IP Library Granted Patent US 11,669,499
Granted Patent B2
US 11,669,499 · App. 17/344,607 · Granted Jun 6, 2023

Management of journal entries associated with customizations of knowledge objects in a search head cluster

Inventor: Eric Timothy Woo (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/178G06F16/27G06F16/285
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,669,499
App. No.
17/344,607
Granted
Jun 6, 2023
Kind
B2
Abstract

Replication of search-related configuration customizations across multiple individual configuration files of search heads of a cluster for a consistent user experience. A search head leader of the cluster can receive a first journal entry relating to a first customization of a knowledge object from a first search head of the cluster. The search head leader may determine that the first journal entry references a parent commit journal entry matching a latest commit journal entry in a journal maintained by the search head leader. The first journal entry can be stored in the journal and sent to one or more search heads of the cluster.

Claims (38)

1. A method comprising:

receiving, by one or more processing devices of a search head leader of a cluster comprising a plurality of search heads, from a first search head of the cluster, a first journal entry relating to a first customization of a knowledge object, wherein the first search head performs a first reduce phase of a first map-reduce search computation of source data in accordance with the first customization, and wherein each search head of the cluster is configured to perform a reduce phase of a map-reduce search computation;

determining, by the one or more processing devices of the search head leader, that the first journal entry references a parent commit journal entry matching a latest commit journal entry in a journal maintained by the search head leader;

storing, by the one or more processing devices of the search head leader, the first journal entry in the journal; and

sending, by the one or more processing devices of the search head leader, the first journal entry to a second search head of the plurality of search heads of the cluster, wherein the second search head adds the first journal entry to a second journal maintained by the second search head.

2. The method of claim 1 , further comprising:

updating a configuration file stored in a local data store of the search head leader to include the first journal entry.

3. The method of claim 2 , further comprising:

sending, to the first search head, a communication indicating the updating of the configuration file.

4. The method of claim 1 , wherein the first customization comprises a customization of at least one of a late-binding schema, a saved search, an event type, a transaction, a tag, a field extraction, a field transform, a lookup, a workflow action, a search command, or a view.

5. The method of claim 1 , wherein the first customization comprises at least one of a change, update, creation, modification, sharing, permissioning, or deletion relating to the knowledge object.

6. The method of claim 1 , wherein the plurality of search heads each comprise a client interface configured to receive one or more customizations from one or more client computing devices.

7. The method of claim 1 , wherein the plurality of search heads each comprise a client interface configured to process one or more customizations shared by the plurality of search heads of the cluster.

8. The method of claim 1 , further comprising:

resolving, by the first search head of the cluster, a conflict between the first customization of the knowledge object and a second customization of the knowledge object processed by a second search head of the cluster.

9. The method of claim 1 , further comprising:

replicating the first customization across the plurality of search heads of the cluster via the search head leader of the cluster, wherein the first customization is communicated via a client interface associated with a second search head of the plurality of search heads of the cluster.

10. The method of claim 1 , further comprising writing, by the search head leader, a configuration setting corresponding to the first customization to a configuration file.

11. The method of claim 1 , further comprising performing a map-reduce search of source data in accordance with the first customization.

12. The method of claim 11 , wherein performing the map-reduce search comprises applying a late binding schema to the source data, the late binding schema associated with one or more extraction rules defining one or more fields in the source data.

13. The method of claim 11 , wherein the source data comprises at least one of aggregated heterogeneous data generated by at least one of a server, a database, an application, or a network, raw machine data, or a plurality of timestamped events, each timestamped event including a portion of raw machine data.

14. The method of claim 1 , wherein the search head leader is configured to synchronize one or more customizations across the plurality of search heads in the cluster.

15. A system comprising:

a local data store; and

a processing device coupled to the local data store, the processing device to execute instructions to:

receive, by a search head leader of a cluster comprising a plurality of search heads, from a first search head of the cluster, a first journal entry relating to a first customization of a knowledge object from a first search head of the cluster, wherein each search head of the cluster is configured to perform a reduce phase of a map-reduce search computation, and wherein each search head of the cluster is configured to perform a reduce phase of a map-reduce search computation;

determine that the first journal entry references a parent commit journal entry matching a latest commit journal entry in a journal maintained by the search head leader;

store the first journal entry in the journal; and

send the first journal entry to a second search head of the plurality of search heads of the cluster, wherein the second search head adds the first journal entry to a second journal maintained by the second search head.

16. The system of claim 15 , the processing device to execute the instructions to update a configuration file stored in a local data store of the search head leader to include the first journal entry.

17. The system of claim 16 , the processing device to execute the instructions to write a configuration setting corresponding to the first customization to the configuration file.

18. The system of claim 15 , wherein the search head leader is configured to synchronize one or more customizations of one or more knowledge objects across the plurality of search heads in the cluster.

19. A non-transitory computer-readable medium encoding instructions thereon that, in response to execution by one or more processing devices cause the one or more processing devices to perform operations comprising:

receiving, by the one or more processing devices of a search head leader of a cluster comprising a plurality of search heads, from a first search head of the cluster, a first journal entry relating to a first customization of a knowledge object, wherein each of the plurality of search heads of the cluster is configured to perform a reduce phase of a map-reduce search computation, and wherein each search head of the cluster is configured to perform a reduce phase of a map-reduce search computation;

determining that the first journal entry references a parent commit journal entry matching a latest commit journal entry in a journal maintained by the search head leader;

storing the first journal entry in the journal; and

sending the first journal entry to a second search head of the plurality of search heads of the cluster, wherein the second search head adds the first journal entry to a second journal maintained by the second search head.

20. The non-transitory computer-readable medium of claim 19 , the operations further comprising writing a configuration setting corresponding to the first customization to a configuration file.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2021
From: WOO, ERIC
To: SPLUNK INC.
Reel/Frame 057380/0952 →
Continuity (3)
Continuation 16690813 · Nov 21, 2019
Continuation 14448919 · Jul 31, 2014
Related Publication 20210303524A1 · Sep 30, 2021