IP Library › Granted Patent US 11,113,342
Granted Patent B2
US 11,113,342 · App. 15/663,596 · Granted Sep 7, 2021

Techniques for compiling and presenting query results

Inventor: Ramesh Panuganty (Cupertino, CA)
Assignee: SPLUNK INC.
G06F16/951
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,113,342
App. No.
15/663,596
Filed
Jul 28, 2017
Granted
Sep 7, 2021
Kind
B2
Art Unit
2167
USPC
707/710
Abstract

Improved crawling and curation of data and metadata from diverse data sources is described. In some embodiments, improvements are achieved by interpreting the context, vocabulary and relationships of data element, to enable relational data search capability for users. The user querying process is improved by systematic identification of the data objects, context, and relationships across data objects and elements, aggregation methods and operators on the data objects and data elements as identified in the curation process. User query suggestions and recommendations can be adjusted based on the context, relationships between the data elements, user profile, and the data sources. When the user query is executed, the query text is translated into an equivalent of one or more query statements, such as SQL or PostGre statements, and the query is performed on the identified data sources. Results are assembled to present the answer in a meaningful visualization for the user query.

Claims (38)

1. A system comprising:

a memory including instructions; and

a processor that is coupled to the memory and, when executing the instructions, is configured to perform the steps of:

identifying one or more anomalies in monitored data and associated with a natural language search query based on the monitored data satisfying at least one threshold, wherein the at least one threshold is determined based on one or more patterns associated with a plurality of related attributes in the monitored data; and

presenting, along with one or more results to the natural language search query, the one or more anomalies and at least one action or recommendation associated with the one or more anomalies.

2. The system as described in claim 1 , wherein the processor, when executing the instructions, is further configured to perform the steps of detecting critical anomalies and, responsive to detecting the critical anomalies, executing one or more remediation actions.

3. The system as described in claim 1 , wherein the processor, when executing the instructions, is further configured to provide an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and at least some of the data sources are public data sources.

4. The system as described in claim 1 , wherein the processor, when executing the instructions, is further configured to provide an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and at least some of the data sources are non-public data sources.

5. The system as described in claim 1 , wherein the processor, when executing the instructions, is further configured to provide an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and the data sources comprise relational data sources and non-relational data sources.

6. The system as described in claim 1 , wherein the processor, when executing the instructions, is further configured to provide an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and providing the ability to search or filter services or associated data sources comprises providing related searches associated with the previously-occurred anomalies.

7. The system as described in claim 1 , wherein the processor, when executing the instructions, is further configured to provide an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and providing the ability to search or filter services or associated data sources comprises providing one or more filters based on the threshold.

8. The system as described in claim 7 , wherein the one or more filters comprise a range filter.

9. The system as described in claim 7 , wherein the one or more filters comprise a minimum or maximum value filter.

10. The system as described in claim 1 , wherein the processor, when executing the instructions, is further configured to aggregate and identify correlated data to present suggestions to a user associated with the natural language query, and the correlated data have a parent-child relationship.

11. A computer-implemented method, comprising:

identifying one or more anomalies in monitored data and associated with a natural language search query based on the monitored data satisfying at least one threshold, wherein the at least one threshold is determined based on one or more patterns associated with a plurality of related attributes in the monitored data; and

presenting, along with one or more results to the natural language search query, the one or more anomalies and at least one action or recommendation associated with the one or more anomalies.

12. A method as described in claim 11 , further comprising detecting critical anomalies and, responsive to detecting the critical anomalies, executing one or more remediation actions.

13. A method as described in claim 11 , further comprising providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, wherein at least some of the data sources are public data sources.

14. A method as described in claim 11 , further comprising providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, wherein at least some of the data sources are non-public data sources.

15. A method as described in claim 11 , further comprising providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, wherein the data sources comprise relational data sources and non-relational data sources.

16. A method as described in claim 11 , further comprising providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, wherein providing the ability to search or filter services or associated data sources comprises providing related searches associated with the previously-occurred anomalies.

17. A method as described in claim 11 , further comprising providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, wherein providing the ability to search or filter services or associated data sources comprises providing one or more filters based on the threshold.

18. A method as described in claim 17 , wherein the one or more filters comprise a range filter.

19. A method as described in claim 17 , wherein the one or more filters comprise a minimum or maximum value filter.

20. A method as described in claim 11 , further comprising aggregating and identifying correlated data to present suggestions to a user associated with a natural language query, wherein the correlated data have a parent-child relationship.

21. One or more computer-readable storage media storing instructions which, when executed by one or more processors, cause the one or more processors to perform operations comprising:

identifying one or more anomalies in monitored data and associated with a natural language search query based on the monitored data satisfying at least one threshold, wherein the at least one threshold is determined based on one or more patterns associated with a plurality of related attributes in the monitored data; and

presenting, along with one or more results to the natural language search query, the one or more anomalies and at least one action or recommendation associated with the one or more anomalies.

22. The one or more computer-readable storage media as described in claim 21 , wherein the operations further comprise detecting critical anomalies and, responsive to detecting the critical anomalies, executing one or more remediation actions.

23. The one or more computer-readable storage media as described in claim 21 , wherein the operations further comprise providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and at least some of the data sources are public data sources.

24. The one or more computer-readable storage media as described in claim 21 , wherein the operations further comprise providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and at least some of the data sources are non-public data sources.

25. The one or more computer-readable storage media as described in claim 21 , wherein the operations further comprise providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and the data sources comprise relational data sources and non-relational data sources.

26. The one or more computer-readable storage media as described in claim 21 , wherein the operations further comprise providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and providing the ability to search or filter services or associated data sources comprises providing related searches associated with the previously-occurred anomalies.

27. The one or more computer-readable storage media as described in claim 21 , wherein the operations further comprise providing an ability to search or filter servers or associated data sources by referencing previously-occurred anomalies, and providing the ability to search or filter services or associated data comprises providing one or more filters based on the threshold.

28. The one or more computer-readable storage media as described in claim 27 , wherein the one or more filters comprise a range filter.

29. The one or more computer-readable storage media as described in claim 27 , wherein the one or more filters comprise a minimum or maximum value filter.

30. The one or more computer-readable storage media as described in claim 21 , wherein the operations further comprise aggregating and identifying correlated data to present suggestions to a user associated with a natural language query, and the correlated data have a parent-child relationship.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: PANUGANTY, RAMESH
To: DRASTIN, INC.
Reel/Frame 043153/0205 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: DRASTIN, INC.
To: SPLUNK INC.
Reel/Frame 043153/0433 →
Continuity (3)
Continuation 15188769 · Jun 21, 2016
Provisional Application 62183194 · Jun 23, 2015
Related Publication 20170329854A1 · Nov 16, 2017