IP Library Granted Patent US 12,613,926
Granted Patent B1
US 12,613,926 · App. 17/805,780 · Granted Apr 28, 2026

Causing a spawned ERP process to retrieve and return search results

Inventors: Ledion Bitincka (Pasadena, CA); Steve Zhang (San Francisco, CA); Igor Stojanovski (San Francisco, CA); Stephen Sorkin (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F16/951G06F16/2455G06F16/24568G06F16/2471G06F16/90335
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,613,926
App. No.
17/805,780
Granted
Apr 28, 2026
Kind
B1
Abstract

A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing realtime search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.

Claims (41)

1 . A method comprising:

determining, by a first computing device, a set of data storage systems referenced by a received user-specified query;

determining, by the first computing device, how many and what type of external results provider (ERP) processes support searching the set of data storage systems referenced by the received user-specified query;

spawning, by the first computing device, one or more instances of the ERP processes based on the determining of how many and what type, thereby causing each spawned ERP process to execute an interface through which the first computing device retrieves a set of search results responsive to a corresponding portion of the received user-specified query from a corresponding one of the data storage systems referenced by the corresponding portion of the received user-specified query, by triggering the spawned ERP process to:

transform the corresponding portion of the received user-specified query into a transformed query with a syntax that is compatible with the corresponding one of the data storage systems;

establish communication with an interface application of the spawned ERP process installed at the corresponding one of the data storage systems, and

pass the transformed query to the interface application at the corresponding one of the data storage systems; and

providing, from the first computing device to a second computing device, aggregated search results based on the set of search results from each of the data storage systems.

2 . The method of claim 1 , wherein the one or more instances of the ERP processes include a common instance that supports searching a common type of the data storage systems.

3 . The method of claim 1 , wherein the first computing device is of a search support system, wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems operated by a common vendor as a service for an operator of the search support system.

4 . The method of claim 1 , wherein the first computing device is of a search support system, wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems of different types operated by a common vendor as a service for an operator of the search support system.

5 . The method of claim 1 , wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems with a common indexing scheme.

6 . The method of claim 1 , wherein the one or more instances of the ERP processes include different instances of the ERP processes for different instances of a common type of the data storage systems.

7 . One or more computer-readable storage media containing instructions which, when executed by one or more processors, cause the one or more processors to perform operations comprising:

determining, by a first computing device, a set of data storage systems referenced by a received user-specified query;

determining, by the first computing device, how many and what type of external results provider (ERP) processes support searching the set of data storage systems referenced by the received user-specified query;

spawning, by the first computing device, one or more instances of the ERP processes based on the determining of how many and what type, thereby causing each spawned ERP process to execute an interface through which the first computing device retrieves a set of search results responsive to a corresponding portion of the received user-specified query from a corresponding one of the data storage systems referenced by the corresponding portion of the received user-specified query, by triggering the spawned ERP process to:

transform the corresponding portion of the received user-specified query into a transformed query with a syntax that is compatible with the corresponding one of the data storage systems;

establish communication with an interface application of the spawned ERP process installed at the corresponding one of the data storage systems, and

pass the transformed query to the interface application at the corresponding one of the data storage systems; and

providing, from the first computing device to a second computing device, aggregated search results based on the set of search results from each of the data storage systems.

8 . The one or more computer-readable storage media of claim 7 , wherein the one or more instances of the ERP processes include a common instance that supports searching a common type of the data storage systems.

9 . The one or more computer-readable storage media of claim 7 , wherein the first computing device is of a search support system, wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems operated by a common vendor as a service for an operator of the search support system.

10 . The one or more computer-readable storage media of claim 7 , wherein the first computing device is of a search support system, wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems of different types operated by a common vendor as a service for an operator of the search support system.

11 . The one or more computer-readable storage media of claim 7 , wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems with a common indexing scheme.

12 . The one or more computer-readable storage media of claim 7 , wherein the one or more instances of the ERP processes include different instances of the ERP processes for different instances of a common type of the data storage systems.

13 . A computing system, comprising:

one or more processors; and

one or more computer-readable storage media containing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

determining, by a first computing device, a set of data storage systems referenced by a received user-specified query;

determining, by the first computing device, how many and what type of external results provider (ERP) processes support searching the set of data storage systems referenced by the received user-specified query;

spawning, by the first computing device, one or more instances of the ERP processes based on the determining of how many and what type, thereby causing each spawned ERP process to execute an interface through which the first computing device retrieves a set of search results responsive to a corresponding portion of the received user-specified query from a corresponding one of the data storage systems referenced by the corresponding portion of the received user-specified query, by triggering the spawned ERP process to:

transform the corresponding portion of the received user-specified query into a transformed query with a syntax that is compatible with the corresponding one of the data storage systems;

establish communication with an interface application of the spawned ERP process installed at the corresponding one of the data storage systems, and

pass the transformed query to the interface application at the corresponding one of the data storage systems; and

providing, from the first computing device to a second computing device, aggregated search results based on the set of search results from each of the data storage systems.

14 . The computing system of claim 13 , wherein the one or more instances of the ERP processes include a common instance that supports searching a common type of the data storage systems.

15 . The computing system of claim 13 , wherein the first computing device is of a search support system, wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems operated by a common vendor as a service for an operator of the search support system.

16 . The computing system of claim 13 , wherein the first computing device is of a search support system, wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems of different types operated by a common vendor as a service for an operator of the search support system.

17 . The computing system of claim 13 , wherein the one or more instances of the ERP processes include a common instance that supports searching a subset of the data storage systems with a common indexing scheme.

18 . The computing system of claim 13 , wherein the one or more instances of the ERP processes include different instances of the ERP processes for different instances of a common type of the data storage systems.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
Continuity (4)
Continuation 17080032 · Oct 26, 2020
Continuation 16032890 · Jul 11, 2018
Continuation 14266832 · May 1, 2014
Continuation 13886737 · May 3, 2013
References Cited (128)
US 6446062B1 · Levine · 2002 [cited by examiner]
US 7103589B1 · Kepler et al. · 2006 [cited by applicant]
US 7246210B2 · Georgis et al. · 2007 [cited by applicant]
US 7631019B2 · Schneider et al. · 2009 [cited by applicant]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8214338B1 · Kirchhoff et al. · 2012 [cited by applicant]
US 8341142B2 · Sejnoha et al. · 2012 [cited by applicant]
US 8412696B2 · Zhang et al. · 2013 [cited by applicant]
US 8478616B2 · De Klerk · 2013 [cited by examiner]
US 8589403B2 · Marquardt et al. · 2013 [cited by applicant]
US 8682925B1 · Marquardt · 2014 [cited by examiner]
US 8738587B1 · Bitincka · 2014 [cited by examiner]
US 8738629B1 · Bitincka · 2014 [cited by examiner]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788459B2 · Patel · 2014 [cited by examiner]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 8793225B1 · Bitincka · 2014 [cited by examiner]
US 8826434B2 · Merza · 2014 [cited by applicant]
US 9124612B2 · Vasan et al. · 2015 [cited by applicant]
US 9130971B2 · Vasan et al. · 2015 [cited by applicant]
US 9164998B2 · Klevenz et al. · 2015 [cited by applicant]
US 9175526B2 · O'Blenes · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9514189B2 · Bitincka · 2016 [cited by examiner]
US 9753974B2 · Marquardt · 2017 [cited by examiner]
US 9916385B2 · Bitincka · 2018 [cited by examiner]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 11467803B2 · Agrawal et al. · 2022 [cited by applicant]
US 11762869B1 · Werner · 2023 [cited by examiner]
US 20040078359A1 · Bolognese · 2004 [cited by examiner]
US 20040172385A1 · Dayal · 2004 [cited by applicant]
US 20040225641A1 · Dettinger · 2004 [cited by examiner]
US 20050149584A1 · Bourbonnais et al. · 2005 [cited by applicant]
US 20050203876A1 · Cragun · 2005 [cited by examiner]
US 20060053174A1 · Gardner · 2006 [cited by examiner]
US 20060253423A1 · McLane · 2006 [cited by examiner]
US 20070128899A1 · Mayer · 2007 [cited by applicant]
US 20070209080A1 · Ture · 2007 [cited by examiner]
US 20070214164A1 · MacLennan · 2007 [cited by examiner]
US 20070288247A1 · Mackay · 2007 [cited by examiner]
US 20080022347A1 · Cohen · 2008 [cited by applicant]
US 20080104542A1 · Cohen · 2008 [cited by examiner]
US 20080177994A1 · Mayer · 2008 [cited by examiner]
US 20080229037A1 · Bunte et al. · 2008 [cited by applicant]
US 20080281915A1 · Elad et al. · 2008 [cited by applicant]
US 20080301123A1 · Schneider et al. · 2008 [cited by applicant]
US 20080301124A1 · Alves · 2008 [cited by examiner]
US 20080301125A1 · Alves · 2008 [cited by examiner]
US 20080301135A1 · Alves · 2008 [cited by examiner]
US 20080319943A1 · Fischer · 2008 [cited by examiner]
US 20090070786A1 · Alves · 2009 [cited by examiner]
US 20090300065A1 · Birchall · 2009 [cited by examiner]
US 20090307287A1 · Barsness et al. · 2009 [cited by applicant]
US 20090319512A1 · Baker · 2009 [cited by examiner]
US 20090319672A1 · Reisman · 2009 [cited by applicant]
US 20100100562A1 · Millsap · 2010 [cited by examiner]
US 20100333162A1 · Lloyd et al. · 2010 [cited by applicant]
US 20110066585A1 · Subrahmanyam · 2011 [cited by examiner]
US 20110093471A1 · Brockway · 2011 [cited by examiner]
US 20110191373A1 · Botros · 2011 [cited by examiner]
US 20110209049A1 · Ghosh · 2011 [cited by examiner]
US 20110225143A1 · Khosravy · 2011 [cited by examiner]
US 20110252016A1 · Shacham · 2011 [cited by examiner]
US 20110289422A1 · Spivack · 2011 [cited by examiner]
US 20120030180A1 · Klevenz et al. · 2012 [cited by applicant]
US 20120059813A1 · Sejnoha · 2012 [cited by examiner]
US 20120059823A1 · Barber · 2012 [cited by examiner]
US 20120079363A1 · Folting · 2012 [cited by examiner]
US 20120110004A1 · Meijer · 2012 [cited by examiner]
US 20120191716A1 · Omoigui · 2012 [cited by examiner]
US 20130022116A1 · Bennett · 2013 [cited by applicant]
US 20130054642A1 · Morin · 2013 [cited by examiner]
US 20130124495A1 · Sejnoha et al. · 2013 [cited by applicant]
US 20130219068A1 · Ballani et al. · 2013 [cited by applicant]
US 20130239163A1 · Kim et al. · 2013 [cited by applicant]
US 20130275452A1 · Krishnamurthy et al. · 2013 [cited by applicant]
US 20130292165A1 · Lin · 2013 [cited by applicant]
US 20130311427A1 · Patel · 2013 [cited by examiner]
US 20130311438A1 · Marquardt · 2013 [cited by examiner]
US 20130318236A1 · Coates et al. · 2013 [cited by applicant]
US 20140019405A1 · Borthakur · 2014 [cited by examiner]
US 20140025427A1 · Bastian · 2014 [cited by examiner]
US 20140059552A1 · Cunningham et al. · 2014 [cited by applicant]
US 20140101178A1 · Ginter · 2014 [cited by examiner]
US 20140115282A1 · Natkovich et al. · 2014 [cited by applicant]
US 20140137104A1 · Nelson · 2014 [cited by examiner]
US 20140160238A1 · Yim et al. · 2014 [cited by applicant]
US 20140188931A1 · Smiling · 2014 [cited by examiner]
US 20140222758A1 · March et al. · 2014 [cited by applicant]
US 20140236889A1 · Vasan · 2014 [cited by examiner]
US 20140280032A1 · Kornacker et al. · 2014 [cited by applicant]
US 20140324862A1 · Bingham et al. · 2014 [cited by applicant]
US 20140330815A1 · Bitincka · 2014 [cited by examiner]
US 20140344256A1 · Bitincka · 2014 [cited by examiner]
US 20150278153A1 · Leonard · 2015 [cited by examiner]
US 20160055225A1 · Xu · 2016 [cited by examiner]
US 20170046433A1 · Bitincka · 2017 [cited by examiner]
US 20170139996A1 · Marquardt · 2017 [cited by examiner]
US 20180157755A1 · Bitincka · 2018 [cited by examiner]
US 20180285418A1 · Petropoulos · 2018 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190317947A1 · Xu · 2019 [cited by examiner]
Bitincka, L., et al., “Optimizing Data Analysis With a Semi-Structured Time Series Database,” pp. 1-9 (2010). [cited by applicant]
Carasso, D., “Exploring Splunk Search Processing Language (SPL) Primer and Cookbook”, CITO Research, pp. 1-156 (2012). [cited by applicant]
“Incident Review dashboard,” User Manual, Splunk® App for PCI Compliance, Version 2.1.1, accessed at http://docs.splunk.com/Documentation/PCI/2.1.1/User/IncidentReviewdashboard, accessed on Sep. 9, 2019, pp. 2. [cited by applicant]
Elghandour, I., and Aboulnaga, A., “ReStore: Reusing Results of MapReduce Jobs,” Proceedings of the VLDB Endowment, vol. 5, No. 6, pp. 586-597 (2012). [cited by applicant]
“VSphere Monitoring and Performance,” Update 1, vSphere 5.5, EN-001357-00, accessed at https://web.archive.org/web/20140913043828/http://pubs.vmware.com/vsphere-55/topic/com.vmware.ICbase/PDF/vsphere-esxi-vcenter-server… [cited by applicant]
“Splunk Cloud 8.0.2004 User Manual”, available online, retrieved on May 20, 2020 from docs.splunk.com, pp. 66. [cited by applicant]
“Splunk Enterprise 8.0.0 Overview”, available online, retrieved on May 20, 2020 from docs.splunk.com, pp. 17. [cited by applicant]
“Splunk Quick Reference Guide”, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, pp. 6. [cited by applicant]
SQL/MED retrieved from http://wiki.postgresql.org/wiki/SQL/MED, accessed on Sep. 11, 2013, pp. 10. [cited by applicant]
U.S. Appl. No. 13/886,692, filed May 3, 2013, Granted. [cited by applicant]
U.S. Appl. No. 14/815,734, filed Jul. 31, 2015, Granted. [cited by applicant]
U.S. Appl. No. 13/886,737, filed May 3, 2013, Granted. [cited by applicant]
U.S. Appl. No. 13/951,273, filed Jul. 25, 2013, Granted. [cited by applicant]
U.S. Appl. No. 14/266,832, filed May 1, 2014, Granted. [cited by applicant]
U.S. Appl. No. 14/449,144, filed Jul. 31, 2014, Granted. [cited by applicant]
U.S. Appl. No. 15/339,951, filed Nov. 1, 2016, Granted. [cited by applicant]
U.S. Appl. No. 15/885,629, filed Jan. 31, 2018, Granted. [cited by applicant]
U.S. Appl. No. 15/885,521, filed Jan. 31, 2018, Granted. [cited by applicant]
U.S. Appl. No. 16/032,890, filed Jul. 11, 2018, Granted. [cited by applicant]
U.S. Appl. No. 16/830,010, filed Mar. 25, 2020, Granted. [cited by applicant]
U.S. Appl. No. 17/807,321, filed Jun. 16, 2022, Pending. [cited by applicant]
U.S. Appl. No. 17/808,177, filed Jun. 22, 2022, Pending. [cited by applicant]
U.S. Appl. No. 17/080,032, filed Oct. 26, 2020, Granted. [cited by applicant]
U.S. Appl. No. 17/080,067, filed Oct. 26, 2020, Granted. [cited by applicant]