IP Library Granted Patent US 11,010,390
Granted Patent B2
US 11,010,390 · App. 16/444,593 · Granted May 18, 2021

Using an electron process to determine a primary indexer for responding to search queries including generation identifiers

Inventors: Vishal Patel (San Francisco, CA); Mitchell Neuman Blank, Jr. (San Francisco, CA); Sundar Renegarajan Vasan (San Francisco, CA); Stephen Phillip Sorkin (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/24575G06F11/20G06F11/2094G06F16/2272G06F16/27G06F16/275G06F16/29G06F16/9535G06F16/9537H04L67/1097G06F3/065G06F3/067G06F3/0617
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,010,390
App. No.
16/444,593
Granted
May 18, 2021
Kind
B2
Abstract

Embodiments are directed towards managing within a cluster environment having a plurality of indexers for data storage using redundancy the data being managed using a generation identifier, such that a primary indexer is designated for a given generation of data. When a master device for the cluster fails, data may continue to be stored using redundancy, and data searches performed may still be performed.

Claims (71)

1. A computer-implemented method comprising:

generating, at a searcher device, a first query for a set of data for a plurality of indexers in a cluster, wherein the set of data comprises time-stamps within a particular time frame;

providing, with the first query, a first generation identifier for the set of data, wherein the first generation identifier identifies a first indexer from the plurality of indexers to serve as a primary indexer for responding to queries that pertain to the set of data and that comprise the first generation identifier, wherein one or more indexers in the cluster that are other than the primary indexer are designated as secondary indexers, and wherein the secondary indexers are configured to ignore queries that pertain to the set of data and that comprise the first generation identifier;

broadcasting the first query to each indexer in the cluster; and

receiving a response to the first query from the first indexer,

wherein in response to an event prompting a change in a primary indexer designation for the set of data, a second indexer from the secondary indexers is elected as a new primary indexer by an election process conducted between the secondary indexers.

2. The computer-implemented method of claim 1 , wherein, responsive to the election process, the first generation identifier is incremented to generate a second generation identifier, wherein the second generation identifier identifies the second indexer as the new primary indexer for responding to queries that pertain to the set of data.

3. The computer-implemented method of claim 1 , wherein, responsive to the election process, the first generation identifier is incremented to generate a second generation identifier, wherein the second generation identifier identifies the new primary indexer for responding to queries that pertain to the set of data, and further comprising:

generating, at the searcher device, a second query for the set of data;

providing, with the second query, the second generation identifier;

broadcasting the second query to the plurality of indexers in the cluster; and

receiving a response to the second query from the second indexer.

4. The computer-implemented method of claim 1 , wherein the searcher device is comprised within a client device.

5. The computer-implemented method of claim 1 , wherein the searcher device is accessed by a client device.

6. The computer-implemented method of claim 1 , wherein the searcher device is external to the cluster comprising the plurality of indexers.

7. The computer-implemented method of claim 1 , wherein the cluster comprises a master device operable to manage generation identifiers for the cluster.

8. The computer-implemented method of claim 1 , wherein the cluster comprises a master device, wherein the master device is operable to manage generation identifiers for the cluster, and wherein the master device is configured to update the first generation identifier to a second generation identifier, wherein the second generation identifier identifies the second indexer as the new primary indexer for responding to queries that pertain to the set of data.

9. The computer-implemented method of claim 1 , wherein the event prompting a change in the primary indexer designation is a failure of the first indexer.

10. The computer-implemented method of claim 1 , further comprising:

generating, at the searcher device, a second query for the set of data;

waiting for the election process to resolve to receive a response from the second indexer; and

responsive to the election process resolving, receiving a response to the second query from the second indexer.

11. The computer-implemented method of claim 1 , further comprising:

generating, at the searcher device, a second query for the set of data;

providing, with the second query, a plurality of generation identifiers, wherein each generation identifier identifies a different primary indexer for a respective portion of the set of data;

broadcasting the first query to each indexer in the cluster; and

receiving a response from each primary indexer designated by the plurality of generation identifiers for the respective portion of the set of data.

12. The computer-implemented method of claim 1 , wherein the response to the first query comprises metadata, wherein the metadata comprises diagnostic information.

13. The computer-implemented method of claim 1 , wherein the response to the first query comprises metadata, wherein the metadata comprises an amount of time required to process the first query.

14. One or more non-transitory computer-readable storage media, storing software instructions, which when executed by one or more processors cause performance of:

generating, at a searcher device, a first query for a set of data for a plurality of indexers in a cluster, wherein the set of data comprises time-stamps within a particular time frame;

providing, with the first query, a first generation identifier for the set of data, wherein the first generation identifier identifies a first indexer from the plurality of indexers to serve as a primary indexer for responding to queries that pertain to the set of data and that comprise the first generation identifier, wherein one or more indexers in the cluster that are other than the primary indexer are designated as secondary indexers, and wherein the secondary indexers are configured to ignore queries that pertain to the set of data and that comprise the first generation identifier;

broadcasting the first query to each indexer in the cluster; and

receiving a response to the first query from the first indexer,

wherein in response to an event prompting a change in a primary indexer designation for the set of data, a second indexer from the secondary indexers is elected as a new primary indexer by an election process conducted between the secondary indexers.

15. The one or more non-transitory computer-readable storage media of claim 14 , wherein, responsive to the election process, the first generation identifier is incremented to generate a second generation identifier, wherein the second generation identifier identifies the second indexer as the new primary indexer for responding to queries that pertain to the set of data.

16. The one or more non-transitory computer-readable storage media of claim 14 , wherein, responsive to the election process, the first generation identifier is incremented to generate a second generation identifier, wherein the second generation identifier identifies the new primary indexer for responding to queries that pertain to the set of data, and wherein the instructions, when executed by the one or more computing devices, further cause performance of:

generating, at the searcher device, a second query for the set of data;

providing, with the second query, the second generation identifier;

broadcasting the second query to the plurality of indexers in the cluster; and

receiving a response to the second query from the second indexer.

17. The one or more non-transitory computer-readable storage media of claim 14 , wherein the searcher device is comprised within a client device.

18. The one or more non-transitory computer-readable storage media of claim 14 , wherein the searcher device is accessed by a client device.

19. The one or more non-transitory computer-readable storage media of claim 14 , wherein the cluster comprises a master device operable to manage generation identifiers for the cluster.

20. The one or more non-transitory computer-readable storage media of claim 14 , wherein the cluster comprises a master device, wherein the master device is operable to manage generation identifiers for the cluster, and wherein the master device is configured to update the first generation identifier to a second generation identifier, wherein the second generation identifier identifies the second indexer as the new primary indexer for responding to queries that pertain to the set of data.

21. The one or more non-transitory computer-readable storage media of claim 14 , wherein the event prompting a change in the primary indexer designation is a failure of the first indexer.

22. The one or more non-transitory computer-readable storage media of claim 14 , wherein the instructions, when executed by the one or more computing devices, further cause performance of:

generating, at the searcher device, a second query for the set of data;

waiting for the election process to resolve to receive a response from the second indexer; and

responsive to the election process resolving, receiving a response to the second query from the second indexer.

23. The one or more non-transitory computer-readable storage media of claim 14 , wherein the instructions, when executed by the one or more computing devices, further cause performance of:

generating, at the searcher device, a second query for the set of data;

providing, with the second query, a plurality of generation identifiers, wherein each generation identifier identifies a different primary indexer for a respective portion of the set of data;

broadcasting the first query to each indexer in the cluster; and

receiving a response from each primary indexer designated by the plurality of generation identifiers for the respective portion of the set of data.

24. An apparatus comprising:

a subsystem, implemented at least partially in hardware, that generates, at a searcher device, a first query for a set of data for a plurality of indexers in a cluster, wherein the set of data comprises time-stamps within a particular time frame;

a subsystem, implemented at least partially in hardware, that provides, with the first query, a first generation identifier for the set of data, wherein the first generation identifier identifies a first indexer from the plurality of indexers to serve as a primary indexer for responding to queries that pertain to the set of data and that comprise the first generation identifier, wherein one or more indexers in the cluster that are other than the primary indexer are designated as secondary indexers, and wherein the secondary indexers are configured to ignore queries that pertain to the set of data and that comprise the first generation identifier;

a subsystem, implemented at least partially in hardware, that broadcasts the first query to each indexer in the cluster; and

a subsystem, implemented at least partially in hardware, that receives a response to the first query from the first indexer,

wherein in response to an event prompting a change in a primary indexer designation for the set of data, a second indexer from the secondary indexers is elected as a new primary indexer by an election process conducted between the secondary indexers.

25. The apparatus of claim 24 , wherein, responsive to the election process, the first generation identifier is incremented to generate a second generation identifier, wherein the second generation identifier identifies the second indexer as the new primary indexer for responding to queries that pertain to the set of data.

26. The apparatus of claim 24 , wherein, responsive to the election process, the first generation identifier is incremented to generate a second generation identifier, wherein the second generation identifier identifies the new primary indexer for responding to queries that pertain to the set of data, and further comprising:

a subsystem, implemented at least partially in hardware, that generates, at the searcher device, a second query for the set of data;

a subsystem, implemented at least partially in hardware, that provides, with the second query, the second generation identifier;

a subsystem, implemented at least partially in hardware, that broadcasts the second query to the plurality of indexers in the cluster; and

a subsystem, implemented at least partially in hardware, that receives a response to the second query from the second indexer.

27. The apparatus of claim 24 , wherein the searcher device is comprised within a client device.

28. The apparatus of claim 24 , wherein the searcher device is accessed by a client device.

29. The apparatus of claim 24 , wherein the searcher device is external to the cluster comprising the plurality of indexers.

30. The apparatus of claim 24 , wherein the cluster comprises a master device operable to manage generation identifiers for the cluster.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2020
From: PATEL, VISHAL; BLANK, MITCHELL NEUMAN, JR.; VASAN, SUNDAR RENGARAJAN; SORKIN, STEPHEN PHILLIP
To: SPLUNK INC.
Reel/Frame 051850/0511 →
Continuity (6)
Continuation 15967385 · Apr 30, 2018
Continuation 14815974 · Aug 1, 2015
Continuation 14266812 · Apr 30, 2014
Continuation In Part 13648116 · Oct 9, 2012
Provisional Application 61647245 · May 15, 2012
Related Publication 20190303373A1 · Oct 3, 2019