IP Library Granted Patent US 11,768,848
Granted Patent B1
US 11,768,848 · App. 17/664,816 · Granted Sep 26, 2023

Retrieving, modifying, and depositing shared search configuration into a shared data store

Inventors: Ledio Ago (Oakland, CA); Declan Gerard Shanaghy (Benicia, CA)
Assignee: SPLUNK Inc.
G06F16/254G06F16/215G06F16/2228G06F16/24564G06F16/27G06F16/951H04L63/029H04L67/10H04W4/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,768,848
App. No.
17/664,816
Granted
Sep 26, 2023
Kind
B1
Abstract

Various embodiments describe multi-site cluster-based data intake and query systems, including cloud-based data intake and query systems. Using a hybrid search system that includes cloud-based data intake and query systems working in concert with so-called “on-premises” data intake and query systems can promote the scalability of search functionality. In addition, the hybrid search system can enable data isolation in a manner in which sensitive data is maintained “on premises” and information or data that is not sensitive can be moved to the cloud-based system. Further, the cloud-based system can enable efficient leveraging of data that may already exist in the cloud.

Claims (30)

1. A computer-implemented method comprising:

depositing, by a first cluster of a plurality of clusters of a multi-site clustered data intake and query system dispersed across multiple data centers or buildings, a shared search configuration that is shared by the plurality of clusters and that represents a saved search that defines how the plurality of clusters retrieve or report search results based on ingested data in the plurality of clusters, into a shared data store that is shared by and located outside of the plurality of clusters;

retrieving, by a second cluster of the plurality of clusters, through a first firewall associated with the second cluster, the shared search configuration from the shared data store;

generating, by the second cluster, a modified shared search configuration that modifies the shared search configuration; and

depositing, by the second cluster, the modified shared search configuration into the shared data store through the first firewall.

2. The computer-implemented method of claim 1 , further comprising retrieving, by the first cluster, the modified shared search configuration from the shared data store through a second firewall associated with the first cluster.

3. The computer-implemented method of claim 1 , wherein the second cluster is configured to lock the shared search configuration in the shared data store in association with the retrieving of the shared search configuration, and to unlock the shared search configuration in association with the depositing of the modified shared search configuration that modifies the shared search configuration in the shared data store.

4. The computer-implemented method of claim 1 , wherein the modified shared search configuration is unlocked in the shared data store, enabling other clusters of the plurality of clusters to make changes to the modified shared search configuration.

5. The computer-implemented method of claim 1 , wherein the second cluster is an on-premises cluster.

6. The computer-implemented method of claim 1 , wherein the second cluster is a cloud-based cluster residing in a hosted web service.

7. One or more non-transitory computer-readable media storing instructions thereon, the instructions, when executed by one or more processors, cause the one or more processors to perform operations comprising:

depositing, by a first cluster of a plurality of clusters of a multi-site clustered data intake and query system dispersed across multiple data centers or buildings, a shared search configuration that is shared by the plurality of clusters and that represents a saved search that defines how the plurality of clusters retrieve or report search results based on ingested data in the plurality of clusters, into a shared data store that is shared by and located outside of the plurality of clusters;

retrieving, by a second cluster of the plurality of clusters, through a first firewall associated with the second cluster, the shared search configuration from the shared data store;

generating, by the second cluster, a modified shared search configuration that modifies the shared search configuration; and

depositing, by the second cluster, the modified shared search configuration into the shared data store through the first firewall.

8. The one or more non-transitory computer-readable media of claim 7 , the operations further comprising retrieving, by the first cluster, the modified shared search configuration from the shared data store through a second firewall associated with the first cluster.

9. The one or more non-transitory computer-readable media of claim 7 , wherein the second cluster is configured to lock the shared search configuration in the shared data store in association with the retrieving of the shared search configuration, and to unlock the shared search configuration in association with the depositing of the modified shared search configuration that modifies the shared search configuration in the shared data store.

10. The one or more non-transitory computer-readable media of claim 7 , wherein the modified shared search configuration is unlocked in the shared data store, enabling other clusters of the plurality of clusters to make changes to the modified shared search configuration.

11. The one or more non-transitory computer-readable media of claim 7 , wherein the second cluster is an on-premises cluster.

12. The one or more non-transitory computer-readable media of claim 7 , wherein the second cluster is a cloud-based cluster residing in a hosted web service.

13. A computer-implemented system comprising:

one or more processors and memory storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

depositing, by a first cluster of a plurality of clusters of a multi-site clustered data intake and query system dispersed across multiple data centers or buildings, a shared search configuration that is shared by the plurality of clusters and that represents a saved search that defines how the plurality of clusters retrieve or report search results based on ingested data in the plurality of clusters, into a shared data store that is shared by and located outside of the plurality of clusters;

retrieving, by a second cluster of the plurality of clusters, through a first firewall associated with the second cluster, the shared search configuration from the shared data store;

generating, by the second cluster, a modified shared search configuration that modifies the shared search configuration; and

depositing, by the second cluster, the modified shared search configuration into the shared data store through the first firewall.

14. The computer-implemented system of claim 13 , the operations further comprising retrieving, by the first cluster, the modified shared search configuration from the shared data store through a second firewall associated with the first cluster.

15. The computer-implemented system of claim 13 , wherein the second cluster is configured to lock the shared search configuration in the shared data store in association with the retrieving of the shared search configuration, and to unlock the shared search configuration in association with the depositing of the modified shared search configuration that modifies the shared search configuration in the shared data store.

16. The computer-implemented system of claim 13 , wherein the modified shared search configuration is unlocked in the shared data store, enabling other clusters of the plurality of clusters to make changes to the modified shared search configuration.

17. The computer-implemented system of claim 13 , wherein the second cluster is an on-premises cluster.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2022
From: AGO, LEDIO; SHANAGHY, DECLAN GERARD
To: SPLUNK INC.
Reel/Frame 060005/0816 →
Continuity (3)
Continuation 16259837 · Jan 28, 2019
Continuation 14526500 · Oct 28, 2014
Provisional Application 62058003 · Sep 30, 2014