IP Library Granted Patent US 10,565,263
Granted Patent B2
US 10,565,263 · App. 15/421,382 · Granted Feb 18, 2020

GUI-triggered processing of performance data and log data from an information technology environment

Inventors: Brian Bingham (Denver, CO); Tristan Fletcher (Pleasant Hill, CA); Alok Anant Bhide (Mountain View, CA)
Assignee: SPLUNK INC.
G06F16/9038G06F3/0482G06F3/04847G06F16/2477G06F16/334G06F16/90335
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,565,263
App. No.
15/421,382
Granted
Feb 18, 2020
Kind
B2
Abstract

The disclosed system and method acquire and store performance measurements relating to performance of a component in an information technology (IT) environment and log data produced by the IT environment, in association with corresponding time stamps. The disclosed system and method correlate at least one of the performance measurements with at least one of the portions of log data.

Claims (79)

1. A method comprising:

acquiring, by a computer system, a plurality of performance measurements for a performance metric associated with at least one hardware or software component of an information technology (IT) environment, the plurality of performance measurements acquired from a third-party software application that collects the performance measurements;

acquiring, by the computer system, a plurality of portions of log data representing activity of the at least one hardware or software component of the IT environment;

storing, by the computer system, the acquired performance measurements in a first time-series data store and the acquired portions of log data in a second time-series data store separate from the first time-series data store;

causing, by the computer system, display of a graphical user interface element;

inputting, by the computer system, a search criterion from a user via the graphical user interface element, the search criterion for use by the computer system as a portion of a search query;

generating, by the computer system, the search query in a search query language, the search query including the search criterion input via the graphical user interface; and

correlating, by the computer system, at least one of the performance measurements stored in the first time-series data store with at least one of the portions of log data stored in the second time-series data store, based on the search criterion, wherein said correlating includes

applying the search query, in the search query language and including the search criterion input via the graphical user interface element, to the performance measurements stored in the first time-series data store and portions of log data stored in the second time-series data store separate from the first time-series data store,

causing display of an indication of a performance measurement that satisfies the search criterion, and

causing display of an indication of a portion of log data from the at least one log file, that satisfies the search criterion.

2. A method as recited in claim 1 , wherein the search criterion is a time-based criterion.

3. A method as recited in claim 1 , wherein the search criterion is not a time-based criterion.

4. A method as recited in claim 1 , wherein the search criterion identifies a hardware or software component in the IT environment.

5. A method as recited in claim 1 , wherein the search criterion is a user-specified value or a user-specified range of values, for a user-specified field.

6. A method as recited in claim 1 , wherein said storing comprises:

storing the acquired performance measurements as time-stamped performance events and storing the acquired portions of log data as time-stamped log events, such that each performance event and each log event is stored in association with a respective time stamp.

7. A method as recited in claim 1 , wherein:

said storing comprises storing the acquired performance measurements as time-stamped performance events and storing the acquired portions of log data as time-stamped log events, such that each performance event and each log event is stored in association with a respective time stamp; and

said correlating further comprises identifying at least one of the stored performance events and at least one of the stored log events whose time stamps each satisfy a user-specified time criterion.

8. A method as recited in claim 1 , wherein said method comprises acquiring, by the computer system, a plurality of performance measurements for each of a plurality of performance metrics, the plurality of performance metrics associated with a plurality of components of the IT environment.

9. A method as recited in claim 1 , wherein said correlating comprises causing concurrent display of the performance measurements that satisfy the search criterion and a listing of raw log data that satisfy the search criterion.

10. A method as recited in claim 1 , wherein the graphical user interface element is one of a drop-down selection list, a slider or a checkbox.

11. A method as recited in claim 1 , further comprising:

obtaining a second search criterion by a user input to a drop-down list in a graphical user interface, wherein the second search criterion relates to a machine in the IT environment;

wherein said correlating further comprises identifying a performance measurement and a portion of log data that both satisfy the second search criterion.

12. A method as recited in claim 1 , wherein said storing comprises storing each of the acquired performance measurements and each of the acquired portions of log data with a time-stamp in a time-series data store;

said correlating comprises identifying at least one of the stored performance measurements and at least one of the stored portions of log data that have time stamps that satisfy a user-specified time criterion.

13. A method as recited in claim 1 , wherein the performance measurements have been determined by direct measurement of a hardware or software component in the IT environment.

14. A method as recited in claim 1 , wherein the plurality of portions of log data are from a text-based log file.

15. A method as recited in claim 1 , wherein the plurality of performance measurements are not derived from a log file and are acquired independently of the plurality of portions of log data.

16. A method as recited in claim 1 , wherein the plurality of performance measurements are acquired independently of the plurality of portions of log data, and wherein the performance measurements have been determined by direct measurement of a hardware or software component in the IT environment and the plurality of portions of log data are from a text-based log file.

17. A method as recited in claim 1 , wherein the plurality of performance measurements are acquired independently of the plurality of portions of log data by direct measurement of a hardware or software component in the IT environment, and the plurality of portions of log data are acquired independently of the performance measurements.

18. A method as recited in claim 1 , wherein the performance measurements are stored in a time-series data store in a first format, and the portions of log data are stored in said time-series data store in a second format different from the first format.

19. A method as recited in claim 1 , wherein the performance measurements are stored in a first time-series data store in a first format, and the portions of log data are stored in a second time-series data store separate from the first time-series data store in a second format different from the first format.

20. A method as recited in claim 1 , wherein:

the performance measurements are stored in a first time-series data store in a first format, and the portions of log data are stored in a second time-series data store separate from the first time-series data store in a second format different from the first format; and

said correlating includes, in response to the user-specified search query, searching the first time-series data store for performance data that satisfy the search criterion and searching the second time-series data store for log data that satisfy the search criterion.

21. A method as recited in claim 1 , wherein:

the performance measurements are stored in a first time-series data store and the portions of log data are stored in a second time-series data store separate from the first time-series data store;

the performance measurements and portions of log data are stored in the first and second time-series data stores, respectively, in different formats;

the search criterion comprises a user-specified value or a user-specified range of values, for a user-Specified field; and

said correlating includes, in response to the user-specified search query, searching the first time-series data store for performance data that satisfy the search criterion and searching the second time-series data store for log data that satisfy the search criterion.

22. A method as recited in claim 1 , further comprising:

acquiring structure data indicative of structure characteristics of the IT environment;

storing the acquired structure data indicative of structure characteristics of the IT environment; and

correlating a performance characteristic of the IT environment with a structure characteristic of the IT environment, based on the stored performance measurements and stored structure data.

23. A method as recited in claim 1 , further comprising:

acquiring structure data indicative of structure characteristics of the IT environment, wherein the structure data is derived from log data from the IT environment;

storing the acquired structure data indicative of structure characteristics of the IT environment; and

correlating a performance characteristic of the IT environment with a structure characteristic of the IT environment, based on the stored performance measurements and stored structure data.

24. A method as recited in claim 1 , wherein the performance metric comprises a performance metric for at least one hardware or software resource of a computer system.

25. A method as recited in claim 1 , wherein the performance metric comprises a performance metric for at least one virtual machine or virtual machine host.

26. A method as recited in claim 1 , wherein the performance metric comprises a performance metric for a virtual machine cluster.

27. A non-transitory machine-readable storage medium for use in a processing system of a data intake and query system, the non-transitory machine-readable storage medium storing instructions, an execution of which in the processing system causes the processing system to perform operations comprising:

acquiring, by a computer system, a plurality of performance measurements for a performance metric associated with at least one hardware or software component of an information technology (IT) environment, the plurality of performance measurements acquired from a third-party software application that collects the performance measurements;

acquiring, by the computer system, a plurality of portions of log data representing activity of the at least one hardware or software component of the IT environment;

storing, by the computer system, the acquired performance measurements in a first time-series data store and the acquired portions of log data in a second time-series data store separate from the first data store;

causing, by the computer system, display of a graphical user interface element;

inputting, by the computer system, a search criterion from a user via the graphical user interface element, the search criterion for use by the computer system as a portion of a search query;

generating, by the computer system, the search query in a search query language, the search query including the search criterion input via the graphical user interface; and

correlating, by the computer system, at least one of the performance measurements stored in the first time-series data store with at least one of the portions of log data stored in the second time-series data store, based on the search criterion, wherein said correlating includes

applying the search query, in the search query language and including the search criterion input via the graphical user interface element, to the performance measurements stored in the first time-series data store and portions of log data stored in the second time-series data store separate from the first time-series data store,

causing display of an indication of a performance measurement that satisfies the search criterion, and

causing display of an indication of a portion of log data from the at least one log file, that satisfies the search criterion.

28. A system comprising:

a communication device through which to communicate on a computer network;

and

at least one processor operatively coupled to the communication device and configured to perform operations including

acquiring, by a computer system, a plurality of performance measurements for a performance metric associated with at least one hardware or software component of an information technology (IT) environment, the plurality of performance measurements acquired from a third-party software application that collects the performance measurements;

acquiring, by the computer system, a plurality of portions of log data representing activity of the at least one hardware or software component of the IT environment;

storing, by the computer system, the acquired performance measurements in a first time-series data store and the acquired portions of log data in a second time-series data store separate from the first data store;

causing, by the computer system, display of a graphical user interface element;

inputting, by the computer system, a search criterion from a user via the graphical user interface element, the search criterion for use by the computer system as a portion of a search query;

generating, by the computer system, the search query in a search query language, the search query including the search criterion input via the graphical user interface; and

correlating, by the computer system, at least one of the performance measurements stored in the first time-series data store with at least one of the portions of log data stored in the second time-series data store, based on the search criterion, wherein said correlating includes

applying the search query, in the search query language and including the search criterion input via the graphical user interface element, to the performance measurements stored in the first time-series data store and portions of log data stored in the second time-series data store separate from the first time-series data store,

causing display of an indication of a performance measurement that satisfies the search criterion, and

causing display of an indication of a portion of log data from the at least one log file, that satisfies the search criterion.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2017
From: BINGHAM, BRIAN; FLETCHER, TRISTAN; BHIDE, ALOK ANANT
To: SPLUNK INC.
Reel/Frame 042739/0890 →
Continuity (16)
Continuation In Part 14167316 · Jan 29, 2014
Continuation In Part 13874423 · Apr 30, 2013
Continuation In Part 13874434 · Apr 30, 2013
Continuation In Part 13874441 · Apr 30, 2013
Continuation In Part 13874448 · Apr 30, 2013
Continuation In Part 14801721 · Jul 16, 2015
Continuation 14253548 · Apr 15, 2014
Continuation In Part 14167316 · Jan 29, 2014
Continuation In Part 13874423 · Apr 30, 2013
Continuation In Part 13874434 · Apr 30, 2013
Continuation In Part 13874441 · Apr 30, 2013
Continuation In Part 13874448 · Apr 30, 2013
Provisional Application 61883869 · Sep 27, 2013
Provisional Application 61900700 · Nov 6, 2013
Provisional Application 61979484 · Apr 14, 2014
Related Publication 20170169134A1 · Jun 15, 2017