IP Library Granted Patent US 11,853,804
Granted Patent B2
US 11,853,804 · App. 17/752,199 · Granted Dec 26, 2023

Routing log-based information

Inventors: Frank Mitchell (Pawtucket, RI); Andrew Thompson (Attleboro, MA)
Assignee: Rapid7, Inc.
G06F9/505G06F9/546G06F11/3476H04L9/0643
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,853,804
App. No.
17/752,199
Granted
Dec 26, 2023
Kind
B2
Abstract

Routing log-based information between production servers and logging servers is disclosed. A log entry for a logging server is generated at a production server. A shard identifier is computed for a shard associated with the logging server based on application of a hashing algorithm to properties associated with the production server. The hashing algorithm and properties are selected to prevent or minimize the likelihood of computing of the same shard identifier by another production server for the same shard associated with the logging server. The log entry is transmitted to the shard associated with the logging server. A determination is made that the logging server has malfunctioned by detecting that the log entry transmitted to the shard is absent. In response, another shard identifier is computed for another shard of another logging server and a subsequent log entry from the production server is transmitted to the another shard of the another logging over. No load balancers are used by the routing system.

Claims (63)

1. A computer-implemented method, comprising:

generating a log entry for a logging server at a production server;

computing a shard identifier for a shard associated with the logging server, wherein

the shard identifier is computed based on application of a hashing algorithm to one or more properties associated with the production server, and

the hashing algorithm and the one or more properties are selected to prevent computation of the shard identifier by another production server for the shard associated with the logging server;

transmitting the log entry to the shard associated with the logging server;

determining that the logging server has malfunctioned by detecting that the log entry transmitted to the shard is absent;

in response to detecting failure of the logging server, computing another shard identifier for another shard of another logging server;

transmitting a subsequent log entry from the production server to the another shard of the another logging server; and

removing the logging server that has malfunctioned by changing a modulo value used in the computation of the shard identifier.

2. The computer-implemented method of claim 1 , wherein

the shard identifier is static, and

the shard identifier is mapped one-to-one onto the shard associated with the logging server.

3. The computer-implemented method of claim 1 , wherein

a property of the one or more properties associated with the production server is an instance identifier associated with a virtual machine implementing the production server.

4. The computer-implemented method of claim 1 , further comprising:

determining a time at which the subsequent log entry was routed from the shard of the logging server to the another shard of the another logging server.

5. The computer-implemented method of claim 1 , wherein

the hashing algorithm comprises CRC32, MD5, or SHA256.

6. The computer-implemented method of claim 4 , wherein

the hashing algorithm and the one or more properties are selected to reduce a likelihood the another production server computes the shard identifier for the shard associated with the logging server instead of the another shard identifier for the another shard associated with the another logging server.

7. A non-transitory computer readable storage medium comprising program instructions executable to:

generate a log entry for a logging server at a production server;

compute a shard identifier for a shard associated with the logging server, wherein

the shard identifier is computed based on application of a hashing algorithm to one or more properties associated with the production server, and

the hashing algorithm and the one or more properties are selected to prevent computation of the shard identifier by another production server for the shard associated with the logging server;

transmit the log entry to the shard associated with the logging server;

determine that the logging server has malfunctioned by detecting that the log entry transmitted to the shard is absent;

in response to detecting failure of the logging server, compute another shard identifier for another shard of another logging server;

transmit a subsequent log entry from the production server to the another shard of the another logging server; and

remove the logging server that has malfunctioned by changing a modulo value used in the computation of the shard identifier.

8. The non-transitory computer readable storage medium of claim 7 , wherein

the shard identifier is static, and

the shard identifier is mapped one-to-one onto the shard associated with the logging server.

9. The non-transitory computer readable storage medium of claim 7 , wherein

a property of the one or more properties associated with the production server is an instance identifier associated with a virtual machine implementing the production server.

10. The non-transitory computer readable storage medium of claim 7 , further comprising:

determining a time at which the subsequent log entry was routed from the shard of the logging server to the another shard of the another logging server.

11. The non-transitory computer readable storage medium of claim 7 , wherein

the hashing algorithm comprises CRC32, MD5, or SHA256.

12. The non-transitory computer readable storage medium of claim 10 , wherein

the hashing algorithm and the one or more properties are selected to reduce a likelihood the another production server computes the shard identifier for the shard associated with the logging server instead of the another shard identifier for the another shard associated with the another logging server.

13. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

generate a log entry for a logging server at a production server;

compute a shard identifier for a shard associated with the logging server, wherein

the shard identifier is computed based on application of a hashing algorithm to one or more properties associated with the production server, and

the hashing algorithm and the one or more properties are selected to prevent computation of the shard identifier by another production server for the shard associated with the logging server;

transmit the log entry to the shard associated with the logging server;

determine that the logging server has malfunctioned by detecting that the log entry transmitted to the shard is absent;

in response to detecting failure of the logging server, compute another shard identifier for another shard of another logging server;

transmit a subsequent log entry from the production server to the another shard of the another logging server; and

remove the logging server that has malfunctioned by changing a modulo value used in the computation of the shard identifier.

14. The system of claim 13 , wherein

the shard identifier is static, and

the shard identifier is mapped one-to-one onto the shard associated with the logging server.

15. The system of claim 13 , wherein

a property of the one or more properties associated with the production server is an instance identifier associated with a virtual machine implementing the production server.

16. The system of claim 13 , further comprising:

determining a time at which the subsequent log entry was routed from the shard of the logging server to the another shard of the another logging server.

17. The system of claim 13 , wherein

the hashing algorithm comprises CRC32, MD5, or SHA256.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2022
From: MITCHELL, FRANK; THOMPSON, ANDREW
To: RAPID7, INC.
Reel/Frame 060000/0303 →
Continuity (2)
Continuation 15901541 · Feb 21, 2018
Related Publication 20220283861A1 · Sep 8, 2022