IP Library Granted Patent US 11,956,137
Granted Patent B1
US 11,956,137 · App. 17/833,519 · Granted Apr 9, 2024

Analyzing servers based on data streams generated by instrumented software executing on the servers

Inventors: Ozan Turgut (San Mateo, CA); Joseph Ari Ross (Redwood City, CA); Eyal Ophir (Mountain View, CA); Calvin Chan (Sunnyvale, CA)
Assignee: Splunk Inc.
H04L43/14G06F11/3006G06F11/302G06F11/3404G06F11/3409G06F11/3612G06F11/3644H04L41/0686H04L43/0817H04L43/16G06F11/3452G06F2201/81H04L43/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,956,137
App. No.
17/833,519
Granted
Apr 9, 2024
Kind
B1
Abstract

An instrumentation analysis system processes data streams received from servers executing instrumented software. The system determines a set of servers that satisfy a given criteria, for example, a set of servers with high resource utilization. The set of servers may be determined by the system based on triggers or specified by a user. The system analyzes properties of servers to determine a property that characterizes the set of servers. The property characterizing the servers is provided to users via a user interface or alerts for further analysis, for example, to analyze the cause of high resource utilization.

Claims (58)

1. A computer-implemented method for analyzing servers executing instrumented software, comprising:

filtering a set of servers from a plurality of servers based at least in part on a filtering criterion;

identifying properties of the filtered set of servers, each property comprising at least a name value pair having at least a dimension of servers and a value of the dimension, wherein the dimension represents a measurable characteristic of the server;

comparing a likelihood of a server from the filtered set of servers having the property with a likelihood of a server outside the filtered set of servers having the property;

calculating scores for each of the properties based on the comparing and a probability mass function for a selected dimension for the plurality of servers;

ranking the properties of the filtered set of servers based on the scores;

identifying characteristic properties of the filtered set of servers based on the ranking, such that the servers from the filtered set of servers have a higher likelihood of having the characteristic properties than servers outside the filtered set of servers;

and

causing display of the ranking of the properties of the filtered set of servers based on the selected dimension through a graphical user interface, wherein the graphical user interface enables selection of one or more dimensions and each of the selected dimensions are graphically represented for the ranking of the properties for the filtered set of servers.

2. The method of claim 1 , further comprising:

storing attributes of each of the plurality of servers, each attribute associated with a dimension describing the servers, wherein each attribute value for a server is determined based on one of: data received as a data stream from the server or metadata describing the server specified independent of the data streams; and

receiving a filtering criterion based on an attribute representing resource utilization of servers, the filtering criterion determining whether the attribute representing resource utilization of servers has a value within a specified set of values.

3. The method of claim 2 , wherein the identified plurality of properties represents values of attributes based on metadata describing servers, the metadata specified independent of the data streams.

4. The method of claim 2 , wherein the resource utilization comprises at least one of CPU utilization, memory utilization, disk utilization, or network utilization.

5. The method of claim 1 , wherein the ranking further comprises determining a score for a characteristic property as a function of a first value of the probability mass function and a second value of the probability mass function.

6. The method of claim 5 , wherein the score for the characteristic property is a difference of the first value of the probability mass function and the second value of the probability mass function.

7. The method of claim 5 , wherein the score for the characteristic property is a ratio of the first value of the probability mass function and the second value of the probability mass function.

8. The method of claim 1 , further comprising:

generating an alert describing a characteristic property; and

sending the generated alert to a user account associated with at least one server of the plurality of servers.

9. The method of claim 1 , wherein the graphical user interface includes a chart view of the characteristic properties of the filtered set of servers.

10. A system for analyzing servers executing instrumented software, the system comprising:

at least one memory having instructions stored thereon; and

at least one processor configured to execute the instructions, wherein the at least one processor is configured to:

filter a set of servers from a plurality of servers based at least in part on a filtering criterion;

identify properties of the filtered set of servers, each property comprising at least a name value pair having at least a dimension of servers and a value of the dimension, wherein the dimension represents a measurable characteristic of the server;

compare a likelihood of a server from the filtered set of servers having the property with a likelihood of a server outside the filtered set of servers having the property;

calculate scores for each of the properties based on the comparing and a probability mass function for a selected dimension for the plurality of servers;

rank the properties of the filtered set of servers based on the scores;

identify characteristic properties of the filtered set of servers based on the ranking, such that the servers from the filtered set of servers have a higher likelihood of having the characteristic properties than servers outside the filtered set of servers;

and

cause display of the ranking of the properties of the filtered set of servers based on the selected dimension through a graphical user interface, wherein the graphical user interface enables selection of one or more dimensions and each of the selected dimensions are graphically represented for the ranking of the properties for the filtered set of servers.

11. The system of claim 10 , further configured to:

store attributes of each of the plurality of servers, each attribute associated with a dimension describing the servers, wherein each attribute value for a server is determined based on one of: data received as a data stream from the server or metadata describing the server specified independent of the data streams; and

receive a filtering criterion based on an attribute representing resource utilization of servers, the filtering criterion determining whether the attribute representing resource utilization of servers has a value within a specified set of values.

12. The system of claim 11 , wherein the identified plurality of properties represents values of attributes based on metadata describing servers, the metadata specified independent of the data streams.

13. The system of claim 11 , wherein the resource utilization represents one of: CPU utilization, memory utilization, disk utilization, or network utilization.

14. The system of claim 10 , wherein the ranking further comprises determining a score for a characteristic property as a function of a first value of the probability mass function and a second value of the probability mass function.

15. The system of claim 14 , wherein the score for the characteristic property is a difference of the first value of the probability mass function and the second value of the probability mass function.

16. The system of claim 14 , wherein the score for the characteristic property is a ratio of the first value of the probability mass function and the second value of the probability mass function.

17. The system of claim 10 , further configured to:

generate an alert describing a characteristic property; and

send the generated alert to a user account associated with at least one server of the plurality of servers.

18. A non-transitory computer-readable storage medium comprising instructions stored thereon, which when executed by one or more processors, cause the one or more processors to perform operations for analyzing servers executing instrumented software, comprising:

filtering a set of servers from a plurality of servers based at least in part on a filtering criterion;

identifying properties of the filtered set of servers, each property comprising at least a name value pair having at least a dimension of servers and a value of the dimension, wherein the dimension represents a measurable characteristic of the server;

comparing a likelihood of a server from the filtered set of servers having the property with a likelihood of a server outside the filtered set of servers having the property;

calculating scores for each of the properties based on the comparing and a probability mass function for a selected dimension for the plurality of servers;

ranking the properties of the filtered set of servers based on the scores;

identifying characteristic properties of the filtered set of servers based on the ranking, such that the servers from the filtered set of servers have a higher likelihood of having the characteristic properties than servers outside the filtered set of servers;

and

causing display of the ranking of the properties of the filtered set of servers based on the selected dimension through a graphical user interface, wherein the graphical user interface enables selection of one or more dimensions and each of the selected dimensions are graphically represented for the ranking of the properties for the filtered set of servers.

19. The non-transitory computer-readable storage medium of claim 18 , further configured for:

generating an alert describing a characteristic property; and

sending the generated alert to a user account associated with at least one server of the plurality of servers.

20. The non-transitory computer-readable storage medium of claim 18 , further configured for:

storing attributes of each of the plurality of servers, each attribute associated with a dimension describing the servers, wherein each attribute value for a server is determined based on one of: data received as a data stream from the server or metadata describing the server specified independent of the data streams; and

receiving a filtering criterion based on an attribute representing resource utilization of servers.

Assignments (5)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2023
From: TURGUT, OZAN; ROSS, JOE; OPHIR, EYAL; CHAN, CALVIN
To: SIGNALFX, INC.
Reel/Frame 065450/0039 →
MERGER AND CHANGE OF NAME Recorded Nov 3, 2023
From: SIGNALFX, INC.; SOLIS MERGER SUB II, LLC; SIGNALFX LLC
To: SIGNALFX LLC
Reel/Frame 065450/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2023
From: SIGNALFX LLC
To: SPLUNK INC.
Reel/Frame 065450/0283 →
Continuity (3)
Continuation 16990923 · Aug 11, 2020
Continuation 15699451 · Sep 8, 2017
Provisional Application 62393012 · Sep 10, 2016