IP Library Granted Patent US 12,061,533
Granted Patent B1
US 12,061,533 · App. 17/877,725 · Granted Aug 13, 2024

Ingest health monitoring

Inventors: Amritpal Singh Bath (Alamo, CA); Samat Jain (San Francisco, CA); Felix Jiang (San Jose, CA); Shanmugam Kailasam (Cupertino, CA); Jibang Liu (San Jose, CA); Isabelle Park (Glendale, CA); Vishal Patel (San Francisco, CA); Divya Vijayan (Pleasant Hill, CA); Jiahan Wang (San Mateo, CA); Tingjin Xu (Dublin, CA)
Assignee: Splunk Inc.
G06F11/3476G06F3/0619G06F2201/81
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,061,533
App. No.
17/877,725
Granted
Aug 13, 2024
Kind
B1
Abstract

Ingest health monitoring includes receiving an event stream of events in a data intake and query system to store on at least one storage system and obtaining an event from the event stream. Ingest health monitoring further includes transmitting the event to a selected ingest module queue for the event, updating an output rate indicator counter for the selected ingest module queue when failure to store the event in the ingest module queue occurs, obtaining the event from the selected ingest module queue, processing the event to generate a file for the event, and transmitting the file to the at least one storage system. Ingest health monitoring further includes updating the write failure indicator counter for a storage system of the at least one storage system when failure to transmit to the storage system occurs and updating the user interface based on the output rate indicator counter and the write failure indicator counter.

Claims (78)

1. A computer-implemented method, comprising:

receiving an event stream of events in a data intake and query system to store on at least one storage system;

obtaining an event from the event stream;

transmitting the event to a selected ingest module queue for the event;

updating an output rate indicator counter for the selected ingest module queue when failure to store the event in the selected ingest module queue occurs;

obtaining the event from the selected ingest module queue;

processing the event to generate a file for the event;

transmitting the file to the at least one storage system;

updating a write failure indicator counter for a storage system of the at least one storage system when failure to transmit to the storage system occurs; and

updating a user interface based on the output rate indicator counter and the write failure indicator counter.

2. The method of claim 1 , further comprising:

resetting the output rate indicator counter upon success of storage in the selected ingest module queue.

3. The method of claim 1 , further comprising:

resetting the write failure indicator counter upon success of transmission to the storage system.

4. The method of claim 1 , further comprising:

generating an output rate status by performing a comparison of the output rate indicator counter with output rate indicator thresholds; and

updating the user interface with the output rate status based on the comparison.

5. The method of claim 1 , further comprising:

generating a write failure status by performing a comparison of the write failure indicator counter with write failure indicator thresholds; and

updating the user interface with the write failure status based on the comparison.

6. The method of claim 1 , further comprising:

generating an output rate status by performing a first comparison of the output rate indicator counter with output rate indicator thresholds;

generating a write failure status by performing a second comparison of the write failure indicator counter with write failure indicator thresholds;

determining a maximum of the output rate status and the write failure status; and

updating the user interface with the maximum.

7. The method of claim 1 , further comprising:

selecting the storage system for the event to obtain a selected storage system, and

identifying the output rate indicator counter for the selected storage system,

wherein each of the at least one storage system comprises an individual output rate indicator counter, and

wherein the output rate indicator counter for the selected storage system is updated.

8. The method of claim 1 , wherein each of the at least one storage system comprises an individual write failure indicator counter.

9. The method of claim 1 , wherein each of a plurality of output processors write events to the selected ingest module queue, and wherein each of the plurality of output processors update the output rate indicator counter for the selected ingest module queue.

10. A computing device, comprising:

a processor; and

a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including:

receiving an event stream of events in a data intake and query system to store on at least one storage system,

obtaining an event from the event stream,

transmitting the event to a selected ingest module queue for the event,

updating an output rate indicator counter for the selected ingest module queue when failure to store the event in the selected ingest module queue occurs,

obtaining the event from the selected ingest module queue,

processing the event to generate a file for the event,

transmitting the file to the at least one storage system,

updating a write failure indicator counter for a storage system of the at least one storage system when failure to transmit to the storage system occurs, and

updating a user interface based on the output rate indicator counter and the write failure indicator counter.

11. The computing device of claim 10 , the operations further comprising:

resetting the output rate indicator counter upon success of storage in the selected ingest module queue.

12. The computing device of claim 10 , the operations further comprising:

resetting the write failure indicator counter upon success of transmission to the storage system.

13. The computing device of claim 10 , the operations further comprising:

generating an output rate status by performing a comparison of the output rate indicator counter with output rate indicator thresholds; and

updating the user interface with the output rate status based on the comparison.

14. The computing device of claim 10 , the operations further comprising:

generating a write failure status by performing a comparison of the write failure indicator counter with write failure indicator thresholds; and

updating the user interface with the write failure status based on the comparison.

15. The computing device of claim 10 , the operations further comprising:

generating an output rate status by performing a first comparison of the output rate indicator counter with output rate indicator thresholds;

generating a write failure status by performing a second comparison of the write failure indicator counter with write failure indicator thresholds;

determining a maximum of the output rate status and the write failure status; and

updating the user interface with the maximum.

16. The computing device of claim 10 , the operations further comprising:

selecting the storage system for the event to obtain a selected storage system, and

identifying the output rate indicator counter for the selected storage system,

wherein each of the at least one storage system comprises an individual output rate indicator counter, and

wherein the output rate indicator counter for the selected storage system is updated.

17. The computing device of claim 10 , wherein each of the at least one storage system comprises an individual write failure indicator counter.

18. The computing device of claim 10 , wherein each of a plurality of output processors write events to the selected ingest module queue, and wherein each of the plurality of output processors update the output rate indicator counter for the selected ingest module queue.

19. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processor to perform operations including:

receiving an event stream of events in a data intake and query system to store on at least one storage system;

obtaining an event from the event stream;

transmitting the event to a selected ingest module queue for the event;

updating an output rate indicator counter for the selected ingest module queue when failure to store the event in the selected ingest module queue occurs;

obtaining the event from the selected ingest module queue;

processing the event to generate a file for the event;

transmitting the file to the at least one storage system;

updating a write failure indicator counter for a storage system of the at least one storage system when failure to transmit to the storage system occurs; and

updating a user interface based on the output rate indicator counter and the write failure indicator counter.

20. The non-transitory computer-readable medium of claim 19 , the operations further comprising:

resetting the output rate indicator counter upon success of storage in the selected ingest module queue.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0558 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2022
From: BATH, AMRITPAL SINGH; JAIN, SAMAT; JIANG, FELIX; KAILASAM, SHANMUGAM; LIU, JIBANG; PARK, ISABELLE; PATEL, VISHAL; VIJAYAN, DIVYA; WANG, JIAHAN; XU, TINGJIN
To: SPLUNK INC.
Reel/Frame 060908/0754 →