IP Library Granted Patent US 10,713,314
Granted Patent B2
US 10,713,314 · App. 15/011,361 · Granted Jul 14, 2020

Facilitating data model acceleration in association with an external data system

Inventors: Hailun Yan (Sunnyvale, CA); Ledion Bitincka (San Francisco, CA); Kishore Reddy Ramasayam (Sunnyvale, CA); Elizabeth Lin (San Francisco, CA); David Ryan Marquardt (San Francisco, CA)
Assignee: SPLUNK INC.
G06F16/9535G06F16/2455G06F16/28G06F16/288
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,713,314
App. No.
15/011,361
Granted
Jul 14, 2020
Kind
B2
Abstract

Embodiments are directed to facilitating data model acceleration in association with an external data system. In some embodiments, at a core engine, a search request associated with a data model is received. The data model generally designates one or more fields, from among a plurality of fields of interest for subsequent searches. Thereafter, it is determined that an accelerated data model summary associated with the data model is stored at an external data system remote from the core engine that received the search request. The accelerated data model summary includes field values associated with the one or more fields designated in the data model. A search for the received search request is initiated using the accelerated data model summary at the external data. A set of search results relevant to the search request is obtained and provided to a user device for display to a user.

Claims (48)

1. A computer-implemented method comprising:

receiving, at a core engine, a search request associated with a data model, the data model designating one or more fields, from among a plurality of fields, that are of interest for subsequent searches;

determining that an accelerated data model summary, of a dataset stored in an external data system, and associated with the data model is stored at the external data system, the external data system not under management of the core engine that received the search request, the accelerated data model summary organized into a columnar format comprising a plurality of data blocks, each data block adjacently storing values of a column of data from a subset of rows of the dataset, for a set of columns of the dataset corresponding to the one or more fields designated by the data model;

triggering the external data system to generate a set of search results relevant to the search request by causing the external data system to read data from the accelerated data model summary and execute a search of the data from the accelerated data model summary;

receiving the set of search results from the external data system; and

providing the set of search results to a user device for display to a user.

2. The computer-implemented method of claim 1 , wherein the search request comprises a tstats search command or a pivot search command.

3. The computer-implemented method of claim 1 , wherein triggering the external data system comprises communicating a search query to the external data system, the search query including search parameters.

4. The computer-implemented method of claim 1 , wherein the set of search results relevant to the search request are received from the external data system.

5. The computer-implemented method of claim 1 , wherein the set of search results are modified prior to being provided to the user device for display to the user.

6. The computer-implemented method of claim 1 further comprising:

determining one or more input splits to apply to the accelerated data model summary; and

assigning a map task for each of the one or more input splits, wherein the map task indicates a task to perform the search.

7. The computer-implemented method of claim 1 , wherein triggering the external data system comprises communicating a search query to the external data system along with an indication of the one or more input splits and corresponding map tasks.

8. The computer-implemented method of claim 1 , wherein the accelerated data model summary stores values of a column of raw data from the dataset in a corresponding row in the accelerated model data summary.

9. The computer-implemented method of claim 1 , wherein the accelerated data model summary is stored in association with raw data from the dataset from which the accelerated data model was generated.

10. The computer-implemented method of claim 1 further comprising:

determining that at least a portion of data to be searched is not within the accelerated data model summary; and

triggering the external data system to search for the received search request using the accelerated data model summary at the external data system and a set of raw data stored at the external data system, the set of raw data stored at the external data system being used only for the at least the portion of the data not within the accelerated data model summary.

11. The computer-implemented method of claim 1 further comprising:

determining that at least a portion of data to be searched is not within the accelerated data model summary;

determining one or more input splits to apply to a set of raw data stored at the external data system;

assigning a map task for each of the one or more input split to apply to the set of raw data; and

triggering the external data system to search for the received search request using the accelerated data model summary at the external data system and the set of raw data stored at the external data system, the set of raw data stored at the external data system being used only for the at least the portion of the data not within the accelerated data model summary.

12. The computer-implemented method of claim 1 , wherein a lookup system is used to determine that the accelerated data model summary associated with the data mode is stored at the external data system.

13. The computer-implemented method of claim 1 further comprising, in response to receiving the search request, referencing a lookup table to determine that the data model associated with the search request has been accelerated.

14. The computer-implemented method of claim 1 further comprising, prior to receiving the search request, initiating generation of the accelerated data model summary.

15. The computer-implemented method of claim 1 further comprising, prior to receiving the search request, initiating generation of the accelerated data model summary by:

receiving a request to accelerate the data model;

determining one or more input splits to apply to a set of raw data stored at the external data system;

assigning a map task for each of the one or more input splits to apply to the set of raw data, the map task specifying generation of the accelerated data model summary; and

providing an accelerated data model request to the external data system along with an indication of the one or more input splits to apply to the set of raw data and the corresponding map tasks.

16. The computer-implemented method of claim 1 , wherein generation of the accelerated data model summary is triggered by a user selection to accelerate the data model.

17. The computer-implemented method of claim 1 , wherein the external data system is configured to use the accelerated data model summary to search for the set of search results relevant to the search request.

18. One or more computer-readable storage media having instructions stored thereon, wherein the instructions, when executed by a computing device, cause the computing device to:

receive, at a core engine, a search request associated with a data model, the data model designating one or more fields, from among a plurality of fields, that are of interest for subsequent searches;

determine that an accelerated data model summary, of a dataset stored in an external data system, and associated with the data model is stored at the external data system, the external data system not under management of the core engine that received the search request, the accelerated data model summary organized into a columnar format comprising a plurality of data blocks, each data block adjacently storing values of a column of data from a subset of rows of the dataset, for a set of columns of the dataset corresponding to the one or more fields designated by the data model;

trigger the external data system to generate a set of search results relevant to the search request by causing the external data system to read data from the accelerated data model summary and execute a search of the data from the accelerated data model summary;

receive the set of search results from the external data system; and

provide the set of search results to a user device for display to a user.

19. A computing device comprising:

one or more processors; and

a memory coupled with the one or more processors, the memory having instructions stored thereon, wherein the instructions, when executed by the one or more processors, cause the computing device to:

receive, at a core engine, a search request associated with a data model, the data model designating one or more fields, from among a plurality of fields, that are of interest for subsequent searches;

determine that an accelerated data model summary, of a dataset stored in an external data system, and associated with the data model is stored at the external data system, the external data system not under management of the core engine that received the search request, the accelerated data model summary organized into a columnar format comprising a plurality of data blocks, each data block adjacently storing values of a column of data from a subset of rows of the dataset, for a set of columns of the dataset corresponding to the one or more fields designated by the data model;

trigger the external data system to generate a set of search results relevant to the search request by causing the external data system to read data from the accelerated data model summary and execute a search of the data from the accelerated data model summary;

receive the set of search results from the external data system; and

provide the set of search results to a user device for display to a user.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2016
From: YAN, HAILUN; BITINCKA, LEDION; RAMASAYAM, KISHORE REDDY; LIN, ELIZABETH; MARQUARDT, DAVID RYAN
To: SPLUNK INC.
Reel/Frame 037818/0207 →
Continuity (1)
Related Publication 20170220685A1 · Aug 3, 2017
Cited By (2)
US 12,292,870 US 12,608,366