IP Library Granted Patent US 11,537,951
Granted Patent B2
US 11,537,951 · App. 17/146,339 · Granted Dec 27, 2022

Efficiently executing commands at external computing services

Inventors: Lin Ma (Vancouver, CA); Jacob Leverich (San Francisco, CA); Adam Oliner (San Francisco, CA); Alex Cruise (San Francisco, CA); Hongyang Zhang (Vancouver, CA)
Assignee: Splunk Inc.
G06N20/00G06F7/08G06F16/24564G06F16/283G06F16/90335G06F16/951H04L41/14H04L63/1416H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,537,951
App. No.
17/146,339
Granted
Dec 27, 2022
Kind
B2
Abstract

Embodiments of the present invention are directed to facilitating distributed data processing for machine learning. In accordance with aspects of the present disclosure, a set of commands in a query to process at an external computing service is identified. For each command in the set of commands, at least one compute unit including at least one operation to perform at the external computing service is identified. Each of the at least one compute unit associated with each command is analyzed to identify an optimized manner in which to execute the set of commands at the external computing service. An indication of the optimized manner in which to execute the set of commands and a corresponding set of data is provided to the external computing service to utilize for executing the set of commands at the external computing service.

Claims (37)

1. A computer-implemented method comprising:

identifying, at a data-processing system, a set of commands in a query to process at an external computing service, wherein the external computing service is separate from the data-processing system that receives the query to search for events in a data store, wherein each event includes a portion of raw machine data that reflects activity in an information technology environment that is produced by a component of that information technology environment;

for each command in the set of commands, identifying at least one compute unit including at least one operation to perform at the external computing service;

analyzing each of the at least one compute unit associated with each command to identify a manner in which to execute the set of commands at the external computing service to reduce memory consumption or improve execution time, the manner being identified based on information accessible via the data-processing system and inaccessible to the external computing service; and

providing, to the external computing service, an indication of the manner in which to execute the set of commands and a corresponding set of data to utilize for executing the set of commands at the external computing service.

2. The computer-implemented method of claim 1 , wherein the data store is a field-searchable data store, and wherein each event is associated with a timestamp extracted from the raw machine data associated with that event.

3. The computer-implemented method of claim 1 , wherein the corresponding set of data comprises a set of events, wherein each event of the set of events is associated with a timestamp extracted from the raw machine data associated with that event.

4. The computer-implemented method of claim 1 further comprising receiving the query from a client computing device.

5. The computer-implemented method of claim 1 , wherein the set of commands identified in the query correspond with an external processing indicator.

6. The computer-implemented method of claim 1 , wherein the set of commands identified in the query correspond with an external processing indicator that provides an indication to process the set of commands in the external computing service.

7. The computer-implemented method of claim 1 , wherein the set of commands identified in the query correspond with an external processing indicator that provides an indication to process the set of commands in the external computing service, the external processing indicator comprising a command, a symbol, a syntax, or combination thereof.

8. The computer-implemented method of claim 1 , wherein the set of commands identified in the query comprise a portion of commands included in the query.

9. The computer-implemented method of claim 1 , wherein for each command in the set of commands, the at least one compute unit further includes an indication of one or more fields to utilize in performing the at least one operation.

10. The computer-implemented method of claim 1 , further comprising identifying one or more required fields for performing the at least one operation and using the one or more required fields to identify the at least one compute unit.

11. The computer-implemented method of claim 1 further comprising aggregating each of the at least one compute units associated with each command.

12. The computer-implemented method of claim 1 , wherein the manner comprises an at least one of a compute unit reordering, a merger of multiple compute units, an aggregation of multiple compute units, a removal of a compute unit, a parallel execution of multiple compute units, or a combination thereof.

13. The computer-implemented method of claim 1 , wherein the manner is identified in accordance with a preference to optimize memory consumption or a preference to optimize execution time.

14. The computer-implemented method of claim 1 , wherein the manner comprises an external command pipeline indicating machine learning commands to perform at the external computing service and a set of metadata indicating operations to perform to prepare data for performing the machine learning commands.

15. The computer-implemented method of claim 1 , further comprising obtaining the set of data based on the query, wherein the set of data comprises chunks of events in an input buffer.

16. The computer-implemented method of claim 1 , wherein the external computing service utilizes the indication of the manner and the corresponding set of data to execute the set of commands.

17. The computer-implemented method of claim 1 , wherein the external computing service:

obtains the set of data based on the query, the set of data comprising chunks of data;

stores the chunks of data in a plurality of partitions in a columnar format;

performs column-based operations on the chunks of data to obtain data having a same schema.

18. The computer-implemented method of claim 1 , wherein the external computing service is selected from among a set of candidate external computing services based on optimization of the external computing service to execute the set of commands compared to the other external computing services in the set of candidate external computing services.

19. One or more computer-readable storage media having instructions stored thereon, wherein the instructions, when executed by a computing device, cause the computing device to:

identifying, at a data-processing system, a set of commands in a query to process at an external computing service, wherein the external computing service is separate from the data-processing system that receives the query to search for events in a data store, wherein each event includes a portion of raw machine data that reflects activity in an information technology environment that is produced by a component of that information technology environment;

for each command in the set of commands, identifying at least one compute unit including at least one operation to perform at the external computing service;

analyzing each of the at least one compute unit associated with each command to identify a manner in which to execute the set of commands at the external computing service to reduce memory consumption or improve execution time, the manner being identified based on information accessible via the data-processing system and inaccessible to the external computing service; and

providing, to the external computing service, an indication of the manner in which to execute the set of commands and a corresponding set of data to utilize for executing the set of commands at the external computing service.

20. A computing system comprising:

one or more processors; and

a memory coupled with the one or more processors, the memory having instructions stored thereon, wherein the instructions, when executed by the one or more processors, cause the computing device to:

identify, at a data-processing system, a set of commands in a query to process at an external computing service, wherein the external computing service is separate from the data-processing system that receives the query to search for events in a data store, wherein each event includes a portion of raw machine data that reflects activity in an information technology environment that is produced by a component of that information technology environment;

for each command in the set of commands, identify at least one compute unit including at least one operation to perform at the external computing service;

analyze each of the at least one compute unit associated with each command to identify a manner in which to execute the set of commands at the external computing service to reduce memory consumption or improve execution time, the manner being identified based on information accessible via the data-processing system and inaccessible to the external computing service; and

provide, to the external computing service, an indication of the manner in which to execute the set of commands and a corresponding set of data to utilize for executing the set of commands at the external computing service.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2021
From: MA, LIN; OLINER, ADAM; CRUISE, ALEX; ZHANG, HONGYANG; LEVERICH, JACOB
To: SPLUNK INC.
Reel/Frame 054881/0346 →
Continuity (3)
Continuation 15885395 · Jan 31, 2018
Provisional Application 62562205 · Sep 22, 2017
Related Publication 20210133634A1 · May 6, 2021