IP Library Granted Patent US 12,067,007
Granted Patent B1
US 12,067,007 · App. 17/874,024 · Granted Aug 20, 2024

Analyzing a pipelined search to determine data on which to execute the pipelined search

Inventors: Jesse Brandau Miller (San Francisco, CA); Marc V. Robichaud (San Francisco, CA); Cory Eugene Burke (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/2425G06F16/2428G06F16/2455G06F16/248
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,067,007
App. No.
17/874,024
Granted
Aug 20, 2024
Kind
B1
Abstract

A method includes causing display to a user of at least one event of a first result set from a first pipelined search on events at an event source. Each event comprises a time stamp and a portion of machine data. A selection of a command is received from the user. The selection is to extend the first pipelined search with the selected command in a second pipelined search. The system selects between the first result set and the event source for execution of the second pipelined search based on an analysis of the selected command and at least one command of the first pipelined search. Based on the selecting being of the first result set, display to the user is caused of at least one event of a second result set from the execution of the second pipelined search on the first result set.

Claims (43)

1. A computer-implemented method for executing search queries, the method comprising:

analyzing at least one command of a pipelined search to determine whether to execute the pipelined search on an event source having a set of events and whether to execute the pipelined search on a result set from a previous search performed on the set of events at the event source, wherein events of the set of events comprise a time stamp and a portion of machine data reflecting security-related information of at least one computing system;

based on the determination, executing, by at least one processor, the pipelined search on the set of events of the event source or the result set from the previous search performed on the set of events at the event source; and

causing display of at least one event of a second result set from the execution of the pipelined search.

2. The computer-implemented method of claim 1 , wherein the pipelined search corresponds with a plurality of commands represented in a command entry list, and the determining is based on metadata of at least one command entry in the command entry list.

3. The computer-implemented method of claim 1 , further comprising receiving a selection of a command to use to extend the pipelined search, wherein the selection of the command is of an option of a plurality of selectable options in an option menu, each selectable option corresponding to one or more of the plurality of selectable commands.

4. The computer-implemented method of claim 1 , further comprising:

assigning the result set as a search point prior to a selection of the at least one command;

determining to retain the result set as the search point, wherein a selection is of the result set based on the determining to retain the result set as the search point.

5. The computer-implemented method of claim 1 , further comprising:

receiving a selection of a command, the selection being to extend the pipelined search with the selected command in a new pipelined search;

selecting between the result set and the set of events of the event source for execution of the new pipelined search based on an analysis of the selected command and at least one command of the pipelined search; and

based on the selecting being of the result set, causing of at least one event of a new result set from the execution of the new pipelined search on the result set.

6. The computer-implemented method of claim 1 , wherein at a time of the execution of the pipelined search on the result set, the event source includes at least one more event incorporated into the set of events than at a time of execution of the previous search.

7. The computer-implemented method of claim 1 , wherein each event of the set of events comprises a portion of raw machine data.

8. The computer-implemented method of claim 1 , wherein the pipelined search applies a late-binding schema.

9. The computer-implemented method of claim 1 , further comprising:

identifying an endpoint of the pipelined search;

identifying a search point of the pipelined search based determining a most recent filtering command in the pipelined search prior to the endpoint; and

based on the identifying of the search point, causing display of at least one event of a new result set produced by executing a query on a result set corresponding to the identified search point, the query representing the pipelined search up through the endpoint.

10. The computer-implemented method of claim 1 , wherein the execution of the pipelined search on the result set executes a query represented in a pipeline query language.

11. One or more non-transitory computer-readable media having instructions stored thereon, the instructions, when executed by at least one processor of a computing device, to cause the computing device to perform a method comprising:

analyzing at least one command of a pipelined search to determine whether to execute the pipelined search on an event source having a set of events and whether to execute the pipelined search on a result set from a previous search performed on the set of events at the event source, wherein events of the set of events comprise a time stamp and a portion of machine data reflecting security-related information of at least one computing system;

based on the determination, executing, by at least one processor, the pipelined search on the set of events of the event source or the result set from the previous search performed on the set of events at the event source; and

causing display of at least one event of a second result set from the execution of the pipelined search.

12. The one or more non-transitory computer-readable media of claim 11 , further comprising receiving a selection of a command to use to extend the pipelined search, wherein the selection of the command is of an option of a plurality of selectable options in an option menu, each selectable option corresponding to one or more of the plurality of selectable commands.

13. The one or more computer-readable media of claim 11 , further comprising:

assigning the result set as a search point prior to a selection of the at least one command;

determining to retain the result set as the search point, wherein a selection is of the result set based on the determining to retain the result set as the search point.

14. The one or more non-transitory computer-readable media of claim 11 , further comprising: receiving a selection of a command, the selection being to extend the pipelined search with the selected command in a new pipelined search; selecting between the result set and the set of events of the event source for execution of the new pipelined search based on an analysis of the selected command and at least one command of the pipelined search; and based on the selecting being of the result set, causing of at least one event of a new result set from the execution of the new pipelined search on the result set.

15. The one or more non-transitory computer-readable media of claim 11 , wherein at a time of the execution of the pipelined search on the result set, the event source includes at least one more event incorporated into the set of events than at a time of execution of the previous search.

16. The one or more computer-readable media of claim 11 , wherein the first pipelined search corresponds with a plurality of commands represented in a command entry list, and the determining is based on metadata of at least one command entry in the command entry list.

17. A system comprising:

at least one processor; and

memory having instructions stored thereon, the instructions, executable by the at least one processor to cause the system to perform a method comprising:

analyzing at least one command of a pipelined search to determine whether to execute the pipelined search on an event source having a set of events and whether to execute the pipelined search on a result set from a previous search performed on the set of events at the event source, wherein events of the set of events comprise a time stamp and a portion of machine data reflecting security-related information of at least one computing system;

based on the determination, executing, by at least one processor, the pipelined search on the set of events of the event source or the result set from the previous search performed on the set of events at the event source; and

causing display of at least one event of a second result set from the execution of the pipelined search.

18. The system of claim 17 , wherein the pipelined search applies a late-binding schema.

19. The system of claim 17 , further comprising:

identifying an endpoint of the pipelined search;

identifying a search point of the pipelined search based determining a most recent filtering command in the pipelined search prior to the endpoint; and

based on the identifying of the search point, causing display of at least one event of a new result set produced by executing a query on a result set corresponding to the identified search point, the query representing the pipelined search up through the endpoint.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2022
From: MILLER, JESSE BRANDAU; ROBICHAUD, MARC V.; BURKE, CORY EUGENE
To: SPLUNK INC.
Reel/Frame 060629/0203 →
Continuity (2)
Continuation 16776317 · Jan 29, 2020
Continuation 15221392 · Jul 27, 2016
Cited By (2)
US 12,505,184 US 12,657,185