IP Library Granted Patent US 12,124,669
Granted Patent B1
US 12,124,669 · App. 17/688,029 · Granted Oct 22, 2024

Spatially aligned concurrent display of results from multiple non-identical time-based search queries of event data

Inventors: Cary Noel (Pleasant Hill, CA); John Coates (Berkeley, CA)
Assignee: Splunk Inc.
G06F3/0481G06F3/0484G06F3/04842G06F16/2477G06F16/248
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,124,669
App. No.
17/688,029
Granted
Oct 22, 2024
Kind
B1
Abstract

A visualization can include a set of swim lanes, each swim lane representing information about an event type. An event type can be specified, e.g., as those events having certain keywords and/or having specified value(s) for specified field(s). The swim lane can plot when (within a time range) events of the associated event type occurred. Specifically, each such event can be assigned to a bucket having a bucket time matching the event time. A swim lane can extend along a timeline axis in the visualization, and the buckets can be positioned at a point along the axis that represents the bucket time. Thus, the visualization may indicate whether events were clustered at a point in time. Because the visualization can include a plurality of swim lanes, the visualization can further indicate how timing of events of a first type compare to timing of events of a second type.

Claims (73)

1. A method comprising:

executing, by a computer system, a plurality of non-identical time-based search queries on a set of data that is indexed and stored;

causing display on a display device, by the computer system, of a plurality of concurrently displayed graphical plots and an additional graphical plot, all aligned to a common timeline, each of the plurality of concurrently displayed graphical plots including a plurality of events and representing results from a different one of the plurality of non-identical time-based search queries, the additional graphical plot being a time-based plot for displaying one or more notable events;

receiving, by the computer system, a single selection input that specifies a selection of a plurality of time-aligned portions of the plurality of concurrently displayed graphical plots, the plurality of time-aligned portions including a portion from each of the plurality of concurrently displayed graphical plots and collectively representing a portion of the set of data for a particular time period corresponding to the single selection input; and

in response to the single selection input,

defining, by the computer system, the portion of the set of data for the particular time period as a notable event; and

causing display, by the computer system, of a graphical indicator representing the notable event on the additional graphical plot in a time-aligned manner relative to the plurality of time-aligned portions of the plurality of concurrently displayed graphical plots.

2. The method of claim 1 , further comprising:

based on user input, adjusting a timeframe of the plurality of concurrently displayed graphical plots.

3. The method of claim 1 , further comprising:

based on user input, adjusting a timeframe of the plurality of concurrently displayed graphical plots; and

causing display of plurality of concurrently displayed graphical plots to represent search results within the adjusted timeframe.

4. The method of claim 1 , further comprising:

based on user input, adjusting a timeframe of the plurality of concurrently displayed graphical plots;

executing the plurality of non-identical time-based search queries across the set of data for the adjusted timeframe;

causing display of plurality of concurrently displayed graphical plots to represent search results for the plurality of non-identical time-based search queries over the adjusted timeframe.

5. The method of claim 1 , further comprising:

causing display of a population graph that represents a time plot across the common timeline of one or more of the search results for the plurality of non-identical time-based search queries.

6. The method of claim 1 , further comprising:

causing display of a population graph that represents a time plot across the common timeline of one or more of the search results for the plurality of non-identical time-based search queries;

wherein portions of the population graph are selectable by a user.

7. The method of claim 1 , further comprising:

causing display of a population graph that represents a time plot across the common timeline of one or more of the search results for the plurality of non-identical time-based search queries;

wherein portions of the population graph are selectable by a user;

based on user input selecting a portion of the population graph, adjusting a timeframe of the common timeline to match a time period of the selected portion of the population graph.

8. The method of claim 1 , further comprising:

based on user input, rearranging a displayed order of the display of the plurality of graphical plots for the plurality of non-identical time-based search queries.

9. One or more non-transitory machine-readable storage media, storing one or more sequences of instructions, execution of which in a machine causes performance of:

executing a plurality of non-identical time-based search queries on a set of data that is indexed and stored;

causing display on a display device of a plurality of concurrently displayed graphical plots and an additional graphical plot, all aligned to a common timeline, each of the plurality of concurrently displayed graphical plots including a plurality of events and representing search results from a separate one of the plurality of non-identical time-based search queries, the additional graphical plot being a time-based plot for displaying one or more notable events;

receiving a single selection input specifying selection of a plurality of time-aligned portions of the plurality of concurrently displayed graphical plots, the plurality of time-aligned portions including a portion from each of the plurality of concurrently displayed graphical plots and collectively representing a portion of the set of data for a particular time period corresponding to the single selection input; and

in response to the single selection input,

defining the portion of the set of data for the particular time period as a notable event; and

causing display of a graphical indicator to represent the notable event on the additional graphical plot in a time-aligned manner relative to the plurality of time-aligned portions of the plurality of concurrently displayed graphical plots.

10. The one or more non-transitory machine-readable storage media of claim 9 , further comprising sequences of instructions, execution of which in the machine causes performance of:

based on user input, adjusting a timeframe of the plurality of concurrently displayed graphical plots.

11. The one or more non-transitory machine-readable storage media of claim 9 , further comprising sequences of instructions, execution of which in the machine causes performance of:

based on user input, adjusting a timeframe of the plurality of concurrently displayed graphical plots; and

causing display of plurality of concurrently displayed graphical plots to represent search results within the adjusted timeframe.

12. The one or more non-transitory machine-readable storage media of claim 9 , further comprising sequences of instructions, execution of which in the machine causes performance of:

based on user input, adjusting a timeframe of the plurality of concurrently displayed graphical plots;

executing the plurality of non-identical time-based search queries across the set of data for the adjusted timeframe;

causing display of plurality of concurrently displayed graphical plots to represent search results for the plurality of non-identical time-based search queries over the adjusted timeframe.

13. The one or more non-transitory machine-readable storage media of claim 9 , further comprising sequences of instructions, execution of which in the machine causes performance of:

causing display of a population graph that represents a time plot across the common timeline of one or more of the search results for the plurality of non-identical time-based search queries.

14. The one or more non-transitory machine-readable storage media of claim 9 , further comprising sequences of instructions, execution of which in the machine causes performance of:

causing display of a population graph that represents a time plot across the common timeline of one or more of the search results for the plurality of non-identical time-based search queries;

wherein portions of the population graph are selectable by a user.

15. The one or more non-transitory machine-readable storage media of claim 9 , further comprising sequences of instructions, execution of which in the machine causes performance of:

causing display of a population graph that represents a time plot across the common timeline of one or more of the search results for the plurality of non-identical time-based search queries;

wherein portions of the population graph are selectable by a user;

based on user input selecting a portion of the population graph, adjusting a timeframe of the common timeline to match a time period of the selected portion of the population graph.

16. The one or more non-transitory machine-readable storage media of claim 9 , further comprising sequences of instructions, execution of which in the machine causes performance of:

based on user input, rearranging a displayed order of the display of the plurality of graphical plots for the plurality of non-identical time-based search queries.

17. A processing system comprising:

a processor; and,

a storage facility, accessible to the processor, and storing instructions that, when executed by the processor, cause the processing system to perform operations including

executing a plurality of non-identical time-based search queries on a set of data that is indexed and stored;

causing display, on a display device, of a plurality of concurrently displayed graphical plots and an additional graphical plot, all aligned to a common timeline, each of the plurality of concurrently displayed graphical plots including a plurality of events and representing search results from a separate one of the plurality of non-identical time-based search queries, the additional graphical plot being a time-based plot for displaying one or more notable events;

receiving a single selection input specifying selection of a plurality of time-aligned portions of the plurality of concurrently displayed graphical plots, the plurality of time-aligned portions including a portion from each of the plurality of concurrently displayed graphical plots and collectively representing a portion of the set of data for a particular time period corresponding to the single selection input; and

in response to the selection input,

defining the portion of the set of data for the particular time period as a notable event; and

causing display of a graphical indicator to represent the notable event on the additional graphical plot in a time-aligned manner relative to the plurality of time-aligned portions of the plurality of concurrently displayed graphical plots.

18. The processing system of claim 17 , further comprising instructions that, when executed by the processor, cause the processing system to perform operations including:

based on user input, adjusting a timeframe of the plurality of concurrently displayed graphical plots.

19. The processing system of claim 17 , further comprising instructions that, when executed by the processor, cause the processing system to perform operations including:

based on user input, adjusting a timeframe of the plurality of concurrently displayed graphical plots;

executing the plurality of non-identical time-based search queries across the set of data for the adjusted timeframe;

causing display of plurality of concurrently displayed graphical plots to represent search results for the plurality of non-identical time-based search queries over the adjusted timeframe.

20. The processing system of claim 17 , further comprising instructions that, when executed by the processor, cause the processing system to perform operations including:

causing display of a population graph that represents a time plot across the common timeline of one or more of the search results for the plurality of non-identical time-based search queries;

wherein portions of the population graph are selectable by a user;

based on user input selecting a portion of the population graph, adjusting a timeframe of the common timeline to match a time period of the selected portion of the population graph.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0558 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2022
From: NOEL, CARY; COATES, JOHN
To: SPLUNK INC.
Reel/Frame 059184/0012 →
Continuity (6)
Continuation 15721551 · Sep 29, 2017
Continuation 14691045 · Apr 20, 2015
Continuation 14326459 · Jul 8, 2014
Continuation 14046767 · Oct 4, 2013
Provisional Application 61883071 · Sep 26, 2013
Provisional Application 61878498 · Sep 16, 2013