IP Library Granted Patent US 11,860,881
Granted Patent B1
US 11,860,881 · App. 17/526,606 · Granted Jan 2, 2024

Tracking event records across multiple search sessions

Inventors: Steve Yu Zhang (San Francisco, CA); Stephen Phillip Sorkin (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/24578G06F16/182G06F16/22G06F16/2322G06F16/24G06F16/248G06F16/2455G06F16/2471G06F16/2477G06F16/24553G06F16/24554G06F16/24575G06F16/334G06F16/9038G06F16/90328G06F16/951G06F16/9535H04L41/0604H04L41/22H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,860,881
App. No.
17/526,606
Granted
Jan 2, 2024
Kind
B1
Abstract

A method, system, and processor-readable storage medium are directed towards generating a report derived from data, such as event data, stored on a plurality of distributed nodes. In one embodiment the analysis is generated using a “divide and conquer” algorithm, such that each distributed node analyzes locally stored event data while an aggregating node combines these analysis results to generate the report. In one embodiment, each distributed node also transmits a list of event data references associated with the analysis result to the aggregating node. The aggregating node may then generate a global ordered list of data references based on the list of event data references received from each distributed node. Subsequently, in response to a user selection of a range of global event data, the report may dynamically retrieve event data from one or more distributed nodes for display according to the global order.

Claims (39)

1. A computer-implemented method, comprising:

receiving, at a first computing device, a search query to be performed on a set of event records accessible by the first computing device;

searching, by the first computing device, the set of event records using the search query;

determining a set of event identifiers associated with respective event records of the set of event records accessible by the first computing device, wherein the respective event records satisfied the search query, wherein each event record comprises a portion of raw data related to an operation or activity in an information technology environment, and wherein each event identifier uniquely identifies a corresponding event record and enables subsequently locating the corresponding event record accessible by the first computing device without searching the set of event records;

outputting the set of event identifiers and corresponding computing device identifier onto a network, the computing device identifier identifying the first computing device for accessing the set of event records;

in response to a request to view underlying raw data associated with a particular event identifier of the set of event identifiers, receiving, at the first computing device in accordance with the corresponding computing device identifier, the particular event identifier;

obtaining, from the set of event records, a particular event record associated with the particular event identifier, the particular event record comprising a first portion of raw data related to an operation or activity in the information technology environment; and

outputting the first portion of raw data from the particular event record onto the network.

2. The computer-implemented method of claim 1 , wherein each event record in the set of event records is associated with a time stamp.

3. The computer-implemented method of claim 1 , wherein each event record in the set of event records is associated with a time stamp and is searchable based on a time represented by the time stamp.

4. The computer-implemented method of claim 1 , wherein the set of event identifiers output onto the network does not include an event record associated with an event identifier that was included in the respective event records.

5. The computer-implemented method of claim 1 , wherein the first computing device includes an indexer.

6. The computer-implemented method of claim 1 , wherein the set of event identifiers are output to a second computing device separate from the first computing device.

7. The computer-implemented method of claim 1 , wherein the first computing device includes an indexer, and wherein the set of event identifiers are output to a second computing device separate from the first computing device, the second computing device including a search head.

8. At least one computer-readable storage medium having computer-executable instructions embodied thereon, wherein, when executed by at least one processor, the computer-executable instructions cause the at least one processor to perform actions comprising:

receiving, at a first computing device, a search query to be performed on a set of event records accessible by the first computing device;

searching, by the first computing device, the set of event records using the search query;

determining a set of event identifiers associated with respective event records of the set of event records accessible by the first computing device, wherein the respective event records satisfied the search query, wherein each event record comprises a portion of raw data related to an operation or activity in an information technology environment, and wherein each event identifier uniquely identifies a corresponding event record and enables subsequently locating the corresponding event record accessible by the first computing device without searching the set of event records;

outputting the set of event identifiers and corresponding computing device identifier onto a network, the computing device identifier identifying the first computing device for accessing the set of event records;

in response to a request to view underlying raw data associated with a particular event identifier of the set of event identifiers, receiving, at the first computing device in accordance with the corresponding computing device identifier, the particular event identifier;

obtaining, from the set of event records, a particular event record associated with the particular event identifier, the particular event record comprising a first portion of raw data related to an operation or activity in the information technology environment; and

outputting the first portion of raw data from the particular event record onto the network.

9. The at least one computer-readable storage medium of claim 8 , wherein each event record in the set of event records is associated with a time stamp.

10. The at least one computer-readable storage medium of claim 8 , wherein each event record in the set of event records is associated with a time stamp and is searchable based on a time represented by the time stamp.

11. The at least one computer-readable storage medium of claim 8 , wherein the set of event identifiers output onto the network does not include an event record associated with an event identifier that was included in the respective event records.

12. A computer-implemented system, comprising:

a processor device; and

a computer-readable storage medium, coupled with the processor device, having instructions stored thereon, which, when executed by the processor device, perform actions comprising:

receiving, at a first computing device, a search query to be performed on a set of event records accessible by the first computing device;

searching, by the first computing device, the set of event records using the search query;

determining a set of event identifiers associated with respective event records of the set of event records accessible by the first computing device, wherein the respective event records satisfied the search query, wherein each event record comprises a portion of raw data related to an operation or activity in an information technology environment, and wherein each event identifier uniquely identifies a corresponding event record and enables subsequently locating the corresponding event record accessible by the first computing device without searching the set of event records;

outputting the set of event identifiers and corresponding computing device identifier onto a network, the computing device identifier identifying the first computing device for accessing the set of event records;

in response to a request to view underlying raw data associated with a particular event identifier of the set of event identifiers, receiving, at the first computing device in accordance with the corresponding computing device identifier, the particular event identifier;

obtaining, from the set of event records, a particular event record associated with the particular event identifier, the particular event record comprising a first portion of raw data related to an operation or activity in the information technology environment; and

outputting the first portion of raw data from the particular event record onto the network.

13. The computer-implemented system of claim 12 , wherein the first computing device includes an indexer.

14. The computer-implemented system of claim 12 , wherein the set of event identifiers are output to a second computing device separate from the first computing device.

15. The computer-implemented system of claim 12 , wherein the first computing device includes an indexer, and wherein the set of event identifiers are output to a second computing device separate from the first computing device, the second computing device including a search head.

16. The computer-implemented system of claim 12 , wherein each event record in the set of event records is associated with a time stamp and is searchable based on a time represented by the time stamp.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2021
From: ZHANG, STEVEN YU; SORKIN, STEPHEN PHILLIP
To: SPLUNK INC.
Reel/Frame 058429/0794 →
Continuity (9)
Continuation 16396569 · Apr 26, 2019
Continuation 16041550 · Jul 20, 2018
Continuation 15224657 · Jul 31, 2016
Continuation 14815978 · Aug 1, 2015
Continuation 14530680 · Oct 31, 2014
Continuation 14158421 · Jan 17, 2014
Continuation 13660845 · Oct 25, 2012
Continuation 13223167 · Aug 31, 2011
Provisional Application 61452591 · Mar 14, 2011