IP Library Granted Patent US 9,984,129
Granted Patent B2
US 9,984,129 · App. 14/815,974 · Granted May 29, 2018

Managing data searches using generation identifiers

Inventors: Vishal Patel (San Francisco, CA); Mitchell Neuman Blank, Jr. (San Francisco, CA); Sundar Renegarajan Vasan (San Francisco, CA); Stephen Phillip Sorkin (San Francisco, CA)
Assignee: SPLUNK INC.
G06F17/30528G06F11/20G06F11/2094G06F17/3087G06F17/30241G06F17/30336G06F17/30575G06F17/30581G06F17/30867H04L67/1097G06F3/065G06F3/067G06F3/0617
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,984,129
App. No.
14/815,974
Granted
May 29, 2018
Kind
B2
Abstract

Embodiments are directed towards managing within a cluster environment having a plurality of indexers for data storage using redundancy the data being managed using a generation identifier, such that a primary indexer is designated for a given generation of data. When a master device for the cluster fails, data may continue to be stored using redundancy, and data searches performed may still be performed.

Claims (74)

1. A method, comprising:

identifying, at a master device of a cluster, a set of data, wherein data in the set of data comprise time stamps within a particular time frame, wherein the cluster comprises the master device and a set of indexers, wherein the master device is operable to coordinate a status of each indexer in the set of indexers;

creating, by the master device, a first generation identifier associated with the set of data;

sending, by the master device, an indication to a first indexer of the set of indexers that

the first generation identifier indicates to the first indexer that the first indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the first indexer that pertains to the set of data that is associated with the first generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the first generation identifier, and wherein each indexer of the set of indexers is operable to store multiple subsets of data, and wherein each subset of data can be replicated across one or more indexers in the set of indexers; and

indicating, by the master device, to a search head that the search head is to include the first generation identifier in a query sent to indexers pertaining to the set of data, wherein the search head is operable to communicate with the master device and further operable to broadcast queries to the set of indexers to perform searches on data managed by the cluster.

2. The method of claim 1 , further comprising:

creating, by the master device, a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier;

sending, by the master device, an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier; and

indicating, by the master device, to a second search head that the second search head is to include the second generation identifier in a query sent to indexers pertaining to the set of data, wherein the second search head is operable to communicate with the master device and further operable to broadcast queries to the set of indexers to perform searches on data managed by the cluster.

3. The method of claim 1 , further comprising:

creating, by the master device, a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier; and

sending, by the master device, an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier,

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for the set of data in different geographical areas.

4. The method of claim 1 , further comprising:

creating, by the master device, a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier;

sending, by the master device, an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier,

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for the set of data in different geographical areas; and

indicating, by the master device, to a second search head that the second search head is to include the second generation identifier in a query sent to indexers pertaining to the set of data, wherein the second search head is operable to communicate with the master device and further operable to broadcast queries to the set of indexers to perform searches on data managed by the cluster.

5. The method of claim 1 , further comprising:

creating, by the master device, a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier; and

sending, by the master device, an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier,

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for different types of searches on the set of data.

6. The method of claim 1 , wherein a generation identifier indicates to an indexer that the indexer is the primary indexer for all sets of data that the indexer has access to.

7. The method of claim 1 , wherein an indexer is the primary indexer for a plurality of sets of data that the indexer has access to and the indexer has a different generation identifier associated with each set of data in the plurality of sets of data.

8. An apparatus, comprising:

a data set identifier, at a master device of a cluster, implemented at least partially in hardware, that identifies a set of data, wherein data in the set of data comprise time stamps within a particular time frame, wherein the cluster comprises the master device and a set of indexers, wherein the master device is operable to coordinate a status of each indexer in the set of indexers;

a generation identifier creator, at the master device, implemented at least partially in hardware, that creates a first generation identifier associated with the set of data;

an indexer communicator, at the master device, implemented at least partially in hardware, that sends an indication to a first indexer of the set of indexers that the first generation identifier indicates to the first indexer that the first indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the first indexer that pertains to the set of data that is associated with the first generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the first generation identifier, and wherein each indexer of the set of indexers is operable to store multiple subsets of data, and wherein each subset of data can be replicated across one or more indexers in the set of indexers;

a search head communicator, at the master device, implemented at least partially in hardware, that indicates to a search head that the search head is to include the first generation identifier in a query sent to indexers pertaining to the set of data, wherein the search head is operable to communicate with the master device and further operable to perform searches on data managed by the cluster.

9. The apparatus of claim 8 ,

wherein the generation identifier creator creates a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier,

wherein the indexer communicator sends an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier, and

wherein the search head communicator indicates to a second search head that the second search head is to include the second generation identifier in a query sent to indexers pertaining to the set of data, wherein the second search head is operable to communicate with the master device and further operable to broadcast queries to the set of indexers to perform searches on data managed by the cluster.

10. The apparatus of claim 8 ,

wherein the generation identifier creator creates a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier,

wherein the indexer communicator sends an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier, and

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for the set of data in different geographical areas.

11. The apparatus of claim 8 ,

wherein the generation identifier creator creates a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier,

wherein the indexer communicator sends an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier,

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for the set of data in different geographical areas, and

wherein the search head communicator indicates to a second search head that the second search head is to include the second generation identifier in a query sent to indexers pertaining to the set of data, wherein the second search head is operable to communicate with the master device and further operable to broadcast queries to the set of indexers to perform searches on data managed by the cluster.

12. The apparatus of claim 8 ,

wherein the generation identifier creator creates a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier,

wherein the indexer communicator sends an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier, and

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for different types of searches on the set of data.

13. The apparatus of claim 8 , wherein a generation identifier indicates to an indexer that the indexer is the primary indexer for all sets of data that the indexer has access to.

14. The apparatus of claim 8 , wherein an indexer is the primary indexer for a plurality of sets of data that the indexer has access to and the indexer has a different generation identifier associated with each set of data in the plurality of sets of data.

15. One or more non-transitory computer-readable storage media, storing software instructions, which when executed by one or more processors cause performance of:

identifying, at a master device of a cluster, a set of data, wherein data in the set of data comprise time stamps within a particular time frame, wherein the cluster comprises the master device and a set of indexers, wherein the master device is operable to coordinate a status of each indexer in the set of indexers;

creating, by the master device, a first generation identifier associated with the set of data;

sending, by the master device, an indication to a first indexer of the set of indexers that

the first generation identifier indicates to the first indexer that the first indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the first indexer that pertains to the set of data that is associated with the first generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the first generation identifier, and wherein each indexer of the set of indexers is operable to store multiple subsets of data, and wherein each subset of data can be replicated across one or more indexers in the set of indexers; and

indicating, by the master device, to a search head that the search head is to include the first generation identifier in a query sent to indexers pertaining to the set of data, wherein the search head is operable to communicate with the master device and further operable to broadcast queries to the set of indexers to perform searches on data managed by the cluster.

16. The one or more non-transitory computer-readable storage media of claim 15 , wherein the instructions, when executed by the one or more computing devices, further cause performance of:

creating, by the master device, a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier;

sending, by the master device, an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier; and

indicating, by the master device, to a second search head that the second search head is to include the second generation identifier in a query sent to indexers pertaining to the set of data, wherein the second search head is operable to communicate with the master device and further operable to broadcast queries to the set of indexers to perform searches on data managed by the cluster.

17. The one or more non-transitory computer-readable storage media of claim 15 , wherein the instructions, when executed by the one or more computing devices, further cause performance of:

creating, by the master device, a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier; and

sending, by the master device, an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier,

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for the set of data in different geographical areas.

18. The one or more non-transitory computer-readable storage media of claim 15 , wherein the instructions, when executed by the one or more computing devices, further cause performance of:

creating, by the master device, a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier;

sending, by the master device, an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier,

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for the set of data in different geographical areas; and

indicating, by the master device, to a second search head that the second search head is to include the second generation identifier in a query sent to indexers pertaining to the set of data, wherein the second search head is operable to communicate with the master device and further operable to broadcast queries to the set of indexers to perform searches on data managed by the cluster.

19. The one or more non-transitory computer-readable storage media of claim 15 , wherein the instructions, when executed by the one or more computing devices, further cause performance of:

creating, by the master device, a second generation identifier associated with the set of data, the second generation identifier different from the first generation identifier; and

sending, by the master device, an indication to a second indexer among the set of indexers that the second generation identifier indicates to the second indexer that the second indexer is to serve as a primary indexer for responding to queries pertaining to the set of data with respect to a query received by the second indexer that pertains to the set of data that is associated with the second generation identifier, wherein other indexers among the set of indexers are configured to ignore queries pertaining to the set of data that include the second generation identifier,

wherein the first generation identifier and the second generation identifier indicate that the first indexer and the second indexer are primary indexers for different types of searches on the set of data.

20. The one or more non-transitory computer-readable storage media of claim 15 , wherein a generation identifier indicates to an indexer that the indexer is the primary indexer for all sets of data that the indexer has access to.

21. The one or more non-transitory computer-readable storage media of claim 15 , wherein an indexer is the primary indexer for a plurality of sets of data that the indexer has access to and the indexer has a different generation identifier associated with each set of data in the plurality of sets of data.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2018
From: PATEL, VISHAL; BLANK, MITCHELL NEUMAN, JR; VASAN, SUNDAR RENGARAJAN; SORKIN, STEPHEN PHILIP
To: SPLUNK INC.
Reel/Frame 045068/0584 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2018
From: VASAN, SUNDAR RENGARAJAN; BLANK, MITCHELL NEUMAN, JR; PATEL, VISHAL; XU, DA; GOPALAN, RAMA
To: SPLUNK INC.
Reel/Frame 045068/0721 →
Continuity (4)
Continuation 14266812 · Apr 30, 2014
Continuation In Part 13648116 · Oct 9, 2012
Provisional Application 61647245 · May 15, 2012
Related Publication 20150347523A1 · Dec 3, 2015