexes of the two or more indexers, wherein the listing of existing indexes comprises at least one of the following for each of the existing indexes:

a name of the index, a maximum storage size of the index, a current size of the index, a retention policy for the index, a count of events in the index, a time of an earliest event in the index, a time of a latest event in the index, an application associated with the index, and a status of the index.

13. The method of claim 1 , wherein the user specified manner defines a maximum storage size based on a user provided storage quantity entered into the one or more user editable interactive elements, and wherein using the user specified manner, data is caused to be removed from an index of the one or more indexes as a result of the two or more indexers receiving the raw machine data based on an age of the data.

14. The method of claim 1 , further comprising causing display of an index progress GUI indicating progress of applying the one or more user specified index settings to the two or more indexers.

15. The method of claim 1 , wherein the distributing of the index configuration file causes the distributed index configuration file to replace a previous version of the index configuration file that is stored at the first indexer.

16. The method of claim 1 , wherein the distributing of the index configuration file causes deletion of at least one existing index by an indexer of the two or more indexers based on the index definition not including the existing index.

17. The method of claim 1 , wherein the user specified manner causes at least one of the two or more indexers to delete a raw data file contained in an index, the raw data file comprising at least some of the raw machine data in compressed form.

18. The method of claim 1 , wherein the index definition comprises a definition of a new index based on the one or more user specified index settings.

19. The method of claim 1 , wherein the distributing of the index configuration file is based on a request from at least one of the two or more indexers.

20. The method of claim 1 , wherein the two or more indexers limit access to data stored in the one or more indexes based at least in part on the index definition.

21. The method of claim 1 , further comprising automatically causing, by the server computer via a network, distribution of the index definition to a forwarder of the machine data processing system, the forwarder collecting the raw machine data from a plurality of sources, and determining for each data item corresponding to the raw machine data, which of the two or more indexers will receive the data item for indexing based on the index definition.

22. A computer-implemented system comprising:

one or more processors; and

one or more memories comprising program instructions stored thereon that are executable by the one or more processors to perform operations comprising:

in response to a request, displaying, by a server computer, an index management graphical user interface (GUI) comprising one or more user editable interactive elements for receiving one or more user specified index settings for managing storage of indexed machine data in one or more indexes of a machine data processing system;

receiving, by the server computer via the one or more user editable interactive elements of the index management GUI, the one or more user specified index settings;

generating, by the server computer, an index configuration file including an index definition comprising a user specified manner in which to index incoming raw machine data that is subsequently received by the machine data processing system to generate indexed machine data that is searchable data in the one or more indexes of the machine data processing system, the user specified manner corresponding to the one or more user specified index settings; and

automatically causing, by the server computer via a network, distributing of the index configuration file in a hierarchical manner to two or more indexers of the machine data processing system that causes the index definition to be synchronized on the two or more indexers, wherein the distributing of the index configuration file is a single distribution of the index definition that effectuates a first change in association with a first indexer of the two or more indexers and a second change in association with a second indexer of the two or more indexers, and causes the two or more indexers to index the raw machine data in accordance with the index definition to generate the indexed machine data, wherein the distributing comprises pushing the index configuration file to a master node of at least one of the first indexer and the second indexer, the master node being part of the machine data processing system.

23. The system of claim 22 , wherein the pushing of the index configuration file is to a first master node of the first indexer and a second master node of the second indexer, the first master node and the second master node each being part of the machine data processing system.

24. The system of claim 22 , wherein the distributing of the index configuration file comprises providing the index configuration file to a first cluster of indexers comprising the first indexer and a second cluster of indexers comprising the second indexer.

25. The system of claim 22 , wherein the distributing of the index configuration file is to a master node indexer of a cluster comprising the first indexer, and the master node indexer distributes the configuration file to a plurality of nodes of the cluster.

26. The system of claim 22 , wherein the distributing of the index configuration file causes a search head of a cluster of indexers comprising the first indexer to use the index definition to distribute search tasks on the indexed machine data to at least some of the indexers of the cluster and merge search results of the search tasks from the at least some of the indexers.

27. One or more non-transitory computer-readable media comprising program instructions stored thereon that are executable by one or more processors to perform operations comprising:

in response to a request, displaying, by a server computer, an index management graphical user interface (GUI) comprising one or more user editable interactive elements for receiving one or more user specified index settings for managing storage of indexed machine data in one or more indexes of a machine data processing system;

receiving, by the server computer via the one or more user editable interactive elements of the index management GUI, the one or more user specified index settings;

generating, by the server computer, an index configuration file including an index definition comprising a user specified manner in which to index incoming raw machine data that is subsequently received by the machine data processing system to generate indexed machine data that is searchable data in the one or more indexes of the machine data processing system, the user specified manner corresponding to the one or more user specified index settings; and

automatically causing, by the server computer via a network, distributing of the index configuration file in a hierarchical manner to two or more indexers of the machine data processing system that causes the index definition to be synchronized on the two or more indexers, wherein the distributing of the index configuration file is a single distribution of the index definition that effectuates a first change in association with a first indexer of the two or more indexers and a second change in association with a second indexer of the two or more indexers, and causes the two or more indexers to index the raw machine data in accordance with the index definition to generate the indexed machine data, wherein the distributing comprises pushing the index configuration file to a master node of at least one of the first indexer and the second indexer, the master node being part of the machine data processing system.

28. The computer-readable media of claim 27 , wherein the pushing of the index configuration file is to a first master node of the first indexer and a second master node of the second indexer, the first master node and the second master node each being part of the machine data processing system.

29. The computer-readable media of claim 27 , wherein the distributing of the index configuration file comprises providing the index configuration file to a first cluster of indexers comprising the first indexer and a second cluster of indexers comprising the second indexer.

30. The computer-readable media of claim 27 , wherein the distributing of the index configuration file is to a master node indexer of a cluster comprising the first indexer, and the master node indexer distributes the configuration file to a plurality of nodes of the cluster.

31. The computer-readable media of claim 27 , wherein the distributing of the index configuration file causes a search head of a cluster of indexers comprising the first indexer to use the index definition to distribute search tasks on the indexed machine data to at least some of the indexers of the cluster and merge search results of the search tasks from the at least some of the indexers.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2015
From: MUNK, ALEXANDER D.; OGDIN, PATRICK LANE
To: SPLUNK INC.
Reel/Frame 034876/0095 →