IP Library Granted Patent US 11,381,492
Granted Patent B1
US 11,381,492 · App. 16/990,923 · Granted Jul 5, 2022

Analyzing servers based on data streams generated by instrumented software executing on the servers

Inventors: Ozan Turgut (San Mateo, CA); Joseph Ari Ross (Redwood City, CA); Eyal Ophir (Mountain View, CA); Calvin Chan (Sunnyvale, CA)
Assignee: Splunk Inc.
H04L43/14G06F11/302G06F11/3006G06F11/3404G06F11/3409G06F11/3612G06F11/3644H04L41/0686H04L43/0817H04L43/16G06F11/3452G06F2201/81H04L43/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,381,492
App. No.
16/990,923
Granted
Jul 5, 2022
Kind
B1
Abstract

An instrumentation analysis system processes data streams received from servers executing instrumented software. The system determines a set of servers that satisfy a given criteria, for example, a set of servers with high resource utilization. The set of servers may be determined by the system based on triggers or specified by a user. The system analyzes properties of servers to determine a property that characterizes the set of servers. The property characterizing the servers is provided to users via a user interface or alerts for further analysis, for example, to analyze the cause of high resource utilization.

Claims (58)

1. A method for analyzing servers executing instrumented software, the method comprising:

identifying a filtered set of servers from a plurality of servers, the filtered set of servers satisfying a filtering criterion;

selecting a plurality of properties of the filtered set of servers, each property from the plurality of properties comprising at least a name value pair having at least a dimension of servers and a value of the dimension;

for each property from the selected plurality of properties, determining a score based on a comparison of a likelihood of a server from the filtered set of servers having the property with a likelihood of a server outside the filtered set of servers having the property;

identifying a characteristic property of the filtered set of servers based on a ranking of the scores, such that servers from the filtered set of servers have a higher likelihood of having the characteristic property than servers outside the filtered set of servers; and

for each property representing a particular value for a particular dimension, ranking properties of servers, the ranking comprising:

determining a first value of a probability mass function for the particular dimension for servers in the filtered set; and

determining a second value of the probability mass function for the particular dimension for a set of servers comprising one or more servers outside the filtered set.

2. The method of claim 1 , further comprising:

storing attributes of each of the plurality of servers, each attribute associated with a dimension describing the servers, wherein each attribute value for a server is determined based on one of: data received as a data stream from the server or metadata describing the server specified independent of the data streams; and

receiving a filtering criterion based on an attribute representing resource utilization of servers, the filtering criterion determining whether the attribute representing resource utilization of servers has a value within a specified set of values.

3. The method of claim 2 , wherein the selected plurality of properties represents values of attributes based on metadata describing servers, the metadata specified independent of the data streams.

4. The method of claim 2 , wherein the resource utilization comprises at least one of CPU utilization, memory utilization, disk utilization, or network utilization.

5. The method of claim 1 , wherein the ranking further comprises:

determining a score for the property as a function of the first value of the probability mass function and the second value of the probability mass function.

6. The method of claim 5 , wherein the score for the property is a difference of the first value of the probability mass function and the second value of the probability mass function.

7. The method of claim 5 , wherein the score for the property is a ratio of the first value of the probability mass function and the second value of the probability mass function.

8. The method of claim 1 , further comprising:

generating an alert describing the characteristic property; and

sending the generated alert to a user account associated with at least one server of the plurality of servers.

9. The method of claim 1 , further comprising:

ranking the selected plurality of properties based on the scores.

10. A system for analyzing servers executing instrumented software, the system comprising:

at least one memory having instructions stored thereon; and

at least one processor configured to execute the instructions, wherein the at least one processor is configured to:

identify a filtered set of servers from a plurality of servers, the filtered set of servers satisfying a filtering criterion;

select a plurality of properties of the filtered set of servers, each property from the plurality of properties comprising at least a name value pair having at least a dimension of servers and a value of the dimension;

for each property from the selected plurality of properties, determine a score based on a comparison of a likelihood of a server from the filtered set of servers having the property with a likelihood of a server outside the filtered set of servers having the property;

identify a characteristic property of the filtered set of servers based on a ranking of the scores, such that servers from the filtered set of servers have a higher likelihood of having the characteristic property than servers outside the filtered set of servers; and

for each property representing a particular value for a particular dimension, ranking properties of servers, the ranking comprising:

determining a first value of a probability mass function for the particular dimension for servers in the filtered set; and

determining a second value of the probability mass function for the particular dimension for a set of servers comprising one or more servers outside the filtered set.

11. The system of claim 10 , further configured to:

store attributes of each of the plurality of servers, each attribute associated with a dimension describing the servers, wherein each attribute value for a server is determined based on one of: data received as a data stream from the server or metadata describing the server specified independent of the data streams; and

receive a filtering criterion based on an attribute representing resource utilization of servers, the filtering criterion determining whether the attribute representing resource utilization of servers has a value within a specified set of values.

12. The system of claim 11 , wherein the selected plurality of properties represents values of attributes based on metadata describing servers, the metadata specified independent of the data streams.

13. The system of claim 11 , wherein the resource utilization represents one of: CPU utilization, memory utilization, disk utilization, or network utilization.

14. The system of claim 10 , wherein the ranking further comprises:

determining a score for the property as a function of the first value of the probability mass function and the second value of the probability mass function.

15. The system of claim 14 , wherein the score for the property is a difference of the first value of the probability mass function and the second value of the probability mass function.

16. The system of claim 14 , wherein the score for the property is a ratio of the first value of the probability mass function and the second value of the probability mass function.

17. The system of claim 10 , further configured to:

generate an alert describing the characteristic property; and

send the generated alert to a user account associated with at least one server of the plurality of servers.

18. A non-transitory computer-readable storage medium comprising instructions stored thereon, which when executed by one or more processors, cause the one or more processors to perform operations for analyzing servers executing instrumented software, comprising:

identifying a filtered set of servers from a plurality of servers, the filtered set of servers satisfying a filtering criterion;

selecting a plurality of properties of the filtered set of servers, each property from the plurality of properties comprising at least a name value pair having at least a dimension of servers and a value of the dimension;

for each property from the selected plurality of properties, determining a score based on a comparison of a likelihood of a server from the filtered set of servers having the property with a likelihood of a server outside the filtered set of servers having the property;

identifying a characteristic property of the filtered set of servers based on a ranking of the scores, such that servers from the filtered set of servers have a higher likelihood of having the characteristic property than servers outside the filtered set of servers; and

for each property representing a particular value for a particular dimension, ranking properties of servers, the ranking comprising:

determining a first value of a probability mass function for the particular dimension for servers in the filtered set; and

determining a second value of the probability mass function for the particular dimension for a set of servers comprising one or more servers outside the filtered set.

19. The non-transitory computer-readable storage medium of claim 18 , further configured for:

generating an alert describing the characteristic property; and

sending the generated alert to a user account associated with at least one server of the plurality of servers.

20. The non-transitory computer-readable storage medium of claim 18 , further configured for:

storing attributes of each of the plurality of servers, each attribute associated with a dimension describing the servers, wherein each attribute value for a server is determined based on one of: data received as a data stream from the server or metadata describing the server specified independent of the data streams; and

receiving a filtering criterion based on an attribute representing resource utilization of servers.

Assignments (5)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2020
From: TURGUT, OZAN; ROSS, JOE; OPHIR, EYAL; CHAN, CALVIN
To: SIGNALFX, INC.
Reel/Frame 053751/0608 →
MERGER AND CHANGE OF NAME Recorded Sep 11, 2020
From: SIGNALFX, INC.; SOLIS MERGER SUB II, LLC; SIGNALFX LLC
To: SIGNALFX LLC
Reel/Frame 053751/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2020
From: SIGNALFX LLC
To: SPLUNK INC.
Reel/Frame 053751/0698 →
Continuity (2)
Continuation 15699451 · Sep 8, 2017
Provisional Application 62393012 · Sep 10, 2016