IP Library › Granted Patent US 12,079,255
Granted Patent B1
US 12,079,255 · App. 17/978,681 · Granted Sep 3, 2024

Systems and methods for updating a status indication in a system providing dynamic indexer discovery

Inventors: Vishal Patel (San Francisco, CA); Jagannath Kerai (Cupertino, CA); Hasan Alayli (San Francisco, CA)
Assignee: SPLUNK INC.
G06F16/328G06F16/1734
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,079,255
App. No.
17/978,681
Filed
Nov 1, 2022
Granted
Sep 3, 2024
Kind
B1
Art Unit
2169
USPC
707/741
Abstract

The present invention is related to a method for providing dynamic indexer discovery. The method comprises receiving, from an index manager, a status indication associated with a plurality of indexers, wherein each of the plurality of indexers indexes events of raw machine-generated data received from a plurality of data collectors. The method further comprises determining a weight associated with each of the plurality of indexers and selecting an indexer from the plurality of indexers. Subsequently, the method comprises allocating data to the indexer in accordance with a respective weight assigned to the indexer and transmitting the allocated data to the indexer.

Claims (39)

1. A method comprising:

receiving a status message from an indexer associated with a set of indexers, wherein each indexer in the set of indexers indexes events of raw machine generated data that are received from a plurality of data collectors, and wherein an index manager tracks a respective status for each indexer in the set of indexers;

updating a status indication associated with the indexer based on the status message;

determining a time duration between a receipt of a prior status message and the status message; and

in response to determining that the time duration exceeds a predetermined threshold, removing the indexer from the set of indexers that index events of raw machine generated data from the plurality of data collectors.

2. The method of claim 1 , wherein the events of raw machine-generated data are each associated with a respective time stamp.

3. The method of claim 1 , wherein the status indication is selected from a group including a status list, a status directory and a status table.

4. The method of claim 1 , wherein the status message is received by the index manager at a pre-determined time.

5. The method of claim 1 , further comprising:

in response to determining that the time duration does not exceed the predetermined threshold, receiving a subsequent status message from the indexer at a periodic time interval after the status message.

6. The method of claim 1 , further comprising:

in response to determining that the time duration does not exceed the predetermined threshold, waiting to receive a subsequent status message from the indexer.

7. The method of claim 1 , wherein the updating comprises:

comparing one or more performance metrics associated with the indexer; and

performing the updating based on a result of the comparing.

8. The method of claim 1 , wherein the status indication comprises a link to the status indication maintained at a remote site.

9. The method of claim 1 , wherein the status indication comprises a read-only instantiation of the status indication.

10. The method of claim 1 , wherein the status indication is stored in a datastore.

11. The method of claim 1 , wherein the predetermined threshold is configurable.

12. The method of claim 1 , further comprising:

in response to determining that the time duration does not exceed the predetermined threshold, receiving a subsequent status message from the indexer at a periodic time interval after the status message, wherein the periodic time interval is configured to be dynamically adjustable by the index manager.

13. The method of claim 1 , wherein the status message may include a performance metric associated with the indexer, wherein the performance metric is related to one or more of: a disk capacity, a storage capacity and a processing capacity.

14. A non-transitory computer-readable medium storing computer-executable instructions which, when executed by a processor, cause the processor to perform operations comprising:

receiving a status message from an indexer associated with a set of indexers, wherein each indexer in the set of indexers indexes events of raw machine generated data that are received from a plurality of data collectors, and wherein the index manager tracks a respective status for each indexer in the set of indexers;

updating a status indication associated with the indexer based on the status message;

determining a time duration between a receipt of a prior status message and the status message; and

in response to determining that the time duration exceeds a predetermined threshold, removing the indexer from the set of indexers that index events of raw machine generated data from the plurality of data collectors.

15. The non-transitory computer-readable medium of claim 14 , wherein the events of raw machine-generated data are each associated with a respective time stamp.

16. The non-transitory computer-readable medium of claim 14 , wherein the status indication is selected from a group including a status list, a status directory and a status table.

17. The non-transitory computer-readable medium of claim 14 , wherein the status message is received by an index manager at a pre-determined time.

18. The non-transitory computer-readable medium of claim 14 , wherein the operations further comprise: in response to determining that the time duration does not exceed the predetermined threshold, receiving a subsequent status message from the indexer at a periodic time interval after the status message.

19. The non-transitory computer-readable medium of claim 14 , wherein the operations further comprise: in response to determining that the time duration does not exceed the predetermined threshold, waiting to receive a subsequent status message from the indexer.

20. A system comprising:

one or more processors; and

one or more memories comprising program instructions stored thereon that are executable by the one or more processors to cause:

receiving a status message from an indexer associated with a set of indexers, wherein each indexer in the set of indexers indexes events of raw machine generated data that are received from a plurality of data collectors, and wherein the index manager tracks a respective status for each indexer in the set of indexers;

updating a status indication associated with the indexer based on the status message;

determining a time duration between a receipt of a prior status message and the status message; and

in response to determining that the time duration exceeds a predetermined threshold, removing the indexer from the set of indexers that index events of raw machine generated data from the plurality of data collectors.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2022
From: PATEL, VISHAL; KERAI, JAGANNATH; ALAYLI, HASAN
To: SPLUNK INC.
Reel/Frame 062141/0719 →
Continuity (2)
Continuation 16353886 · Mar 14, 2019
Continuation 14700844 · Apr 30, 2015
Cited By (1)
US 12,265,855