IP Library Granted Patent US 11,392,582
Granted Patent B2
US 11,392,582 · App. 15/293,007 · Granted Jul 19, 2022

Automatic partitioning

Inventors: Kumar Saurabh (Menlo Park, CA); Christian Friedrich Beedgen (San Carlos, CA)
Assignee: Sumo Logic, Inc.
G06F16/2425G06F16/24534G06F16/313G06F16/3334
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,392,582
App. No.
15/293,007
Granted
Jul 19, 2022
Kind
B2
Abstract

Automatic partitioning is disclosed. A set of previously run queries is obtained. The set of previously run queries is analyzed to determine one or more query fragments from the set of previously run queries. One or more partitions are generated at least in part by using the obtained query fragments.

Claims (50)

1. A system, comprising:

one or more processors configured to:

receive a set of previously run queries for selecting logs from log data, each log comprising data collected during operation of one or more computer systems;

determine a set of query fragments contained in the set of previously run queries, wherein at least one query fragment in the set of query fragments includes less than all words in one of the previously run queries;

access a set of logs in the log data;

for each log in the set of logs:

determine which query fragments, in the set of query fragments, are contained in the log; and

generate a bitset for the log based on the query fragments contained in the log, wherein each bit in the bitset corresponds to one query fragment in the set of query fragments, wherein each bit in the bitset indicates whether the log contains the query fragment associated with the bit;

for each generated bitset, determine a number of logs in the set of logs that match the bitset;

for each generated bitset, based on the determined number of logs for the bitset, generate a partition in the log data for the logs having the bitset, wherein logs having the bitset are placed in the partition; and

index the logs in the log data belonging to the partition; and

a memory coupled to the one or more processors and configured to provide the one or more processors with instructions.

2. The system of claim 1 , wherein the set of query fragments comprises fragments of queries determined to be common among the set of previously run queries.

3. The system of claim 2 , wherein a query fragment is determined to be common based at least in part on an analysis of a frequency of occurrence of the query fragment in the set of previously run queries.

4. The system of claim 1 , wherein the one or more processors are further configured to perform partition rebuilding.

5. The system of claim 4 , wherein the partition rebuilding is performed periodically.

6. The system of claim 4 , wherein the partition rebuilding is performed based at least in part on an evaluation of a second set of previously run queries.

7. The system of claim 1 , wherein generating the partition includes evaluating a plurality of candidate partition sets.

8. The system of claim 7 , wherein evaluating the plurality of candidate partition sets includes estimating a cost associated with building a given candidate partition set.

9. The system of claim 7 , wherein evaluating the plurality of candidate partition sets includes analyzing a savings associated with building a given candidate partition set.

10. The system of claim 1 , wherein indexing the logs in the log data includes, for each log:

determining that the log has the bitset associated with the partition; and

adding the log to the partition in response to the determination.

11. The system of claim 1 , wherein the one or more processors are further configured to receive a query for log data.

12. The system of claim 11 , wherein the one or more processors are further configured to rewrite the query based at least in part on the generated partition.

13. The system of claim 12 , wherein the one or more processors are further configured to use the rewritten query to search the generated partition.

14. The system of claim 1 wherein the one or more processors are further configured to:

determine a partition recommendation based at least in part on the set of query fragments;

provide the partition recommendation to a user for review; and

receive user input indicating approval of the partition recommendation, wherein the partition is generated based on the received user approval.

15. A method, comprising:

receiving a set of previously run queries for selecting logs from log data, each log comprising data collected during operation of one or more computer systems;

determining a set of query fragments contained in the set of previously run queries, wherein at least one query fragment in the set of query fragments includes less than all words in one of the previously run queries;

accessing a set of logs in the log data;

for each log in the set of logs:

determining which query fragments, in the set of query fragments, are contained in the log; and

generating a bitset for the log based on the query fragments contained in the log, wherein each bit in the bitset corresponds to one query fragment in the set of query fragments, wherein each bit in the bitset indicates whether the log contains the query fragment associated with the bit;

for each generated bitset, determine a number of logs in the set of logs that match the bitset;

for each generated bitset, based on the determined number of logs for each bitset, generating, using one or more processors, a partition in the log data for the logs having the bitset, wherein logs having the bitset are placed in the partition; and

indexing the logs in the log data belonging to the partition.

16. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a set of previously run queries for selecting logs from log data, each log comprising data collected during operation of one or more computer systems;

determining a set of query fragments contained in the set of previously run queries, wherein at least one query fragment in the set of query fragments includes less than all words in one of the previously run queries;

accessing a set of logs in the log data;

for each log in the set of logs:

determining which query fragments, in the set of query fragments, are contained in the log; and

generating a bitset for the log based on the query fragments contained in the log, wherein each bit in the bitset corresponds to one query fragment in the set of query fragments, wherein each bit in the bitset indicates whether the log contains the query fragment associated with the bit;

for each generated bitset, determine a number of logs in the set of logs that match the bitset;

for ach generated bitset, based on the determined number of logs for each bitset, generating a partition in the log data for the logs having the bitset, wherein logs having the bitset are placed in the partition; and

indexing the logs in the log data belonging to the partition.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded May 12, 2023
From: SUMO LOGIC, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS COLLATERAL AGENT
Reel/Frame 063633/0648 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF ASSIGNEE TO SUMO LOGIC, INC. PREVIOUSLY RECORDED AT REEL: 041092 FRAME: 0057. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 27, 2021
From: SAURABH, KUMAR; BEEDGEN, CHRISTIAN FRIEDRICH
To: SUMO LOGIC, INC.
Reel/Frame 057335/0953 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2017
From: SAURABH, KUMAR; BEEDGEN, CHRISTIAN FRIEDRICH
To: SUMO LOGIC
Reel/Frame 041092/0057 →
Continuity (4)
Provisional Application 62367033 · Jul 26, 2016
Provisional Application 62265942 · Dec 10, 2015
Provisional Application 62241932 · Oct 15, 2015
Related Publication 20170132276A1 · May 11, 2017