IP Library › Granted Patent US 11,586,692
Granted Patent B2
US 11,586,692 · App. 17/589,764 · Granted Feb 21, 2023

Streaming data processing

Inventors: Arindam Bhattacharjee (Fremont, CA); Alexander Douglas James (Sammamish, WA); Sourav Pal (Foster City, CA)
Assignee: Splunk Inc.
G06F16/9535G06F9/5011G06F9/546G06F16/2471G06F16/90335
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,586,692
App. No.
17/589,764
Filed
Jan 31, 2022
Granted
Feb 21, 2023
Kind
B2
Art Unit
2169
USPC
707/722
Abstract

Systems and methods are disclosed for processing streaming data. The data can come from various sources. Worker nodes can be configured to process the streaming data, without delays that may be caused by indexing the data. The data can be filtered and/or transformed as it is processed. In some cases, data can be stored in a data store without transformation. The data in the data store can be accessed and processed at a later time.

Claims (85)

1. A system, comprising:

non-transitory computer-readable media including computer-executable instructions; and

a processor configured to execute the computer-executable instructions, wherein execution of the computer-executable instructions causes the system to:

responsive to receiving a portion of a stream of unindexed machine generated data containing first unindexed events, each unindexed event of the first unindexed events including a portion of machine data of the unindexed machine generated data:

communicate a copy of the first unindexed events included within the received portion of the stream to a data store without transforming the first unindexed events;

apply at least one filter to the first unindexed events to provide first filtered unindexed events;

transform at least a portion of data of at least one filtered unindexed event of the first filtered unindexed events to provide at least one transformed unindexed event; and

communicate the at least one transformed unindexed event to a data destination that is different from the data store;

receive second unindexed events as part of the stream of unindexed machine generated data, wherein each event of the second unindexed events includes a portion of machine data from the stream of unindexed machine generated data;

store the second unindexed events in the data store without transforming the second unindexed events;

at a later time, retrieve the second unindexed events from the data store;

apply at least one filter to the second unindexed events to provide second filtered unindexed events;

transform at least a portion of data of the second filtered unindexed events to provide at least one second transformed unindexed event; and

communicate the at least one second transformed unindexed event to the data destination.

2. The system of claim 1 , wherein the stream of unindexed machine generated data is a continuous stream of unindexed machine generated data.

3. The system of claim 1 , wherein the processor is configured to receive the portion of the stream of unindexed machine generated data from a message queue of a pub-sub.

4. The system of claim 1 , wherein receiving the portion of the stream of unindexed machine generated data comprises receiving the unindexed events from a topic of a pub-sub.

5. The system of claim 1 , wherein the processor is configured to receive the portion of the stream of unindexed machine generated data from a computing device configured to generate the portion of the stream of unindexed machine generated data from the stream of unindexed machine generated data by breaking the stream of unindexed machine generated data into respective portions.

6. The system of claim 1 , wherein to apply at least one filter to the first unindexed events, the processor is configured to filter the first unindexed events based on metadata associated with the first unindexed events.

7. The system of claim 1 , wherein to apply at least one filter to the first unindexed events, the processor is configured to filter the first unindexed events based on a sourcetype of the first unindexed events.

8. The system of claim 1 , wherein to transform at least a portion of data of the at least one filtered unindexed event, the processor is configured to transform at least a portion of data of the at least one filtered unindexed event based on task instructions of a data pipeline.

9. The system of claim 1 , wherein to transform at least a portion of data of the at least one filtered unindexed event, the processor is configured to annotate the at least one filtered unindexed event based on task instructions of a data pipeline.

10. The system of claim 1 , wherein to transform at least a portion of data of the at least one filtered unindexed event, the processor is configured to mask at least a portion of data of the at least one filtered unindexed event based on task instructions of a data pipeline.

11. The system of claim 1 , wherein to transform at least a portion of data of the at least one filtered unindexed event, the processor is configured to remove at least a portion of data of the at least one filtered unindexed event based on task instructions of a data pipeline.

12. The system of claim 1 , wherein to communicate the at least one transformed unindexed event to a data destination, the processor is configured to communicate the at least one transformed unindexed event to a queue, wherein one or more data indexing devices retrieve the at least one transformed unindexed event from the queue, index the at least one transformed unindexed event to provide at least one indexed event, and store the at least one indexed event in a time series data store.

13. The system of claim 1 , wherein to communicate the at least one transformed unindexed event to a data destination, the processor is configured to communicate the at least one transformed unindexed event to one or more data indexing devices, wherein the one or more data indexing devices index the at least one transformed unindexed event to provide at least one indexed event, and store the at least one indexed event in a time series data store.

14. The system of claim 1 , wherein the processor is further configured to communicate the at least one transformed unindexed event to the data store.

15. The system of claim 1 , wherein the processor is further configured to:

at a later time, retrieve at least one unindexed event of the copy of the first unindexed events from the data store;

transform at least a portion of data of the at least one unindexed event to provide at least one second transformed unindexed event; and

communicate the at least one second transformed unindexed event to the data destination.

16. The system of claim 1 , wherein the processor is further configured to:

at a later time, retrieve at least one unindexed event of the copy of the first unindexed events from the data store;

transform at least a portion of data of the at least one unindexed event to provide at least one second transformed unindexed event; and

communicate the at least one second transformed unindexed event to the data store.

17. The system of claim 1 , wherein the processor is further configured to:

at a later time, apply at least one filter to the copy of the first unindexed events to retrieve at least one unindexed event of the copy of the first unindexed events from the data store;

transform at least a portion of data of the at least one unindexed event to provide at least one second transformed unindexed event; and

communicate the at least one second transformed unindexed event to the data destination.

18. The system of claim 1 , wherein the data destination is a queue, and wherein one or more data indexing devices retrieve the at least one transformed unindexed event from the queue, index the at least one transformed unindexed event to provide at least one indexed event, and store the at least one indexed event in a time series data store, wherein the processor is further configured to:

at a later time, retrieve at least one unindexed event of the copy of the first unindexed events from the data store;

transform at least a portion of data of the at least one unindexed event to provide at least one second transformed unindexed event; and

communicate the at least one second transformed unindexed event to the queue, wherein one or more data indexing devices retrieve the at least one second transformed unindexed event from the queue, index the unindexed events, and store indexed events in a time series data store.

19. The system of claim 1 , wherein the processor is further configured to:

at a later time, retrieve at least one unindexed event of the copy of the first unindexed events from the data store;

transform at least a portion of data of the at least one unindexed event to provide at least one second transformed unindexed event; and

communicate the at least one second transformed unindexed event to the data store.

20. A computer-implemented method, comprising:

responsive to receiving a portion of a stream of unindexed machine generated data containing first unindexed events, each unindexed event of the first unindexed events including a portion of machine data of the unindexed machine generated data:

communicating a copy, of the first unindexed events included within the received portion of the stream, to a data store without transforming the unindexed events;

applying at least one filter to the first unindexed events to provide filtered unindexed events;

transforming at least a portion of data of the first filtered unindexed events to provide at least one transformed unindexed event; and

communicating the at least one transformed unindexed event to a data destination that is different from the data store;

receiving second unindexed events as part of the stream of unindexed machine generated data, wherein each event of the second unindexed events includes a portion of machine data from the stream of unindexed machine generated data;

storing the second unindexed events in the data store without transforming the second unindexed events;

at a later time, retrieving the second unindexed events from the data store;

applying at least one filter to the second unindexed events to provide second filtered unindexed events;

transforming at least a portion of data of the second filtered unindexed events to provide at least one second transformed unindexed event; and

communicating the at least one second transformed unindexed event to the data destination.

21. The computer-implemented method of claim 20 , further comprising communicating the at least one transformed unindexed event to the data store.

22. The computer-implemented method of claim 20 , further comprising:

at a later time, retrieving at least one unindexed event of the copy of the first unindexed events from the data store;

transforming at least a portion of data of the at least one unindexed event to provide at least one second transformed unindexed event; and

communicating the at least one second transformed unindexed event to the data destination.

23. The method of claim 20 , further comprising:

at a later time, retrieving at least one unindexed event of the copy of the unindexed events from the data store;

transforming at least a portion of data of the at least one unindexed event to provide at least one second transformed unindexed event; and

communicating the at least one second transformed unindexed event to the data store.

24. One or more non-transitory computer-readable media including computer-executable instructions that, when executed, cause a computing system to:

responsive receiving a portion of a stream of unindexed machine generated data containing first unindexed events, each unindexed event of the first unindexed events including a portion of machine data of the unindexed machine generated data:

communicate a copy, of the first unindexed events included within the received portion of the stream, to a data store without transforming the first unindexed events;

apply at least one filter to the first unindexed events to provide first filtered unindexed events;

transform at least a portion of data of at least one filtered unindexed event of the first filtered unindexed events to provide at least one transformed unindexed event; and

communicate the at least one transformed unindexed event to a data destination that is different from the data store;

receive second unindexed events as part of the stream of unindexed machine generated data, wherein each event of the second unindexed events includes a portion of machine data from the stream of unindexed machine generated data;

store the second unindexed events in the data store without transforming the second unindexed events;

at a later time, retrieve the second unindexed events from the data store;

apply at least one filter to the second unindexed events to provide second filtered unindexed events;

transform at least a portion of data of the second filtered unindexed events to provide at least one second transformed unindexed event; and

communicate the at least one second transformed unindexed event to the data destination.

25. The one or more non-transitory computer-readable media of claim 24 , wherein the computer-executable instructions further cause the computing system to communicate the at least one transformed unindexed event to the data store.

26. The one or more non-transitory computer-readable media of claim 24 , wherein the computer-executable instructions further cause the computing system to:

at a later time, retrieve at least one unindexed event of the copy of the first unindexed events from the data store;

transform at least a portion of data of the at least one unindexed event to provide at least one second transformed unindexed event; and

communicate the at least one second transformed unindexed event to the data destination.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2023
From: PAL, SOURAV; BHATTACHARJEE, ARINDAM; JAMES, ALEXANDER DOUGLAS
To: SPLUNK INC.
Reel/Frame 062316/0910 →
Continuity (3)
Continuation 15665339 · Jul 31, 2017
Continuation In Part 15276717 · Sep 26, 2016
Related Publication 20220156335A1 · May 19, 2022
Cited By (14)
US 12,204,536 US 12,204,593 US 12,248,484 US 12,265,525 US 12,271,389 US 12,287,790 US 12,393,631 US 12,436,963 US 12,585,638 US 12,613,864 US 12,639,379 US 12,645,587 US 12,650,965 US 12,670,152