IP Library Granted Patent US 11,729,074
Granted Patent B1
US 11,729,074 · App. 17/069,693 · Granted Aug 15, 2023

Online data decomposition

Inventors: Abhinav Mishra (San Francisco, CA); Ram Sriharsha (San Francisco, CA)
Assignee: Splunk Inc.
H04L43/067H04L43/022H04L43/04H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,074
App. No.
17/069,693
Granted
Aug 15, 2023
Kind
B1
Abstract

Embodiments of the present invention are directed to facilitating performing online data decomposition. In accordance with aspects of the present disclosure, an incoming data point of a time series data set is obtained. Thereafter, an iterative process of estimating trend and seasonality is performed to decompose the incoming data point to a set of data components based on a particular set of previous data points of the time series data set and corresponding data components. Generally, the set of data components for the incoming data point include a trend component, a seasonality component, and a residual component. The set of data components is provided for analysis of the incoming data point, such as, for example, to identify data anomalies.

Claims (53)

1. A computer-implemented method comprising:

obtaining an incoming data point of a time series data set, the incoming data point comprising a most recently observed data point;

obtaining a particular set of previous data points of the time series data set and corresponding data components, wherein each of the previous data points were observed prior to the most recently observed data point and were previously decomposed into the data components;

performing an iterative process of estimating trend and seasonality to decompose the incoming data point to a set of data components based on the particular set of previous data points of the time series data set and the corresponding data components, wherein the set of data components for the incoming data point comprises a trend component, a seasonality component, and a residual component; and

providing the set of data components for analysis of the incoming data point.

2. The computer-implemented method of claim 1 , wherein the incoming data point comprises the most recently observed data point provided by a data source.

3. The computer-implemented method of claim 1 , wherein the iterative process of estimating trend and seasonality to decompose the incoming data point is performed in real time upon obtaining the incoming data point such that a subsequent data point of the time series data set is not used to decompose the incoming data point.

4. The computer-implemented method of claim 1 , wherein the iterative process of estimating trend and seasonality to decompose the incoming data point to a set of data components comprises estimating multiple trends and multiple seasonalities in an iterative manner.

5. The computer-implemented method of claim 1 , wherein the iterative process of estimating trend and seasonality to decompose the incoming data point to the set of data components comprises:

estimating an initial trend for the incoming data point based on the particular set of previous data points;

removing the initial trend from the incoming data point to generate a detrended data point;

estimating an initial seasonality for the incoming data point using the detrended data point and an initial seasonality associated with the particular set of previous data points;

estimating an intermediate trend based on the initial seasonality for the incoming data point and the initial seasonality associated with the particular set of previous data points;

removing the initial trend and the intermediate trend from the incoming data point to generate a second detrended data point;

estimating a final seasonality for the incoming data point using the second detrended data point;

removing the final seasonality from the incoming data point to generate a deseasoned data point;

estimating a final trend for the incoming data point based on the deseasoned data point; and

determining a residual for the incoming data point by removing the final trend and the final seasonality from the incoming data point.

6. The computer-implemented method of claim 1 , wherein the iterative process of estimating trend and seasonality to decompose the incoming data point to the set of data components comprises:

estimating an initial trend for the incoming data point based on the particular set of previous data points, wherein the particular set of previous data points correspond with a window size of four times a seasonality parameter;

removing the initial trend from the incoming data point to generate a detrended data point;

estimating an initial seasonality for the incoming data point using the detrended data point and an initial seasonality associated with the particular set of previous data points;

estimating an intermediate trend based on the initial seasonality for the incoming data point and the initial seasonality associated with a first portion of the particular set of previous data points, wherein the first portion of the particular set of previous data points correspond with a second window size of three times the seasonality parameter;

removing the intermediate trend from the detrended data point to generate a second detrended data point;

estimating a final seasonality for the incoming data point using the second detrended data point and a final seasonality associated with the first portion of the particular set of previous data points;

removing the final seasonality from the incoming data point to generate a deseasoned data point;

estimating a final trend for the incoming data point based on the deseasoned data point and a deseasoned data point associated with a second portion of the particular set of previous data points, wherein the second portion of the particular set of previous data points correspond with a third window size of one times the seasonality parameter; and

determining a residual for the incoming data point by removing the final trend and the final seasonality from the incoming data point.

7. The computer-implemented method of claim 1 , wherein estimating trend comprises using a kernel smoothing technique.

8. The computer-implemented method of claim 1 , wherein estimating seasonality comprises using an exponential moving averages technique.

9. The computer-implemented method of claim 1 , wherein the residual component is used to identify an anomaly in the time series data set.

10. The computer-implemented method of claim 1 , wherein the particular set of previous data points of the time series data set and the corresponding data components are stored in a data buffer that captures data associated with the particular set of previous data points.

11. The computer-implemented method of claim 1 , wherein the particular set of previous data points comprises data points within a window size defined as a multiple of a seasonality parameter provided via user input.

12. The computer-implemented method of claim 1 , wherein the set of components are determined in association with ingesting the incoming data point.

13. The computer-implemented method of claim 1 , wherein the set of data components are analyzed in association with ingesting the incoming data point.

14. The computer-implemented method of claim 1 further comprising:

determining that the incoming data point is outside of an initial window size of data points for which batch processing is performed for data decomposition.

15. The computer-implemented method of claim 1 , wherein the corresponding data components used to decompose the incoming data point comprise data components determined via a batch decomposition process.

16. The computer-implemented method of claim 1 , wherein the corresponding data components used to decompose the incoming data point comprise data components determined via a batch decomposition process that performs the iterative process of estimating trend and seasonality.

17. The computer-implemented method of claim 1 , wherein the iterative process of estimating trend and seasonality comprises determining an initial trend, an intermediate trend, and a final trend as well as an initial seasonality and a final seasonality.

18. The computer-implemented method of claim 1 , wherein the particular set of previous data points are stored in a cache for access to perform the iterative process of estimating trend and seasonality.

19. One or more non-transitory computer-readable storage media having instructions stored thereon, wherein the instructions, when executed by a computing device, cause the computing device to:

obtain an incoming data point of a time series data set, the incoming data point comprising a most recently observed data point;

obtain a particular set of previous data points of the time series data set and corresponding data components, wherein each of the previous data points were observed prior to the most recently observed data point and were previously decomposed into the data components;

perform an iterative process of estimating trend and seasonality to decompose the incoming data point to a set of data components based on the particular set of previous data points of the time series data set and the corresponding data components, wherein the set of data components for the incoming data point comprises a trend component, a seasonality component, and a residual component; and

provide the set of data components for analysis of the incoming data point.

20. A computing device comprising:

one or more processors; and

a memory coupled with the one or more processors, the memory having instructions stored thereon, wherein the instructions, when executed by the one or more processors, cause the computing device to:

obtain an incoming data point of a time series data set, the incoming data point comprising a most recently observed data point;

obtain a particular set of previous data points of the time series data set and corresponding data components, wherein each of the previous data points were observed prior to the most recently observed data point and were previously decomposed into the data components;

perform an iterative process of estimating trend and seasonality to decompose the incoming data point to a set of data components based on the particular set of previous data points of the time series data set and the corresponding data components, wherein the set of data components for the incoming data point comprises a trend component, a seasonality component, and a residual component; and

provide the set of data components for analysis of the incoming data point.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2020
From: MISHRA, ABHINAV; SRIHARSHA, RAM
To: SPLUNK INC.
Reel/Frame 054043/0794 →
Continuity (1)
Provisional Application 63064344 · Aug 11, 2020
Cited By (4)
US 12,493,615 US 12,547,886 US 12,608,370 US 12,659,081