IP Library Granted Patent US 10,242,086
Granted Patent B2
US 10,242,086 · App. 15/143,581 · Granted Mar 26, 2019

Identifying system performance patterns in machine data

Inventors: Michael Joseph Baum (Ross, CA); R. David Carasso (San Rafael, CA); Robin Kumar Das (Healdsburg, CA); Bradley Hall (Palo Alto, CA); Brian Philip Murphy (London, GB); Stephen Phillip Sorkin (San Francisco, CA); Andre David Stechert (Brooklyn, NY); Erik M. Swan (Piedmont, CA); Rory Greene (San Francisco, CA); Nicholas Christian Mealy (Oakland, CA); Christina Frances Regina Noren (San Francisco, CA)
Assignee: Splunk Inc.
G06F17/30598G06F17/2785G06F17/30368G06F17/30477G06F17/30507G06F17/30525G06F17/30551G06F17/30604G06F17/30619G06F17/30705G06K9/6217H04L63/1425H04L63/20G06F11/3476G06F17/30657
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,242,086
App. No.
15/143,581
Filed
Apr 30, 2016
Granted
Mar 26, 2019
Kind
B2
Art Unit
2194
USPC
707/736
Abstract

Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.

Claims (46)

1. A method for improving machine data analysis, comprising:

receiving machine data from two or more components in an information technology environment, the received machine data reflecting activity in the information technology environment;

recording, in real-time, behavioral patterns among machine data from two or more different components among the two or more components in the information technology environment, the machine data among the received machine data;

learning, in real-time, new types of associative relationships between the behavioral patterns based on the co-occurrence of events within a time window bounded by a window threshold, wherein the window threshold changes based on data density or an amount of time available to complete the learning;

analyzing the associative relationships to identify one or more associative relationships that frequently occur, wherein the one or more associative relationships that frequently occur are identified as representing typical system behavior in the information technology environment;

wherein the method is performed by one or more computing devices.

2. The method as recited in claim 1 , wherein one or more other associative relationships of the associative relationships are identified as anomalous system behavior.

3. The method as recited in claim 1 , wherein machine data produced from a first component of the two or more components has a different data format than machine data produced from a second data component of the two or more components.

4. The method as recited in claim 1 , wherein learning, in real-time, new types of associative relationships further comprises:

analyzing machine data from the two or more components to identify a relationship between portions of machine data.

5. The method as recited in claim 1 , wherein learning, in real-time, new types of associative relationships further comprises:

analyzing machine data from the two or more components to identify a relationship between portions of machine data;

linking the related portions of machine data to each other.

6. The method as recited in claim 1 , further comprising:

analyzing the received machine data in order to segment the machine data into a plurality of events by determining a beginning and ending of each event in the plurality of events in the received machine data, each event in the plurality of events including a portion of the received machine data segmented for that event.

7. The method as recited in claim 1 , further comprising:

analyzing the received machine data in order to segment the machine data into a plurality of events by determining a beginning and ending of each event in the plurality of events in the received machine data, each event in the plurality of events including a portion of the received machine data segmented for that event;

associating a time stamp with each event in the plurality of events, the time stamp derived from received machine data included in that event.

8. The method as recited in claim 1 , wherein one or more other associative relationships of the associative relationships are identified as deviations from typical system behavior.

9. An apparatus for improving machine data analysis, comprising:

a machine data receiving device, implemented at least partially in hardware, that receives machine data from two or more components in an information technology environment, the received machine data reflecting activity in the information technology environment;

a real-time behavioral pattern recorder device, implemented at least partially in hardware, that records, in real-time, behavioral patterns among machine data from two or more different components among the two or more components in the information technology environment, the machine data among the received machine data;

a real-time learning device, implemented at least partially in hardware, that learns, in real-time, new types of associative relationships between the behavioral patterns based on the co-occurrence of events within a time window bounded by a window threshold, wherein the window threshold changes based on data density or an amount of time available to complete the learning;

wherein the real-time learning device analyzes the associative relationships to identify one or more associative relationships that frequently occur;

wherein the one or more associative relationships that frequently occur are identified as representing typical system behavior in the information technology environment.

10. The apparatus as recited in claim 9 , wherein one or more other associative relationships of the associative relationships are identified as anomalous system behavior.

11. The apparatus as recited in claim 9 , wherein machine data produced from a first component of the one or more components has a different data format than machine data produced from a second data component of the two or more components.

12. The apparatus as recited in claim 9 , wherein one or more other associative relationships of the associative relationships are identified as deviations from typical system behavior.

13. One or more non-transitory computer-readable storage media, storing software instructions for improving machine data analysis, which when executed by one or more processors cause performance of:

receiving machine data from two or more components in an information technology environment, the received machine data reflecting activity in the information technology environment;

recording, in real-time, behavioral patterns among machine data from two or more different components among the two or more components in the information technology environment, the machine data among the received machine data;

learning, in real-time, new types of associative relationships between the behavioral patterns based on the co-occurrence of events within a time window bounded by a window threshold, wherein the window threshold changes based on data density or an amount of time available to complete the learning;

analyzing the associative relationships to identify one or more associative relationships that frequently occur, wherein the one or more associative relationships that frequently occur are identified as representing typical system behavior in the information technology environment.

14. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein one or more other associative relationships of the associative relationships are identified as anomalous system behavior.

15. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein machine data produced from a first component of the two or more components has a different data format than machine data produced from a second data component of the two or more components.

16. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein learning, in real-time, new types of associative relationships further comprises:

analyzing machine data from the two or more components to identify a relationship between portions of machine data.

17. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein learning, in real-time, new types of associative relationships further comprises:

analyzing machine data from the two or more components to identify a relationship between portions of machine data;

linking the related portions of machine data to each other.

18. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein the instructions, when executed by the one or more computing devices, further cause performance of:

analyzing the received machine data in order to segment the machine data into a plurality of events by determining a beginning and ending of each event in the plurality of events in the received machine data, each event in the plurality of events including a portion of the received machine data segmented for that event.

19. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein the instructions, when executed by the one or more computing devices, further cause performance of:

analyzing the received machine data in order to segment the machine data into a plurality of events by determining a beginning and ending of each event in the plurality of events in the received machine data, each event in the plurality of events including a portion of the received machine data segmented for that event;

associating a time stamp with each event in the plurality of events, the time stamp derived from received machine data included in that event.

20. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein one or more other associative relationships of the associative relationships are identified as deviations from typical system behavior.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2017
From: BAUM, MICHAEL JOSEPH; CARASSO, R. DAVID; DAS, ROBIN KUMAR; HALL, BRADLEY; MURPHY, BRIAN PHILIP; SORKIN, STEPHEN PHILLIP; STECHERT, ANDRE DAVID; SWAN, ERIK M.; GREENE, RORY; MEALY, NICHOLAS CHRISTIAN; NOREN, CHRISTINA
To: SPLUNK INC.
Reel/Frame 042276/0454 →
Continuity (7)
Continuation 14611191 · Jan 31, 2015
Continuation 14170228 · Jan 31, 2014
Continuation 13664109 · Oct 30, 2012
Continuation 13099268 · May 2, 2011
Continuation 11459632 · Jul 24, 2006
Provisional Application 60702496 · Jul 25, 2005
Related Publication 20160246873A1 · Aug 25, 2016