IP Library Granted Patent US 11,782,989
Granted Patent B1
US 11,782,989 · App. 17/670,773 · Granted Oct 10, 2023

Correlating data based on user-specified search criteria

Inventors: Brian Bingham (Denver, CO); Tristan Fletcher (Pleasant Hill, CA); Alok Anant Bhide (Mountain View, CA)
Assignee: Splunk Inc.
G06F16/9038G06F3/0482G06F3/0488G06F9/45533G06F11/323G06F16/2471G06F16/26G06F16/9017G06F16/90328G06F16/90335G06F11/3409G06F2201/815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,782,989
App. No.
17/670,773
Granted
Oct 10, 2023
Kind
B1
Abstract

The disclosed system and method acquire and store performance measurements relating to performance of a component in an information technology (IT) environment and log data produced by the IT environment, in association with corresponding time stamps. The disclosed system and method correlate at least one of the performance measurements with at least one of the portions of log data.

Claims (57)

1. A method comprising:

acquiring, by a computer system, a plurality of performance measurements for a performance metric associated with at least one hardware or software component of an information technology (IT) environment including at least one host;

acquiring, by the computer system, a plurality of portions of raw log data representing activity of the at least one hardware or software component of the IT environment;

generating, by the computer system, performance events from the acquired performance measurements and generating log events from the acquired portions of raw log data, wherein each performance event and each log event is stored as a searchable event associated with a respective time stamp;

receiving a user-specified time criterion and a user-specified search criterion that is not a time-based criterion;

correlating, by the computer system, the performance measurements and the raw log data by identifying one or more of the stored performance events with one or more of the stored log events, based on the one or more of the stored performance events and the one or more of the stored log events satisfying the user-specified time criterion and the user-specified search criterion that is not a time-based criterion;

causing display of a graphical plot of performance measurements of the performance metric, based on stored ones of the performance events that correspond to the user-specified time criterion and the user-specified search criterion; and

causing display of a listing of raw log data based on stored ones of the log data events that correspond to the user-specified time criterion and the user-specified search criterion.

2. A method as recited in claim 1 , wherein the user-specified search criterion relates to a machine in the IT environment.

3. A method as recited in claim 1 , wherein the user-specified search criterion relates to a machine in the IT environment, and wherein the user-specified search criterion is specified by a user input to a drop-down list of machines included in the IT environment.

4. A method as recited in claim 1 , further comprising, prior to said correlating:

obtaining the user-specified search criterion from a query input by a user into a query box in a query language for searching a data store that contains at least one of: the performance events or the log events.

5. A method as recited in claim 1 , wherein said correlating further comprises identifying the one or more of the stored performance events and the one or more of the stored log events having time stamps that satisfy the user-specified time criterion, and wherein:

the graphical plot of performance measurements is a plot versus time and is further based on the corresponding stored performance events having time stamps that correspond to the user-specified time criterion, and

the listing of raw log data is further based on the corresponding stored log data events having time stamps that correspond to the user-specified time criterion.

6. A method as recited in claim 1 , wherein the graphical plot of performance measurements is displayed in a first section of a display screen, and the listing of raw log data is displayed in a second section of the display screen that does not overlap the first section.

7. A method as recited in claim 1 , wherein the plurality of performance measurements are acquired independently of the plurality of portions of raw log data.

8. A method as recited in claim 1 , wherein the plurality of performance measurements are acquired independently of the plurality of portions of raw log data, and wherein the plurality of performance measurements have been determined by direct measurement of the at least one hardware or software component in the IT environment and the plurality of portions of log data are derived from a text-based log file.

9. A method as recited in claim 1 , wherein the plurality of performance measurements are acquired independently of the plurality of portions of raw log data by direct measurement of the at least one hardware or software component in the IT environment, and the plurality of portions of raw log data are acquired independently of the plurality of performance measurements.

10. A method as recited in claim 1 , wherein acquiring the plurality of performance measurements comprises acquiring, via an application programming interface (API), the plurality of performance measurements from a third-party software application that collects the plurality of performance measurements.

11. A method as recited in claim 1 , wherein the time stamped performance events are stored in a first time-series data store and the time stamped log events are stored in a second time-series data store separate from the first time-series data store.

12. A method as recited in claim 1 , wherein the time stamped performance events are stored in a first time-series data store and the time stamped log events are stored in a second time-series data store separate from the first time-series data store, the time stamped performance events and the time stamped log events being stored in the first and second time-series data stores, respectively, in different formats.

13. A method as recited in claim 1 , wherein the performance events are stored in a first time-series data store and the log events are stored in a second time-series data store separate from the first time-series data store, the performance events and the log events being stored in the first and second time-series data stores, respectively, in different formats;

the method further comprising:

receiving a user-specified search query in a query language for searching the first and second time-series data stores, the user-specified search query containing the user-specified search criterion, wherein the user-specified search criterion is a user-specified value or a user-specified range of values, for a user-specified field;

wherein said correlating includes, in response to the user-specified search query, searching the first time-series data store for performance data that satisfy the user-specified search criterion and searching the second time-series data store for log data that satisfy the user-specified search criterion.

14. A method as recited in claim 1 , further comprising:

correlating the performance measurements and the raw log data by identifying the one or more of the stored performance events and the one or more of the stored log events that relate to a particular hardware or software component of the IT environment; and

causing concurrent display of an indication of the performance measurements and the raw log data that relate to the particular hardware or software component of the IT environment and the user-specified time criterion.

15. A method as recited in claim 1 , wherein a particular hardware or software component of the IT environment is determined from a user input specifying the particular hardware or software component.

16. A method as recited in claim 1 , further comprising:

acquiring data indicative of structure characteristics of the IT environment, wherein the data indicative of structure characteristics of the IT environment is derived from log data from the IT environment;

storing the data indicative of structure characteristics of the IT environment as time-stamped structure events; and

correlating a performance characteristic of the IT environment with a structure characteristic of the IT environment, by identifying a stored structure event that has a time stamp that corresponds to a time stamp of one of the stored performance events.

17. A method as recited in 1 , further comprising:

acquiring and storing data indicative of structure characteristics of the IT environment;

correlating the data indicative of structure characteristics of the IT environment with the stored performance events to determine a structure characteristic associated with a particular quality of performance; and

causing an indication of the structure characteristic associated with the particular quality of performance to be output to a user.

18. A method as recited in claim 1 , wherein the performance metric comprises a performance metric for one or more hardware or software resources of a computer system, for one or more virtual machines or virtual machine hosts, or for a virtual machine cluster.

19. A non-transitory machine-readable storage medium for use in a processing system of a data intake and query system, the non-transitory machine-readable storage medium storing instructions, an execution of which in the processing system causes the processing system to perform operations comprising:

acquiring, by a computer system, a plurality of performance measurements for a performance metric associated with at least one hardware or software component of an information technology (IT) environment including at least one host;

acquiring, by the computer system, a plurality of portions of raw log data representing activity of the at least one hardware or software component of the IT environment;

generating, by the computer system, performance events from the acquired performance measurements and generating log events from the acquired portions of raw log data, wherein each performance event and each log event is stored as a searchable event associated with a respective time stamp;

receiving a user-specified time criterion and a user-specified search criterion that is not a time-based criterion;

correlating, by the computer system, the performance measurements and the raw log data by identifying one or more of the stored performance events with one or more of the stored log events, based on the one or more of the stored performance events and the one or more of the stored log events satisfying the user-specified time criterion and the user-specified search criterion that is not a time-based criterion;

causing display of a graphical plot of performance measurements of the performance metric, based on stored ones of the performance events that correspond to the user-specified time criterion and the user-specified search criterion; and

causing display of a listing of raw log data based on stored ones of the log data events that correspond to the user-specified time criterion and the user-specified search criterion.

20. A system comprising:

a communication device through which to communicate on a computer network; and

at least one processor operatively coupled to the communication device and configured to perform operations including:

acquiring, by a computer system, a plurality of performance measurements for a performance metric associated with at least one hardware or software component of an information technology (IT) environment including at least one host;

acquiring, by the computer system, a plurality of portions of raw log data representing activity of the at least one hardware or software component of the IT environment;

generating, by the computer system, performance events from the acquired performance measurements and generating log events from the acquired portions of raw log data, wherein each performance event and each log event is stored as a searchable event associated with a respective time stamp;

receiving a user-specified time criterion and a user-specified search criterion that is not a time-based criterion;

correlating, by the computer system, the performance measurements and the raw log data by identifying one or more of the stored performance events with one or more of the stored log events, based on the one or more of the stored performance events and the one or more of the stored log events satisfying the user-specified time criterion and the user-specified search criterion that is not a time-based criterion;

causing display of a graphical plot of performance measurements of the performance metric, based on stored ones of the performance events that correspond to the user-specified time criterion and the user-specified search criterion; and

causing display of a listing of raw log data based on stored ones of the log data events that correspond to the user-specified time criterion and the user-specified search criterion.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2022
From: BINGHAM, BRIAN; FLETCHER, TRISTAN; BHIDE, ALOK ANANT
To: SPLUNK INC.
Reel/Frame 059093/0465 →
Continuity (19)
Continuation 16460423 · Jul 2, 2019
Continuation 15421370 · Jan 31, 2017
Continuation In Part 14167316 · Jan 29, 2014
Continuation In Part 13874423 · Apr 30, 2013
Continuation In Part 13874434 · Apr 30, 2013
Continuation In Part 13874441 · Apr 30, 2013
Continuation In Part 13874448 · Apr 30, 2013
Continuation In Part 14801721 · Jul 16, 2015
Continuation 14253548 · Apr 15, 2014
Continuation In Part 14167316 · Jan 29, 2014
Continuation In Part 13874423 · Apr 30, 2013
Continuation In Part 13874434 · Apr 30, 2013
Continuation In Part 13874441 · Apr 30, 2013
Continuation In Part 13874448 · Apr 30, 2013
Provisional Application 61883869 · Sep 27, 2013
Provisional Application 61900700 · Nov 6, 2013
Provisional Application 61883869 · Sep 27, 2013
Provisional Application 61900700 · Nov 6, 2013
Provisional Application 61979484 · Apr 14, 2014