IP Library Granted Patent US 10,142,412
Granted Patent B2
US 10,142,412 · App. 15/913,079 · Granted Nov 27, 2018

Multi-thread processing of search responses

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,142,412
App. No.
15/913,079
Granted
Nov 27, 2018
Kind
B2
Abstract

Multi-thread processing of search responses is disclosed. An example method may include transmitting, by a computer system, a search request to a plurality of search peers of a data aggregation and analysis system; receiving a plurality of data packets from the plurality of search peers; parsing, by a first processing thread of the computer system, one or more data packets of the plurality of data packets, to produce a partial response to the search request; and processing, by a second processing thread of the computer system, the partial response to produce a memory data structure representing an aggregated response to the search request.

Claims (43)

1. A method, comprising:

transmitting, by a computer system, a search request to a plurality of search peers of a data aggregation and analysis system;

receiving a plurality of data packets from the plurality of search peers;

parsing, by a first processing thread of the computer system, one or more data packets of the plurality of data packets, to produce a partial response to the search request; and

processing, by a second processing thread of the computer system, the partial response to produce a memory data structure representing an aggregated response to the search request.

2. The method of claim 1 , further comprising:

pre-processing the search request by replacing an identifier of a first function returning a first aggregated parameter with an identifier of a second function returning a second aggregated parameter.

3. The method of claim 1 , wherein receiving the plurality of data packets further comprises:

reading, in a non-blocking mode, data from one or more communication endpoints having at least one data packet available.

4. The method of claim 1 , wherein parsing the data packets is performed by two or more processing threads operating in parallel, wherein each processing thread of the two or more processing threads produces a respective partial response to the search request.

5. The method of claim 1 , wherein processing the partial response further comprises:

splitting the partial response into two or more parts based on at least one of: a defined set of bit position or a defined separator.

6. The method of claim 1 , wherein processing the partial response further comprises: encoding the partial response according to a defined encoding rule.

7. The method of claim 1 , wherein receiving the plurality of data packets from the plurality of search peers is performed by the first processing thread.

8. The method of claim 1 , wherein receiving the plurality of data packets from the plurality of search peers is performed by a third processing thread asynchronously with the respect to at least one of: the first processing thread or the second processing thread.

9. The method of claim 1 , wherein parsing the one or more data packets is performed in an order of receiving the data packets over a plurality of transport layer connections.

10. The method of claim 1 , wherein receiving the plurality of data packets is performed over a plurality of transport layer connections.

11. The method of claim 1 , further comprising:

writing the partial response to a message queue; and

responsive to determining that a total size of messages in the message queue exceeds a certain threshold, causing the first processing thread to suspend receiving data packets.

12. The method of claim 11 , further comprising:

responsive to determining that a total size of messages in the message queue falls below a certain threshold, notifying the first processing thread to resume receiving data packets.

13. The method of claim 1 , wherein each search peer of the plurality of search peers performs map operations of a map-reduce search, to return partial results based on a subset of source data.

14. The method of claim 1 , wherein the partial response comprises one or more events derived from time-series source data.

15. The method of claim 1 , wherein the method is performed by a search head that performs map operations of a map-reduce search.

16. A computer system, comprising:

a memory; and

one or more processing devices, coupled to the memory, to:

transmit a search request to a plurality of search peers of a data aggregation and analysis system;

receive a plurality of data packets from the plurality of search peers;

parse, by a first processing thread of the computer system, one or more data packets of the plurality of data packets, to produce a partial response to the search request; and

process, by a second processing thread of the computer system, the partial response to produce a memory data structure representing an aggregated response to the search request.

17. The system of claim 16 , wherein the one or more processing devices are further to:

write the partial response to a message queue; and

responsive to determining that a total size of messages in the message queue exceeds a certain threshold, cause the first processing thread to suspend receiving data packets.

18. The system of claim 16 , wherein the one or more processing devices are further to:

pre-process the search request by replacing an identifier of a first function returning a first aggregated parameter with an identifier of a second function returning a second aggregated parameter.

19. The system of claim 17 , wherein each search peer of the plurality of search peers performs map operations of a map-reduce search, to return partial results based on a subset of source data.

20. A computer-readable non-transitory storage medium comprising executable instructions that, when executed by a computer system, cause the computer system to:

transmit a search request to a plurality of search peers of a data aggregation and analysis system;

receive a plurality of data packets from the plurality of search peers;

parse, by a first processing thread of the computer system, one or more data packets of the plurality of data packets, to produce a partial response to the search request; and

process, by a second processing thread of the computer system, the partial response to produce a memory data structure representing an aggregated response to the search request.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2018
From: PAL, SOURAV; PRIDE, CHRISTOPHER MADDEN
To: SPLUNK INC.
Reel/Frame 045121/0236 →