IP Library Granted Patent US 11,789,993
Granted Patent B2
US 11,789,993 · App. 17/163,883 · Granted Oct 17, 2023

Correlating non-text machine data using event fields

Inventor: Adam Oliner (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/43G06F16/438
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,789,993
App. No.
17/163,883
Granted
Oct 17, 2023
Kind
B2
Abstract

Described herein are technologies that facilitate effective use (e.g., indexing and searching) of non-text machine data (e.g., audio/visual data) in an event-based machine-data intake and query system.

Claims (52)

1. A computer-implemented method comprising:

generating a first dataset of events and a second dataset of events,

wherein each event of the first dataset of events corresponds to a portion of non-text machine data, the non-text machine data comprising images, video, audio, or a combination thereof, the events of the first dataset of events generated by:

automatically annotating, via machine learning, the non-text machine data with associated textual annotations using textual content to describe non-context content of the non-text machine data, and

generating the events, of the first dataset of events, using timestamps associated with the non-text machine data and the textual annotations associated with the non-text machine data, and

wherein each event of the second dataset of events includes a portion of raw machine data in textual form and produced by a component within an information technology environment and associated with a timestamp;

receiving, from a client device by a data intake and query system, a query instructing correlation of:

the first dataset of events, with

the second dataset of events;

generating, by the data intake and query system, a representation of a third dataset of combined events, each combined event combining corresponding events from the first and second datasets of events based on the corresponding events including a common field value for a field specified by the query; and

causing, by the data intake and query system, the client device to display a representation of the third dataset including a first combined event to provide a correlation between a first portion of text machine data associated with the second dataset and a first portion of non-text machine data associated with the first dataset; and

causing, by the data intake and query system, the client device to present an alert based on identification of a trigger identified in association with the first combined event.

2. The method of claim 1 , wherein a first event of the first dataset includes a link to the portion of non-text machine data associated with the first event.

3. The method of claim 1 , wherein the representation of the third dataset includes rows representing the combined events, a first column representing a first field of the first dataset, a second column representing a second field of the second dataset, and a third column representing the field specified by the query.

4. The method of claim 1 , wherein the common field value describes, by text, content of the portion of non-text machine data associated with each of the corresponding events from the first dataset represented in the third dataset set of combined events.

5. The method of claim 1 , wherein the non-text machine data comprises an image, and the common field value represents an object identified in the image based on object recognition.

6. The method of claim 1 , wherein the portion of non-text machine data comprises a frame grab of a video sequence of a video file, a subset of frames of a video sequence of a video file, a clip of audio from an audio file or video file, one or more images from a collection of still images, or a cropped image of an image file.

7. The method of claim 1 , wherein the query instructs the correlation using a join command that instructs a join operation that combines a first event of the corresponding events from the first dataset with a second event of the corresponding events from the second dataset based on the first event and the second event having the common field value for the field specified by the query.

8. The method of claim 7 , wherein the third dataset comprises the first event and the second event.

9. The method of claim 1 , wherein the generating of the third dataset combines at least a first event from the first dataset and a second event from the second dataset resulting in a merged event, the merged event being included in the third dataset.

10. One or more computer-readable media storing instructions thereon that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

generating a first dataset of events and a second dataset of events,

wherein each event of the first dataset of events corresponds to a portion of non-text machine data, the non-text machine data comprising images, video, audio, or a combination thereof, the events of the first dataset of events generated by:

automatically annotating, via machine learning, the non-text machine data with associated textual annotations using textual content to describe non-context content of the non-text machine data, and

generating the events, of the first dataset of events, using timestamps associated with the non-text machine data and the textual annotations associated with the non-text machine data, and

wherein each event of the second dataset of events includes a portion of raw machine data in textual form and produced by a component within an information technology environment and associated with a timestamp;

receiving, from a client device by a data intake and query system, a query instructing correlation of:

the first dataset of events with

the second dataset of events;

generating, by the data intake and query system, a representation of a third dataset of combined events, each combined event combining corresponding events from the first and second datasets of events based on the corresponding events including a common field value for a field specified by the query; and

causing, by the data intake and query system, the client device to display a representation of the third dataset including a first combined event to provide a correlation between a first portion of text machine data associated with the second dataset and a first portion of non-text machine data associated with the first dataset; and

causing, by the data intake and query system, the client device to present an alert based on identification of a trigger identified in association with the first combined event.

11. The one or more computer-readable media of claim 10 , wherein a first event of the first dataset includes a link to the portion of non-text machine data associated with the first event.

12. The one or more computer-readable media of claim 10 , wherein the representation of the third dataset includes rows representing the combined events, a first column representing a first field of the first dataset, a second column representing a second field of the second dataset, and a third column representing the field specified by the query.

13. The one or more computer-readable media of claim 10 , wherein the common field value describes, by text, content of the portion of non-text machine data associated with each of the corresponding events from the first dataset represented in the third dataset set of combined events.

14. A computer-implemented system comprising:

one or more processors; and

one or more computer-readable media storing instructions thereon that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

generating a first dataset of events and a second dataset of events,

wherein each event of the first dataset of events corresponds to a portion of non-text machine data, the non-text machine data comprising images, video, audio, or a combination thereof, the events of the first dataset of events generated by:

automatically annotating, via machine learning, the non-text machine data with associated textual annotations using textual content to describe non-context content of the non-text machine data, and

generating the events, of the first dataset of events, using timestamps associated with the non-text machine data and the textual annotations associated with the non-text machine data, and

wherein each event of the second dataset of events includes a portion of raw machine data in textual form and produced by a component within an information technology environment and associated with a timestamp;

receiving, from a client device by a data intake and query system, a query instructing correlation of:

the first dataset of events with

the second dataset of events;

generating, by the data intake and query system, a representation of a third dataset of combined events, each combined event combining corresponding events from the first and second datasets of events based on the corresponding events including a common field value for a field specified by the query; and

causing, by the data intake and query system, the client device to display a representation of the third dataset including a first combined event to provide a correlation between a first portion of text machine data associated with the second dataset and a first portion of non-text machine data associated with the first dataset; and

causing, by the data intake and query system, the client device to present an alert based on identification of a trigger identified in association with the first combined event.

15. The system of claim 14 , wherein a first event of the first dataset includes a link to the portion of non-text machine data associated with the first event.

16. The system of claim 15 , wherein the representation of the third dataset includes rows representing the combined events, a first column representing a first field of the first dataset, a second column representing a second field of the second dataset, and a third column representing the field specified by the query.

17. The system of claim 15 , wherein the common field value describes, by text, content of the portion of non-text machine data associated with each of the corresponding events from the first dataset represented in the third dataset set of combined events.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2021
From: OLINER, ADAM
To: SPLUNK INC.
Reel/Frame 055096/0262 →
Continuity (3)
Continuation 15582473 · Apr 28, 2017
Continuation In Part 15224491 · Jul 29, 2016
Related Publication 20210209145A1 · Jul 8, 2021