IP Library Granted Patent US 11,310,313
Granted Patent B2
US 11,310,313 · App. 17/014,244 · Granted Apr 19, 2022

Multi-threaded processing of search responses returned by search peers

Inventors: Sourav Pal (Foster City, CA); Christopher Madden Pride (San Francisco, CA)
Assignee: SPLUNK INC.
H04L67/1087G06F15/167G06F16/951H04L43/106H04L43/16H04L67/02H04L67/1004
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,310,313
App. No.
17/014,244
Granted
Apr 19, 2022
Kind
B2
Abstract

Multi-threaded processing of search responses returned by search peers is disclosed. An example method may include transmitting, by a computer system, a search request to a plurality of search peers of a data aggregation and analysis system; receiving, by a first processing thread, a plurality of data packets from the plurality of search peers; parsing, by a second processing thread operating asynchronously with respect to the first processing thread, one or more data packets of the plurality of data packets, to produce a partial response to the search request; splitting the partial response into two or more fields; and generating, based on the two or more fields of the partial response, an aggregated response to the search request.

Claims (48)

1. A method, comprising:

transmitting, by a computer system, a search request to a plurality of search peers of a data aggregation and analysis system;

receiving, by a first processing thread, a plurality of data packets from the plurality of search peers;

parsing, by a second processing thread operating asynchronously with respect to the first processing thread, one or more data packets of the plurality of data packets, to produce a partial response to the search request;

splitting the partial response into two or more fields; and

generating, based on the two or more fields of the partial response, an aggregated response to the search request.

2. The method of claim 1 , wherein the aggregated response comprises one or more events derived from time-series source data.

3. The method of claim 1 , further comprising:

encoding the aggregated response according to a defined encoding rule.

4. The method of claim 1 , further comprising:

writing the partial response to a message queue; and

responsive to determining that a total size of messages in the message queue exceeds a certain threshold, suspending the first processing thread.

5. The method of claim 4 , further comprising:

responsive to determining that a total size of messages in the message queue falls below a certain threshold, notifying the first processing thread to resume receiving data packets.

6. The method of claim 1 , wherein generating the aggregated response further comprises:

assigning the two or more fields of the partial response to respective fields of a memory data structure representing the aggregated response to the search request.

7. The method of claim 1 , further comprising:

pre-processing the search request by replacing an identifier of a first function returning a first aggregated parameter with an identifier of a second function returning a second aggregated parameter.

8. The method of claim 1 , wherein receiving the plurality of data packets further comprises:

reading, in a non-blocking mode, data from one or more communication endpoints having at least one data packet available.

9. The method of claim 1 , wherein parsing the one or more data packets is performed by two or more processing threads operating in parallel, wherein each processing thread of the two or more processing threads produces a respective partial response to the search request.

10. The method of claim 1 , wherein receiving the plurality of data packets is performed over a plurality of transport layer connections.

11. The method of claim 1 , wherein parsing the one or more data packets is performed in an order of receiving the data packets over a plurality of transport layer connections.

12. The method of claim 1 , wherein each search peer of the plurality of search peers performs map operations of a map-reduce search, to return partial results based on a subset of source data.

13. The method of claim 1 , wherein the method is performed by a search head that performs map operations of a map-reduce search.

14. A computer system, comprising:

a memory; and

one or more processing devices, coupled to the memory, to:

transmit a search request to a plurality of search peers of a data aggregation and analysis system;

receive, by a first processing thread, a plurality of data packets from the plurality of search peers;

parse, by a second processing thread operating asynchronously with respect to the first processing thread, one or more data packets of the plurality of data packets, to produce a partial response to the search request;

split the partial response into two or more fields; and

generate, based on the two or more fields of the partial response, an aggregated response to the search request.

15. The computer system of claim 14 , wherein the aggregated response comprises one or more events derived from time-series source data.

16. The computer system of claim 14 , wherein the one or more processing devices are further to:

write the partial response to a message queue; and

responsive to determining that a total size of messages in the message queue exceeds a certain threshold, suspend the first processing thread that is receiving the data packets.

17. The computer system of claim 16 , wherein the one or more processing devices are further to:

responsive to determining that a total size of messages in the message queue falls below a certain threshold, notifying the first processing thread to resume receiving data packets.

18. The computer system of claim 14 , wherein generating the aggregated response further comprises:

assigning the two or more fields of the partial response to respective fields of a memory data structure representing the aggregated response to the search request.

19. The computer system of claim 14 , wherein each search peer of the plurality of search peers performs map operations of a map-reduce search, to return partial results based on a subset of source data.

20. A computer-readable non-transitory storage medium comprising executable instructions that, when executed by a computer system, cause the computer system to:

transmit a search request to a plurality of search peers of a data aggregation and analysis system;

receive, by a first processing thread, a plurality of data packets from the plurality of search peers;

parse, by a second processing thread operating asynchronously with respect to the first processing thread, one or more data packets of the plurality of data packets, to produce a partial response to the search request;

split the partial response into two or more fields; and

generate, based on the two or more fields of the partial response, an aggregated response to the search request.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2020
From: PAL, SOURAV; PRIDE, CHRISTOPHER MADDEN
To: SPLUNK INC.
Reel/Frame 053712/0315 →
Continuity (5)
Continuation 16174883 · Oct 30, 2018
Continuation 15913079 · Mar 6, 2018
Continuation 15334690 · Oct 26, 2016
Continuation 14448995 · Jul 31, 2014
Related Publication 20210058457A1 · Feb 25, 2021