IP Library Granted Patent US 12,572,544
Granted Patent B1
US 12,572,544 · App. 18/159,028 · Granted Mar 10, 2026

Monitoring search performance for scheduled searches at a component level granularity

Inventor: Jay A. Pathak (Newark, CA)
Assignee: Cisco Technology, Inc.
G06F16/24545G06F16/2462G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,572,544
App. No.
18/159,028
Granted
Mar 10, 2026
Kind
B1
Abstract

A computer-implemented method for tracking search performance includes executing a search query at a first computing device and computing a runtime for each of one or more components of the search query. The method also includes comparing a respective runtime for each of the one or more components with a respective threshold value, wherein the respective threshold value for each of the one or more components is based on a respective statistic determined using runtimes from prior executions of the search query. Further, responsive to determining that the respective runtime is higher than the threshold value, the method includes transmitting an alert to a second computing device in a cloud computing environment.

Claims (46)

1 . A computer-implemented method, comprising:

executing a search query at a first computing device in a cloud computing environment;

computing a first runtime for a first component of the search query and a second runtime for a second component of the search query, wherein the first component comprises a first search command and the second component comprises a second search command;

comparing the first computed runtime for the first component with a first threshold value and the second computed runtime for the second component with a second threshold value, wherein the first threshold value for the first component is based on a respective statistic determined by correlating historical computed runtimes for the first component across prior executions of the search query using a unique identifier assigned to the first component;

responsive to determining that the first computed runtime is higher than the first threshold value or the second computed runtime is higher than the second threshold value, transmitting an alert to a second computing device in the cloud computing environment;

identifying, based on the alert, a cause of search degradation in association with a particular component of the search query;

for a plurality of subsequent executions of the search query, comparing a computed runtime for each of one or more components to a respective threshold value;

for each of the one or more components, maintaining a count associated with instances of runtimes for a respective component exceeding the respective threshold value; and

reporting the count for each of the one or more components to the second computing device on a periodic basis.

2 . The computer-implemented method of claim 1 , wherein the respective statistic on which the first threshold value is based is a variance.

3 . The computer-implemented method of claim 1 , wherein the first computing device comprises a search head implemented in a stack in the cloud computing environment, wherein the stack comprises a group of computing devices dedicated to an entity with a subscription to utilize a portion of computing resources available in the cloud computing environment, and wherein the entity with the subscription submits the search query to the first computing device.

4 . The computer-implemented method of claim 1 , wherein the first computing device comprises a search head implemented in a stack in the cloud computing environment, wherein the stack comprises a group of computing devices dedicated to an entity with a subscription to utilize a portion of computing resources available in the cloud computing environment, and wherein the second computing device is controlled by a provider of the cloud computing environment and is separate from the group of computing devices in the stack.

5 . The computer-implemented method of claim 1 , wherein the first computing device comprises a search head implemented in a stack in the cloud computing environment, wherein the stack comprises a group of computing devices dedicated to an entity with a subscription to utilize a portion of computing resources available in the cloud computing environment, wherein the entity with the subscription submits the search query to the first computing device, wherein the second computing device is associated with a second entity providing the computing resources and separate from the group of computing devices in the stack, and wherein a monitoring application installed on the second computing device monitors a performance of searches executing on the stack.

6 . The computer-implemented method of claim 1 , wherein the first computing device is associated with a client of the cloud computing environment, wherein the second computing device is associated with a provider of the cloud computing environment, and wherein a monitoring application installed on the second computing device monitors a performance of searches executed on the first computing device.

7 . The computer-implemented method of claim 1 , wherein the respective statistic on which the first threshold value is based is a variance, and wherein the unique identifier assigned to the first component is consistent across multiple executions of the search query.

8 . The computer-implemented method of claim 1 , further comprising: at the second computing device, maintaining a count of alerts received from the first computing device for each of the one or more components.

9 . The computer-implemented method of claim 1 , further comprising:

at the second computing device, maintaining an aggregate count of alerts received from the first computing device; and

comparing the aggregate count of alerts from the first computing device to a second count of alerts received from a third computing device, wherein the third computing device is associated with a first stack that is different from a second stack associated with the first computing device.

10 . A computing system, comprising:

one or more processors; and

one or more non-transitory computer-readable media having stored thereon instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including:

executing a search query at a first computing device in a cloud computing environment;

computing a first runtime for a first component of the search query and a second runtime for a second component of the search query, wherein the first component comprises a first search command and the second component comprises a second search command;

comparing the first computed runtime for the first component with a first threshold value and the second computed runtime for the second component with a second threshold value, wherein the first threshold value for the first component is based on a respective statistic determined by correlating historical computed runtimes for the first component across prior executions of the search query using a unique identifier assigned to the first component;

responsive to determining that the first computed runtime is higher than the first threshold value or the second computed runtime is higher than the second threshold value, transmitting an alert to a second computing device in the cloud computing environment;

identifying, based on the alert, a cause of search degradation in association with a particular component of the search query;

for a plurality of subsequent executions of the search query, comparing a computed runtime for each of one or more components to a respective threshold value;

for each of the one or more components, maintaining a count associated with instances of runtimes for a respective component exceeding the respective threshold value; and

reporting the count for each of the one or more components to the second computing device on a periodic basis.

11 . The computing system of claim 10 , wherein the respective statistic on which the first threshold value is based is a variance.

12 . The computing system of claim 10 , wherein the first computing device comprises a search head implemented in a stack in the cloud computing environment, wherein the stack comprises a group of computing devices dedicated to an entity with a subscription to utilize a portion of computing resources available in the cloud computing environment, and wherein the entity with the subscription submits the search query to the first computing device.

13 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processor to perform operations including:

executing a search query at a first computing device in a cloud computing environment;

computing a first runtime for a first component of the search query and a second runtime for a second component of the search query, wherein the first component comprises a first search command and the second component comprises a second search command;

comparing the first computed runtime for the first component with a first threshold value and the second computed runtime for the second component with a second threshold value, wherein the first threshold value for the first component is based on a respective statistic determined by correlating historical computed runtimes for the first component across prior executions of the search query using a unique identifier assigned to the first component;

responsive to determining that the first computed runtime is higher than the first threshold value or the second computed runtime is higher than the second threshold value, transmitting an alert to a second computing device in the cloud computing environment;

identifying, based on the alert, a cause of search degradation in association with a particular component of the search query;

for a plurality of subsequent executions of the search query, comparing a computed runtime for each of one or more components to a respective threshold value;

for each of the one or more components, maintaining a count associated with instances of runtimes for a respective component exceeding the respective threshold value; and

reporting the count for each of the one or more components to the second computing device on a periodic basis.

14 . The non-transitory computer-readable medium of claim 13 , wherein the respective statistic on which the first threshold value is based is a variance.

15 . The non-transitory computer-readable medium of claim 13 , wherein the first computing device comprises a search head implemented in a stack in the cloud computing environment, wherein the stack comprises a group of computing devices dedicated to an entity with a subscription to utilize a portion of computing resources available in the cloud computing environment, and wherein the entity with the subscription submits the search query to the first computing device.

16 . The non-transitory computer-readable medium of claim 14 , wherein the first computing device comprises a search head implemented in a stack in the cloud computing environment, wherein the stack comprises a group of computing devices dedicated to an entity with a subscription to utilize a portion of computing resources available in the cloud computing environment, and wherein the second computing device is controlled by a provider of the cloud computing environment and is separate from the group of computing devices in the stack.

17 . The non-transitory computer-readable medium of claim 14 , wherein the first computing device is associated with a client of the cloud computing environment, wherein the second computing device is associated with a provider of the cloud computing environment, and wherein a monitoring application installed on the second computing device monitors a performance of searches executed on the first computing device.

18 . The non-transitory computer-readable medium of claim 14 , wherein the respective statistic on which the first threshold value is based is a variance, and wherein the unique identifier assigned to the first component is consistent across multiple executions of the search query.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2023
From: PATHAK, JAY A.
To: SPLUNK INC.
Reel/Frame 062498/0870 →
References Cited (28)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 20070143438A1 · Citrin et al. · 2007 [cited by applicant]
US 20090106756A1 · Feng et al. · 2009 [cited by applicant]
US 20100198806A1 · Graefe et al. · 2010 [cited by applicant]
US 20130054582A1 · Macklem et al. · 2013 [cited by applicant]
US 20150046530A1 · Mieritz et al. · 2015 [cited by applicant]
US 20170124220A1 · Krueger et al. · 2017 [cited by applicant]
US 20170220685A1 · Yan et al. · 2017 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190272271A1 · Bhattacharjee · 2019 [cited by examiner]
US 20220027754A1 · Singh et al. · 2022 [cited by applicant]
US 20220261287A1 · Dwivedi et al. · 2022 [cited by applicant]
US 20230077774A1 · Ocariza · 2023 [cited by applicant]
US 20230229659A1 · Beresniewicz · 2023 [cited by examiner]
JP 2006067129A · 2006 [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Final Office Action received for U.S. Appl. No. 18/159,025 dated Sep. 10, 2024, 20 pages. [cited by applicant]
Non Final Office Action received for U.S. Appl. No. 18/159,025 dated Jun. 4, 2024, 20 pages. [cited by applicant]