IP Library Granted Patent US 12,367,205
Granted Patent B1
US 12,367,205 · App. 17/808,177 · Granted Jul 22, 2025

Maintaining archive and cut-off dates for querying a data store

Inventors: Elizabeth Lin (San Francisco, CA); Nils Petter Eriksson (Skellefta, SE); Ledion Bitincka (San Francisco, CA)
G06F16/2471
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,205
App. No.
17/808,177
Granted
Jul 22, 2025
Kind
B1
Abstract

In embodiments, a computer-implemented method may entail receiving a search request. A first data store and a second data store, that contains data archived from the first data store, may be identified. Data from the first data store may remain available in the first data store for a limited period of time once archived to the second data store. The first data store storing data in a first format and the second data store storing data in a second format, the first format and the second format being different from one another. Determining that a subset of data that has been archived into the second data store and is to be searched as part of the search request is still available from the first data store, and executing the search request on the subset of data utilizing the first data store. Additional embodiments are described and/or claimed.

Claims (34)

1. A method comprising:

maintaining, by one or more computing devices of a search support system, an archive date that is independent of querying and indicates that any data that is in a first data store and that was stored in the first data store before the archive date is archived data that has been archived to a second data store and exists in both the first data store and the second data store;

maintaining, by the one or more computing devices of the search support system, a cut-off date that is independent of querying, before the archive date, and indicates that any data that was stored in the first data store after the cut-off date, including a subset of the archived data that has been archived to the second data store, is available in the first data store;

querying, by the one or more computing devices, the first data store for a first portion of requested data based on a determination that the first portion of requested data was stored in the first data store after the cut-off date; and

providing, by the one or more computing devices, search results comprising the first portion of the requested data.

2. The method of claim 1 , further comprising maintaining, by the search support system, a delete date that is before the cut-off date and indicates that the first data store does not have any available data that was stored in the first data store before the delete date.

3. The method of claim 1 , further comprising maintaining, by the search support system, a delete date that is before the cut-off date and indicates that the first data store does not have any available data that was stored in the first data store before the delete date, wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store before the cut-off date and after the delete date.

4. The method of claim 1 , further comprising determining to query to the second data store for a second portion of requested data based on determining that the second portion of requested data was stored in the first data store before the cut-off date.

5. The method of claim 1 , wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store more than a set duration of time before the archive date.

6. The method of claim 1 , wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store more than a set duration of time before the archive date, the method further comprising updating, by an archiving process of the search support system and based on a determination that the first data store has an amount of stored data that exceeds a threshold amount of data, the archive date to an updated archive date that would reduce the stored data in the first data store below the threshold amount of data.

7. The method of claim 1 , wherein the cut-off date is global to a plurality of data stores of the search support system, the method further comprising, upon detecting a deletion triggering event configured to cause deletion of a portion of data from one of the data stores, updating the cut-off date based at least on an earliest date associated with the portion of data being deleted.

8. A computer system comprising:

one or more processors; and

one or more computer-readable storage media containing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

maintaining, by one or more computing devices of a search support system, an archive date that is independent of querying and indicates that any data that is in a first data store and that was stored in the first data store before the archive date is archived data that has been archived to a second data store and exists in both the first data store and the second data store;

maintaining, by the one or more computing devices of the search support system, a cut-off date that is independent of querying, before the archive date, and indicates that any data that was stored in the first data store after the cut-off date, including a subset of the archived data that has been archived to the second data store, is available in the first data store;

querying, by the one or more computing devices, the first data store for a first portion of requested data based on a determination that the first portion of requested data was stored in the first data store after the cut-off date; and

providing, by the one or more computing devices, search results comprising the first portion of the requested data.

9. The computer system of claim 8 , the operations further comprising maintaining, by the search support system, a delete date that is before the cut-off date and indicates that the first data store does not have any available data that was stored in the first data store before the delete date.

10. The computer system of claim 8 , the operations further comprising maintaining, by the search support system, a delete date that is before the cut-off date and indicates that the first data store does not have any available data that was stored in the first data store before the delete date, wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store before the cut-off date and after the delete date.

11. The computer system of claim 8 , the operations further comprising determining to query to the second data store for a second portion of requested data based on determining that the second portion of requested data was stored in the first data store before the cut-off date.

12. The computer system of claim 8 , wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store more than a set duration of time before the archive date.

13. The computer system of claim 8 , wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store more than a set duration of time before the archive date, the operations further comprising updating, by an archiving process of the search support system and based on a determination that the first data store has an amount of stored data that exceeds a threshold amount of data, the archive date to an updated archive date that would reduce the stored data in the first data store below the threshold amount of data.

14. The computer system of claim 8 , wherein the cut-off date is global to a plurality of data stores of the search support system, the operations further comprising, upon detecting a deletion triggering event configured to cause deletion of a portion of data from one of the data stores, updating the cut-off date based at least on an earliest date associated with the portion of data being deleted.

15. One or more computer-storage media having instructions which, when executed by one or more processors, cause the one or more processors to perform operations comprising:

maintaining, by one or more computing devices of a search support system, an archive date that is independent of querying and indicates that any data that is in a first data store and that was stored in the first data store before the archive date is archived data that has been archived to a second data store and exists in both the first data store and the second data store;

maintaining, by the one or more computing devices of the search support system, a cut-off date that is independent of querying, before the archive date, and indicates that any data that was stored in the first data store after the cut-off date, including a subset of the archived data that has been archived to the second data store, is available in the first data store;

querying, by the one or more computing devices, the first data store for a first portion of requested data based on a determination that the first portion of requested data was stored in the first data store after the cut-off date; and

providing, by the one or more computing devices, search results comprising the first portion of the requested data.

16. The one or more computer-storage media of claim 15 , the operations further comprising maintaining, by the search support system, a delete date that is before the cut-off date and indicates that the first data store does not have any available data that was stored in the first data store before the delete date.

17. The one or more computer-storage media of claim 15 , the operations further comprising maintaining, by the search support system, a delete date that is before the cut-off date and indicates that the first data store does not have any available data that was stored in the first data store before the delete date, wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store before the cut-off date and after the delete date.

18. The one or more computer-storage media of claim 15 , the operations further comprising determining to query to the second data store for a second portion of requested data based on determining that the second portion of requested data was stored in the first data store before the cut-off date.

19. The one or more computer-storage media of claim 15 , wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store more than a set duration of time before than the archive date.

20. The one or more computer-storage media of claim 15 , wherein the search support system is configured to cause deletion, based on detecting a deletion triggering event, of at least a portion of the archived data in the first data store that was stored in the first data store more than a set duration of time before the archive date, the operations further comprising updating, by an archiving process of the search support system and based on a determination that the first data store has an amount of stored data that exceeds a threshold amount of data, the archive date to an updated archive date that would reduce the stored data in the first data store below the threshold amount of data.

Assignments (5)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
CORRECTIVE ASSIGNMENT TO CORRECT THE FIRST INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 060275 FRAME: 0454. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Jun 24, 2022
From: LIN, ELIZABETH; ERIKSSON, NILS PETTER; BITINCKA, LEDION
To: SPLUNK INC.
Reel/Frame 060439/0941 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2022
From: LILN, ELIZABETH; ERIKSSON, NILS PETTER; BITINCKA, LEDION
To: SPLUNK INC.
Reel/Frame 060275/0454 →
Continuity (6)
Continuation 17080067 · Oct 26, 2020
Continuation 15885521 · Jan 31, 2018
Continuation 14815734 · Jul 31, 2015
Continuation In Part 14449144 · Jul 31, 2014
Continuation 14266832 · May 1, 2014
Continuation 13886737 · May 3, 2013
References Cited (102)
US 6446062B1 · Levine et al. · 2002 [cited by applicant]
US 7103589B1 · Kepler · 2006 [cited by examiner]
US 7246210B2 · Georgis · 2007 [cited by examiner]
US 7631019B2 · Schneider · 2009 [cited by examiner]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8214338B1 · Kirchhoff et al. · 2012 [cited by applicant]
US 8341142B2 · Sejnoha et al. · 2012 [cited by applicant]
US 8412696B2 · Zhang et al. · 2013 [cited by applicant]
US 8478616B2 · De Klerk et al. · 2013 [cited by applicant]
US 8589403B2 · Marquardt et al. · 2013 [cited by applicant]
US 8682925B1 · Marquardt et al. · 2014 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788459B2 · Patel et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 8826434B2 · Merza · 2014 [cited by applicant]
US 9124612B2 · Vasan et al. · 2015 [cited by applicant]
US 9130971B2 · Vasan et al. · 2015 [cited by applicant]
US 9164998B2 · Klevenz · 2015 [cited by examiner]
US 9175526B2 · O'Blenes · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9753974B2 · Marquardt et al. · 2017 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 20040078359A1 · Bolognese et al. · 2004 [cited by applicant]
US 20040172385A1 · Dayal · 2004 [cited by applicant]
US 20040225641A1 · Dettinger et al. · 2004 [cited by applicant]
US 20050149584A1 · Bourbonnais · 2005 [cited by examiner]
US 20050203876A1 · Cragun et al. · 2005 [cited by applicant]
US 20060053174A1 · Gardner et al. · 2006 [cited by applicant]
US 20060101197A1 · Georgis · 2006 [cited by examiner]
US 20060253423A1 · McLane et al. · 2006 [cited by applicant]
US 20070128899A1 · Mayer · 2007 [cited by examiner]
US 20070209080A1 · Ture et al. · 2007 [cited by applicant]
US 20070214164A1 · MacLennan et al. · 2007 [cited by applicant]
US 20070288247A1 · Mackay · 2007 [cited by applicant]
US 20080022347A1 · Cohen · 2008 [cited by applicant]
US 20080104542A1 · Cohen et al. · 2008 [cited by applicant]
US 20080177994A1 · Mayer · 2008 [cited by applicant]
US 20080229037A1 · Bunte · 2008 [cited by examiner]
US 20080281915A1 · Elad et al. · 2008 [cited by applicant]
US 20080301123A1 · Schneider · 2008 [cited by examiner]
US 20080301124A1 · Alves et al. · 2008 [cited by applicant]
US 20080301125A1 · Alves et al. · 2008 [cited by applicant]
US 20080301135A1 · Alves et al. · 2008 [cited by applicant]
US 20080319943A1 · Fischer · 2008 [cited by applicant]
US 20090070786A1 · Alves et al. · 2009 [cited by applicant]
US 20090300065A1 · Birchall · 2009 [cited by applicant]
US 20090307287A1 · Barsness · 2009 [cited by examiner]
US 20090319512A1 · Baker et al. · 2009 [cited by applicant]
US 20090319672A1 · Reisman · 2009 [cited by applicant]
US 20100100562A1 · Millsap · 2010 [cited by applicant]
US 20100333162A1 · Lloyd · 2010 [cited by examiner]
US 20110066585A1 · Subrahmanyam et al. · 2011 [cited by applicant]
US 20110093471A1 · Brockway et al. · 2011 [cited by applicant]
US 20110191373A1 · Botros et al. · 2011 [cited by applicant]
US 20110209049A1 · Ghosh et al. · 2011 [cited by applicant]
US 20110225143A1 · Khosravy et al. · 2011 [cited by applicant]
US 20110252016A1 · Shacham et al. · 2011 [cited by applicant]
US 20110289422A1 · Spivack et al. · 2011 [cited by applicant]
US 20120030180A1 · Klevenz · 2012 [cited by examiner]
US 20120059823A1 · Barber et al. · 2012 [cited by applicant]
US 20120079363A1 · Folting et al. · 2012 [cited by applicant]
US 20120110004A1 · Meijer · 2012 [cited by applicant]
US 20120191716A1 · Omoigui · 2012 [cited by applicant]
US 20130022116A1 · Bennett · 2013 [cited by applicant]
US 20130054642A1 · Morin · 2013 [cited by applicant]
US 20130124495A1 · Sejnoha et al. · 2013 [cited by applicant]
US 20130219068A1 · Ballani et al. · 2013 [cited by applicant]
US 20130239163A1 · Kim et al. · 2013 [cited by applicant]
US 20130275452A1 · Krishnamurthy et al. · 2013 [cited by applicant]
US 20130292165A1 · Lin · 2013 [cited by applicant]
US 20130311427A1 · Patel et al. · 2013 [cited by applicant]
US 20130311438A1 · Marquardt et al. · 2013 [cited by applicant]
US 20130318236A1 · Coates et al. · 2013 [cited by applicant]
US 20140019405A1 · Borthakur et al. · 2014 [cited by applicant]
US 20140025427A1 · Bastian et al. · 2014 [cited by applicant]
US 20140059552A1 · Cunningham et al. · 2014 [cited by applicant]
US 20140101178A1 · Ginter · 2014 [cited by applicant]
US 20140115282A1 · Natkovich et al. · 2014 [cited by applicant]
US 20140137104A1 · Nelson · 2014 [cited by examiner]
US 20140160238A1 · Yim et al. · 2014 [cited by applicant]
US 20140188931A1 · Smiling et al. · 2014 [cited by applicant]
US 20140222758A1 · March · 2014 [cited by examiner]
US 20140236889A1 · Vasan et al. · 2014 [cited by applicant]
US 20140280032A1 · Kornacker et al. · 2014 [cited by applicant]
US 20140324862A1 · Bingham et al. · 2014 [cited by applicant]
US 20150278153A1 · Leonard et al. · 2015 [cited by applicant]
US 20160055225A1 · Xu et al. · 2016 [cited by applicant]
US 20170139996A1 · Marquardt et al. · 2017 [cited by applicant]
US 20180285418A1 · Petropoulos et al. · 2018 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190317947A1 · Xu et al. · 2019 [cited by applicant]
Bitincka, L., et al., “Optimizing Data Analysis With a Semi-Structured Time Series Database,” pp. 1-9 (2010). [cited by applicant]
Carasso, D., “Exploring Splunk Search Processing Language (SPL) Primer and Cookbook”, CITO Research, pp. 1-156 (2012). [cited by applicant]
“Incident Review dashboard,” User Manual, Splunk® App for PCI Compliance, Version 2.1.1, accessed at http://docs.splunk.com/Documentation/PCI/2.1.1/User/IncidentReviewdashboard, accessed on Sep. 9, 2019, p. 2. [cited by applicant]
Elghandour, I., and Aboulnaga, A., “ReStore: Reusing Results of MapReduce Jobs,” Proceedings of the VLDB Endowment, vol. 5, No. 6, pp. 586-597 (2012). [cited by applicant]
“VSphere Monitoring and Performance,” Update 1, vSphere 5.5, EN-001357-00, accessed at https://web.archive.org/web/20140913043828/http://pubs.vmware.com/vsphere-55/topic/com.vmware.ICbase/PDF/vsphere-esxi-vcenter-server… [cited by applicant]
“Splunk Cloud 8.0.2004 User Manual”, available online, retrieved on May 20, 2020 from docs.splunk.com, p. 66. [cited by applicant]
“Splunk Enterprise 8.0.0 Overview”, available online, retrieved on May 20, 2020 from docs.splunk.com, p. 17. [cited by applicant]
“Splunk Quick Reference Guide”, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, p. 6. [cited by applicant]
SQL/MED retrieved from http://wiki.postgresql.org/wiki/SQL/MED, accessed on Sep. 11, 2013, p. 10. [cited by applicant]