IP Library Granted Patent US 12,237,988
Granted Patent B1
US 12,237,988 · App. 17/879,694 · Granted Feb 25, 2025

Service analyzer interface presenting performance information of machines providing component services

Inventors: Adrian Hall (Lake Forest Park, WA); Kenneth M. Sternberg (Seattle, WA); Anupadmaja Raghavan (San Jose, CA); Brian C. Reyes (Seattle, WA)
Assignee: Splunk Inc.
H04L43/16G06F16/24578G06F16/282G06F16/904H04L41/065H04L41/0677H04L41/22H04L43/0817H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,237,988
App. No.
17/879,694
Granted
Feb 25, 2025
Kind
B1
Abstract

Provided are systems and methods for determining and displaying service performance information via a graphical user interface. A method can include visually rendering a service-level dashboard reflecting performance of a service and presenting a visual indication of health of each component service and a list of events each corresponding to a change in performance of one of the component services. The method can further include responsive to receiving, via a graphical user interface (GUI), a selection of a component service, visually rendering a system-level dashboard reflecting performance of the selected component-level service, wherein the component service is performed by one or more machines, and wherein the system-level dashboard presents the machines and one or more events each corresponding to a change in performance of one of the machines.

Claims (43)

1. A computer-implemented method comprising:

visually rendering a service-level dashboard reflecting performance of a service, wherein the service comprises a plurality of component services within an information technology environment, and wherein the service-level dashboard presents a visual indication of health of each of the plurality of component services, and a list of events each corresponding to a change in performance of one of the plurality of the component services; and

responsive to receiving, via a graphical user interface (GUI), a selection of a component service of the plurality of component services within the information technology environment:

visually rendering a system-level dashboard reflecting performance of the selected component service,

wherein the selected component service is performed by one or more machines, and the system-level dashboard presents the selected component service, the one or more machines that perform the selected component service, and one or more events corresponding to a selected machine of the one or more machines that perform the selected component service, wherein at least one event is generated for display based on a determination that the at least one event corresponds to a change of a metric score associated with the selected machine exceeding a threshold value for a metric resulting in a transition from a first performance state of the metric to a second performance state of the metric, wherein the at least one event comprises a discrete portion of text machine data describing a corresponding event and associated with a timestamp from the selected machine of the one or more machines.

2. The computer-implemented method of claim 1 , wherein the visual indication of health of each of the plurality of the component services represents a component service score of a respective component service.

3. The computer-implemented method of claim 1 , further comprising:

responsive to receiving, via the GUI, selection of a machine of the one or more machines, visually rendering a machine-level dashboard presenting additional information pertaining to performance of the selected machine.

4. The computer-implemented method of claim 1 , wherein the system-level dashboard further presents a machine score of each of the one or more machines, the machine score representing a health of a respective machine.

5. The computer-implemented method of claim 4 , wherein the machine score is a composite machine score value that is based on a plurality of metric scores each corresponding to one of a plurality of monitored elements of a respective machine.

6. The computer-implemented method of claim 1 , wherein:

the metric score is derived from source data produced by the respective machine, the source data reflected in computer storage as timestamped events and is based at least in part on at least one of the following: system logs, network packet data, sensor data, and performance monitoring application output data; and

the deriving includes identifying at least one field value from the source data of timestamped events by applying an extraction rule.

7. The computer-implemented method of claim 5 , wherein the composite machine score value for the respective machine is compared to one or more predefined thresholds to determine a health status for the respective machine from among a set of predefined health statuses, each threshold associated with at least one of the predefined health statuses to delimit a range of corresponding values.

8. The computer-implemented method of claim 1 , wherein the health of each of the plurality of component services corresponds to a health of a particular machine of one or more machines performing a respective component service.

9. The computer-implemented method of claim 1 , wherein the one or more machines comprises at least one virtual machine.

10. A system comprising:

a memory comprising program instructions; and

one or more processors to execute the program instructions to perform operations comprising;

visually rendering a service-level dashboard reflecting performance of a service, wherein the service comprises a plurality of component services within an information technology environment, and wherein the service-level dashboard presents a visual indication of health of each of the plurality of component services, and a list of events each corresponding to a change in performance of one of the plurality of the component services; and

responsive to receiving, via a graphical user interface (GUI), a selection of a component service of the plurality of component services within the information technology environment:

visually rendering a system-level dashboard reflecting performance of the selected component service,

wherein the selected component service is performed by one or more machines, and the system-level dashboard presents the selected component service, the one or more machines that perform the selected component service, and one or more events each corresponding to a selected machine of the one or more machines that perform the selected component service, wherein at least one event is generated for display based on a determination that the at least one event corresponds to a change of a metric score associated with the selected machine exceeding a threshold value for a metric resulting in a transition from a first performance state of the metric to a second performance state of the metric, wherein the at least one event comprises a discrete portion of text machine data describing a corresponding event and associated with a timestamp from the selected machine of the one or more machines.

11. The system of claim 10 , wherein the visual indication of health of each of the plurality of the component services represents a component service score of a respective component service.

12. The system of claim 10 , the operations further comprising:

responsive to receiving, via the GUI, selection of a machine of the one or more machines, visually rendering a machine-level dashboard presenting additional information pertaining to performance of the selected machine.

13. The system of claim 10 , wherein the system-level dashboard further presents a machine score of each of the one or more machines, the machine score representing a health of a respective machine.

14. The system of claim 13 , wherein the machine score is a composite machine score value that is based on a plurality of metric scores each corresponding to one of a plurality of monitored elements of a respective machine.

15. The system of claim 10 , wherein:

the metric score is derived from source data produced by the respective machine, the source data reflected in computer storage as timestamped events and is based at least in part on at least one of the following: system logs, network packet data, sensor data, and performance monitoring application output data; and

the deriving includes identifying at least one field value from the source data of timestamped events by applying an extraction rule.

16. The system of claim 14 , wherein the composite machine score value for the respective machine is compared to one or more predefined thresholds to determine a health status for the respective machine from among a set of predefined health statuses, each threshold associated with at least one of the predefined health statuses to delimit a range of corresponding values.

17. The system of claim 10 , wherein the health of each of the plurality of component services corresponds to a health of a particular machine of one or more machines performing a respective component service.

18. A non-transitory computer readable medium comprising program instructions, which when executed by one or more processors cause the one or more processors to perform operations comprising:

visually rendering a service-level dashboard reflecting performance of a service, wherein the service comprises a plurality of component services within an information technology environment, and wherein the service-level dashboard presents a visual indication of health of each of the plurality of component services, and a list of events each corresponding to a change in performance of one of the plurality of the component services; and

responsive to receiving, via a graphical user interface (GUI), a selection of a component service of the plurality of component services within the information technology environment:

visually rendering a system-level dashboard reflecting performance of the selected component service,

wherein the selected component service is performed by one or more machines, and the system-level dashboard presents the selected component service, the one or more machines that perform the selected component service, and one or more events corresponding to a selected machine of the one or more machines that perform the selected component service, wherein at least one event is generated for display based on a determination that the at least one event corresponds to a change of a metric score associated with the selected machine exceeding a threshold value for a metric resulting in a transition from a first performance state of the metric to a second performance state of the metric, wherein the at least one event comprises a discrete portion of text machine data describing a corresponding event and associated with a timestamp from the selected machine of the one or more machines.

19. The non-transitory computer readable medium of claim 18 , wherein the system-level dashboard further presents a machine score of each of the one or more machines, the machine score representing a health of a respective machine.

20. The non-transitory computer readable medium of claim 19 , wherein:

the machine score is a composite machine score value that is based on a plurality of metric scores each corresponding to one of a plurality of monitored elements of a respective machine;

the metric score is derived from source data produced by the respective machine, the source data reflected in computer storage as timestamped events and is based at least in part on at least one of the following: system logs, network packet data, sensor data, and performance monitoring application output data; and

the deriving includes identifying at least one field value from the source data of timestamped events by applying an extraction rule of a late-binding schema.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2022
From: HALL, ADRIAN; STERNBERG, KENNETH M.; RAGHAVAN, ANUPADMAJA; REYES, BRIAN C.
To: SPLUNK INC.
Reel/Frame 061551/0839 →
Continuity (4)
Continuation 16554467 · Aug 28, 2019
Continuation 15925570 · Mar 19, 2018
Continuation 14523661 · Oct 24, 2014
Provisional Application 62058043 · Sep 30, 2014
References Cited (34)
US 8412696B2 · Zhang et al. · 2013 [cited by applicant]
US 8589403B2 · Marquardt et al. · 2013 [cited by applicant]
US 8682925B1 · Marquardt et al. · 2014 [cited by applicant]
US 8826434B2 · Merza · 2014 [cited by applicant]
US 9124612B2 · Vasan et al. · 2015 [cited by applicant]
US 9130860B1 · Boe et al. · 2015 [cited by applicant]
US 9130971B2 · Vasan et al. · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 10229243B2 · Poston · 2019 [cited by examiner]
US 10574548B2 · Coates et al. · 2020 [cited by applicant]
US 20020198985A1 · Fraenkel · 2002 [cited by examiner]
US 20050021733A1 · Clinton · 2005 [cited by examiner]
US 20070079243A1 · Leigh · 2007 [cited by examiner]
US 20120182927A1 · Wiesner · 2012 [cited by examiner]
US 20120197848A1 · Bhagwan · 2012 [cited by examiner]
US 20130018686A1 · Wright · 2013 [cited by examiner]
US 20130238403A1 · Benson · 2013 [cited by examiner]
US 20140122711A1 · Lientz · 2014 [cited by examiner]
US 20140160238A1 · Yim et al. · 2014 [cited by applicant]
US 20140324862A1 · Bingham et al. · 2014 [cited by applicant]
US 20150050637A1 · James-Hatter · 2015 [cited by examiner]
US 20150085681A1 · Bowdery · 2015 [cited by examiner]
US 20150106166A1 · Gutierrez, Jr. · 2015 [cited by examiner]
US 20150200824A1 · Sadovsky · 2015 [cited by examiner]
US 20150254955A1 · Fields · 2015 [cited by examiner]
US 20150314681A1 · Riley, Sr. · 2015 [cited by examiner]
US 20160093226A1 · Machluf · 2016 [cited by examiner]
US 20160094411A1 · Brennan · 2016 [cited by examiner]
US 20160267420A1 · Budic · 2016 [cited by examiner]
CN 103399810A · 2013 [cited by examiner]
WO WO2013119200A1 · 2013 [cited by examiner]
Carasso, David, “Exploring Splunk Search Processing Language (SPL) Primer and Cookbook” CITO Research, 2012, 156 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis With a Semi-Structured Time Series Database” SLAML, 2010, 9 pages. [cited by applicant]
VSphere Monitoring and Performance, Update 1, vSphere 5.5, EN-001357-00, 2010-2014, http://pubs.vmware.com/vsphere-55/topic/com.vmware.ICbase/PDF/vsphere-esxi-vcenterserver-551-monitoring-performance-guide.pdf, 174 page… [cited by applicant]