IP Library › Granted Patent US 12,254,019
Granted Patent B2
US 12,254,019 · App. 18/160,972 · Granted Mar 18, 2025

Interactive visualization of a relationship of isolated execution environments

Inventors: Vladimir A. Shcherbakov (San Ramon, CA); Stewart Smith (San Francisco, CA); Nicholas Matthew Tankersley (Seattle, WA); Junyu Wang (Berkeley, CA); Peter Wu (San Francisco, CA)
Assignee: SPLUNK Inc.
G06F16/248G06F16/26G06F3/04817G06F3/0482
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,254,019
App. No.
18/160,972
Filed
Jan 27, 2023
Granted
Mar 18, 2025
Kind
B2
Art Unit
2166
USPC
707/722
Abstract

Systems and methods are described to determine relationships between one or more components of an isolated execution environment system based on data obtained from a data intake and query system. Based on the determined relationships, an interactive visualization is generated that indicates the hierarchical relationship of the components. In some cases, to illustrate the relationship between components of the isolated execution environment system, the visualization can include one or more display objects displayed in a subordinate or superior relationship to other display objects. In certain cases, based on an interaction with a display object, the system can generate a query and/or display additional information and/or visualizations based on the results of the query.

Claims (62)

1. A computer-implemented method, comprising:

obtaining a set of data associated with an isolated execution environment system, wherein the isolated execution environment system comprises a plurality of isolated execution environments, wherein the plurality of isolated execution environments execute on a computing device, and wherein the plurality of isolated execution environments have a first hierarchical relationship with the computing device;

generating, using the plurality of isolated execution environments, log data;

generating, using the set of data, an interactive visualization of a relationship associated with the plurality of isolated execution environments, wherein the interactive visualization includes a first display object representing the computing device and a second display object representing a particular isolated execution environment of the plurality of isolated execution environments;

causing display of the interactive visualization;

in response to a determined interaction with the first display object representing the computing device within the interactive visualization and based at least in part on the first hierarchical relationship:

determining one or more query parameters, and

generating a first query according to the one or more query parameters to obtain a first generated query for retrieving at least a portion of the log data generated by the particular isolated execution environment, wherein in response to each of 1) the determined interaction with the first display object representing the computing device and 2) a determined interaction with the second display object representing the particular isolated execution environment, one or more respective queries are generated for retrieving the same at least a portion of the log data generated by the particular isolated execution environment; and

initiating execution of the first generated query, wherein, based at least in part on initiating execution of the first generated query, the at least a portion of the log data generated by the particular isolated execution environment is retrieved.

2. The computer-implemented method of claim 1 , wherein the second display object representing the particular isolated execution environment is in subordinate relationship to the first display object representing the computing device.

3. The computer-implemented method of claim 1 , wherein one of the first display object representing the computing device or the second display object representing the particular isolated execution environment is:

a nested element of a tree diagram;

an entity representation of an entity relationship diagram; or

a node of a hyperbolic tree diagram.

4. The computer-implemented method of claim 1 , wherein the relationship comprises a second hierarchical relationship.

5. The computer-implemented method of claim 1 , further comprising determining, using the set of data, the relationship.

6. The computer-implemented method of claim 1 , wherein the set of data comprises metadata.

7. The computer-implemented method of claim 1 , wherein the interactive visualization further includes a third display object representing a group associated with the particular isolated execution environment.

8. The computer-implemented method of claim 1 , further comprising:

in response to the determined interaction with the second display object representing the particular isolated execution environment and based at least in part on the second display object representing the particular isolated execution environment, causing generation of one or more queries, wherein the one or more queries comprise a second generated query for retrieving the at least a portion of the log data generated by the particular isolated execution environment, and

initiating execution of the second generated query, wherein, based at least in part on initiating execution of the second generated query, the at least a portion of the log data generated by the particular isolated execution environment is retrieved.

9. The computer-implemented method of claim 1 , wherein the plurality of isolated execution environments execute on a same computing device.

10. The computer-implemented method of claim 1 , wherein the plurality of isolated execution environments are configured to share a compute resource of the computing device during execution.

11. The computer-implemented method of claim 1 , further comprising:

receiving input indicative of a user interaction with the first display object representing the computing device, wherein the determined interaction with the first display object representing the computing device is based on the user interaction; and

causing display of a user interface in response to the input.

12. The computer-implemented method of claim 1 , wherein the isolated execution environment system comprises the computing device.

13. A computing system comprising:

memory; and

one or more processing devices coupled to the memory and configured to:

obtain a set of data associated with an isolated execution environment system, wherein the isolated execution environment system comprises a plurality of isolated execution environments, wherein the plurality of isolated execution environments execute on a computing device, and wherein the plurality of isolated execution environments have a first hierarchical relationship with the computing device;

generate, using the plurality of isolated execution environments, log data;

generate, using the set of data, an interactive visualization of a relationship associated with the plurality of isolated execution environments, wherein the interactive visualization includes a first display object representing the computing device and a second display object representing a particular isolated execution environment of the plurality of isolated execution environments;

cause display of the interactive visualization;

in response to a determined interaction with the first display object representing the computing device within the interactive visualization and based at least in part on the first hierarchical relationships;

determine one or more query parameters, and

generate a first query according to the one or more query parameters to obtain a first generated query for retrieving at least a portion of the log data generated by the particular isolated execution environment, wherein in response to each of 1) the determined interaction with the first display object representing the computing device and 2) a determined interaction with the second display object representing the particular isolated execution environment, one or more respective queries are generated for retrieving the same at least a portion of the log data generated by the particular isolated execution environment; and

initiate execution of the first generated query, wherein, based at least in part on initiating execution of the first generated query, the at least a portion of the log data generated by the particular isolated execution environment is retrieved.

14. The computing system of claim 13 , wherein the plurality of isolated execution environments are configured to share a compute resource of the computing device during execution.

15. The computing system of claim 13 , wherein the one or more processing devices are further configured to:

receive input indicative of a user interaction with the first display object representing the computing device, wherein the determined interaction with the first display object representing the computing device is based on the user interaction; and

cause display of a user interface in response to the input.

16. The computing system of claim 13 , wherein one of the first display object representing the computing device or the second display object representing the particular isolated execution environment is:

a nested element of a tree diagram;

an entity representation of an entity relationship diagram; or

a node of a hyperbolic tree diagram.

17. Non-transitory computer-readable media including computer-executable instructions that, when executed by a computing system, cause the computing system to:

obtain a set of data associated with an isolated execution environment system, wherein the isolated execution environment system comprises a plurality of isolated execution environments, wherein the plurality of isolated execution environments execute on a computing device, and wherein the plurality of isolated execution environments have a first hierarchical relationship with the computing device;

generate, using the plurality of isolated execution environments, log data;

generate, using the set of data, an interactive visualization of a relationship associated with the plurality of isolated execution environments, wherein the interactive visualization includes a first display object representing the computing device and a second display object representing a particular isolated execution environment of the plurality of isolated execution environments;

cause display of the interactive visualization;

in response to a determined interaction with the first display object representing the computing device within the interactive visualization and based at least in part on the first hierarchical relationship;

determine one or more query parameters, and

generate a first query according to the one or more query parameters to obtain a first generated query for retrieving at least a portion of the log data generated by the particular isolated execution environment, wherein in response to each of 1) the determined interaction with the first display object representing the computing device and 2) a determined interaction with the second display object representing the particular isolated execution environment, one or more respective queries are generated for retrieving the same at least a portion of the log data generated by the particular isolated execution environment; and

initiate execution of the first generated query, wherein, based at least in part on initiating execution of the first generated query, the at least a portion of the log data generated by the particular isolated execution environment is retrieved.

18. The non-transitory computer-readable media of claim 17 , wherein the plurality of isolated execution environments are configured to share a compute resource of the computing device during execution.

19. The non-transitory computer-readable media of claim 17 , wherein execution of the computer-executable instructions by the computing system, further causes the computing system to:

receive input indicative of a user interaction with the first display object representing the computing device, wherein the determined interaction with the first display object representing the computing device is based on the user interaction; and cause display of a user interface in response to the input.

20. The non-transitory computer-readable media of claim 17 , wherein one of the first display object representing the computing device or the second display object representing the particular isolated execution environment is:

a nested element of a tree diagram;

an entity representation of an entity relationship diagram; or

a node of a hyperbolic tree diagram.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2023
From: SHCHERBAKOV, VLADIMIR A.; SMITH, STEWART; TANKERSLEY, NICHOLAS MATTHEW; WANG, JUNYU; WU, PETER
To: SPLUNK INC.
Reel/Frame 062552/0939 →
Continuity (3)
Continuation 17143063 · Jan 6, 2021
Continuation 16148918 · Oct 1, 2018
Related Publication 20230169084A1 · Jun 1, 2023
References Cited (153)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8060466B1 · Round et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 8983912B1 · Beedgen et al. · 2015 [cited by applicant]
US 9135560B1 · Saurabh et al. · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9262519B1 · Saurabh · 2016 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9342571B1 · Kurtic et al. · 2016 [cited by applicant]
US 9853986B2 · Dash et al. · 2017 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10171312B2 · Kannan et al. · 2019 [cited by applicant]
US 10223145B1 · Neogy et al. · 2019 [cited by applicant]
US 10242062B2 · Turner · 2019 [cited by applicant]
US 10346775B1 · Xu et al. · 2019 [cited by applicant]
US 10419469B1 · Singh et al. · 2019 [cited by applicant]
US 10445311B1 · Saurabh et al. · 2019 [cited by applicant]
US 10474656B1 · Bronnikov et al. · 2019 [cited by applicant]
US 10547521B1 · Roy et al. · 2020 [cited by applicant]
US 10762746B2 · Liang et al. · 2020 [cited by applicant]
US 10929415B1 · Shcherbakov et al. · 2021 [cited by applicant]
US 11238012B1 · Liang et al. · 2022 [cited by applicant]
US 11537627B1 · Baskaran et al. · 2022 [cited by applicant]
US 11567960B2 · Shcherbkov et al. · 2023 [cited by applicant]
US 11886455B1 · Baskaran et al. · 2024 [cited by applicant]
US 20050114707A1 · DeStefano et al. · 2005 [cited by applicant]
US 20070174429A1 · Mazzaferri et al. · 2007 [cited by applicant]
US 20070283194A1 · Villella et al. · 2007 [cited by applicant]
US 20080162592A1 · Huang et al. · 2008 [cited by applicant]
US 20100185961A1 · Fisher et al. · 2010 [cited by applicant]
US 20110035248A1 · Juillard · 2011 [cited by applicant]
US 20120246303A1 · Petersen et al. · 2012 [cited by applicant]
US 20120259825A1 · Tashiro et al. · 2012 [cited by applicant]
US 20120310899A1 · Wasserman et al. · 2012 [cited by applicant]
US 20130042123A1 · Smith et al. · 2013 [cited by applicant]
US 20130117676A1 · De Pauw · 2013 [cited by examiner]
US 20130227349A1 · Nodir et al. · 2013 [cited by applicant]
US 20130332424A1 · Nos et al. · 2013 [cited by applicant]
US 20130332588A1 · Maytal et al. · 2013 [cited by applicant]
US 20140040182A1 · Gilder et al. · 2014 [cited by applicant]
US 20140047099A1 · Flores et al. · 2014 [cited by applicant]
US 20140229607A1 · Jung et al. · 2014 [cited by applicant]
US 20140278807A1 · Bohacek · 2014 [cited by applicant]
US 20140278808A1 · Iyoob et al. · 2014 [cited by applicant]
US 20140279201A1 · Iyoob et al. · 2014 [cited by applicant]
US 20140324647A1 · Iyoob et al. · 2014 [cited by applicant]
US 20140330832A1 · Viau · 2014 [cited by applicant]
US 20150039651A1 · Kinsely et al. · 2015 [cited by applicant]
US 20150039757A1 · Petersen et al. · 2015 [cited by applicant]
US 20150149879A1 · Miller et al. · 2015 [cited by applicant]
US 20150180891A1 · Seward et al. · 2015 [cited by applicant]
US 20150271109A1 · Bullotta et al. · 2015 [cited by applicant]
US 20150309710A1 · Ashoori · 2015 [cited by examiner]
US 20150341240A1 · Iyoob et al. · 2015 [cited by applicant]
US 20150363851A1 · Stella et al. · 2015 [cited by applicant]
US 20150369664A1 · Garsha et al. · 2015 [cited by applicant]
US 20160019636A1 · Adapalli et al. · 2016 [cited by applicant]
US 20160036903A1 · Pal et al. · 2016 [cited by applicant]
US 20160043892A1 · Hason et al. · 2016 [cited by applicant]
US 20160092475A1 · Stojanovic et al. · 2016 [cited by applicant]
US 20160092558A1 · Ago et al. · 2016 [cited by applicant]
US 20160094477A1 · Bai et al. · 2016 [cited by applicant]
US 20160180557A1 · Yousaf et al. · 2016 [cited by applicant]
US 20160198003A1 · Luft · 2016 [cited by applicant]
US 20160246844A1 · Turner · 2016 [cited by applicant]
US 20160271500A1 · Nath et al. · 2016 [cited by applicant]
US 20160282858A1 · Michalscheck et al. · 2016 [cited by applicant]
US 20160292166A1 · Russel · 2016 [cited by applicant]
US 20160359955A1 · Gill et al. · 2016 [cited by applicant]
US 20170046445A1 · Cormier et al. · 2017 [cited by applicant]
US 20170061339A1 · Littlejohn et al. · 2017 [cited by applicant]
US 20170085446A1 · Zhong et al. · 2017 [cited by applicant]
US 20170085447A1 · Chen et al. · 2017 [cited by applicant]
US 20170093645A1 · Zhong et al. · 2017 [cited by applicant]
US 20170116321A1 · Jain et al. · 2017 [cited by applicant]
US 20170228460A1 · Amel et al. · 2017 [cited by applicant]
US 20170295181A1 · Parimi et al. · 2017 [cited by applicant]
US 20170364538A1 · Jacob et al. · 2017 [cited by applicant]
US 20170364540A1 · Sigler · 2017 [cited by applicant]
US 20180012166A1 · Devadas et al. · 2018 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180115463A1 · Sinha et al. · 2018 [cited by applicant]
US 20180165142A1 · Harutyunyan et al. · 2018 [cited by applicant]
US 20180225345A1 · Gilder et al. · 2018 [cited by applicant]
US 20180246797A1 · Modi et al. · 2018 [cited by applicant]
US 20180321927A1 · Borthakur et al. · 2018 [cited by applicant]
US 20180336027A1 · Narayanan et al. · 2018 [cited by applicant]
US 20180367412A1 · Sethi et al. · 2018 [cited by applicant]
US 20190018717A1 · Feijoo et al. · 2019 [cited by applicant]
US 20190018844A1 · Bhagwat et al. · 2019 [cited by applicant]
US 20190052542A1 · Passante et al. · 2019 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190155953A1 · Brown et al. · 2019 [cited by applicant]
US 20190190773A1 · Shi et al. · 2019 [cited by applicant]
US 20190306236A1 · Wiener et al. · 2019 [cited by applicant]
US 20190310977A1 · Pal et al. · 2019 [cited by applicant]
US 20190312939A1 · Noble · 2019 [cited by applicant]
US 20190324962A1 · Turner · 2019 [cited by applicant]
US 20190342372A1 · Lee et al. · 2019 [cited by applicant]
US 20190379590A1 · Rimar et al. · 2019 [cited by applicant]
US 20190386891A1 · Chitalia et al. · 2019 [cited by applicant]
US 20200026624A1 · Parthasarathy et al. · 2020 [cited by applicant]
US 20200034484A1 · Arora et al. · 2020 [cited by applicant]
US 20200134359A1 · Kim et al. · 2020 [cited by applicant]
US 20200099610A1 · Heron · 2020 [cited by applicant]
US 20210105597A1 · Wright et al. · 2021 [cited by applicant]
US 20210224259A1 · Shcherbakov · 2021 [cited by applicant]
US 20220300464A1 · Liang et al. · 2022 [cited by applicant]
US 20240152488A1 · Liang · 2024 [cited by applicant]
KR 101810762B1 · 2017 [cited by applicant]
U.S. Appl. No. 15/979,933, filed May 15, 2018, Liang et al. [cited by applicant]
U.S. Appl. No. 15/980,008, filed May 15, 2018, Modestino et al. [cited by applicant]
U.S. Appl. No. 18/146,256, filed Dec. 23, 2022, Baskaran et al. [cited by applicant]
Add Docker metadata, Filebeat Reference 6.0, https://www.elastic.co/guide/en/beats/filebeat/6.0/add-docker-metadata.html, software version (6.0.0) realized 2017. [cited by applicant]
Beats Version 5.0.0. Release Notes [relating to version 5.0, allegedly released Oct. 2016] [online], [retrieved on Jan. 31, 2020]. Retrieved from the Internet :< URL: https://www.elastic.co/guide/en/beats/libbeat/curren… [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Filebeat Prospectors Configuration. Filebeat Reference [relating to version 5.0, allegedly released Oct. 2016] [version 5.0 allegedly released Oct. 2016] [online], [retrieved on Jan. 31, 2020]. Retrieved from the Intern… [cited by applicant]
Perez-Aradros, C. Enriching Logs with Docker Metadata Using Filebeat. Elastic Blog [online], Jul. 2017 [retrieved on Jan. 31, 2020]. Retrieved from the Internet: < URL: https://www.elastic.co/blog/enrich-docker-logs-wit… [cited by applicant]
Perez-Aradros, C. Shipping Kubernetes Logs to Elasticsearch with Filebeat. Elastic Blog [online], Nov. 2017 [retrieved on Jan. 31, 2020]. Retrieved from the Internet: < URL: https://www.elastic.co/blog/shipping-kubernet… [cited by applicant]
Set up Prospectors. Filebeat Reference [relating to version 6.2, allegedly released Feb. 2018] [online], [retrieved on Jan. 31, 2020]. Retrieved from the Internet: < URL: https://www.elastic.co/guide/en/beats/filebeat/6… [cited by applicant]
SLAML 10 Reports, Workshop On Managing Systems via Log Analysis and Machine Learning Techniques, ;login: Feb. 2011 Conference Reports. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
TSG. ‘Second proposal for JSON support’. In Elastic/Beats Pull Requests [online], Mar. 2016 [retrieved on Jan. 31, 2020]. Retrieved from the internet: <URL: https://github.com/elastic/beats/pull/1143>. [cited by applicant]
Vaid, Workshop on Managing Systems via log Analysis and Machine Learning Techniques (SLAML '10), ;login: vol. 36, No. 1, Oct. 3, 2010, Vancouver, BC, Canada. [cited by applicant]
Office Action in U.S. Appl. No. 15/979,933, dated Feb. 20, 2020, 17 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 15/979,933, dated Aug. 19, 2020 in 23 pages. [cited by applicant]
Office Action in U.S. Appl. No. 15/979,933, dated May 18, 2021 in 22 pages. [cited by applicant]
Office Action in U.S. Appl. No. 15/980,008, dated May 7, 2020, 11 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 15/980,008, dated Oct. 20, 2020, in 19 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 15/980,008, dated May 13, 2021, in 13 pages. [cited by applicant]
Office Action in U.S. Appl. No. 16/262,746, dated Mar. 29, 2019, 14 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 16/262,746, dated Oct. 16, 2019, 15 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 16/262,746, dated Jan. 30, 2020, 17 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 16/262,746, dated Mar. 23, 2020, 9 pages. [cited by applicant]
Office Action in U.S. Appl. No. 17/143,063 dated Feb. 18, 2022 in 15 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 17/143,063 dated Jul. 18, 2022 in 7 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 17/143,063 dated Sep. 28, 2022 in 9 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 15/979,933, dated Sep. 17, 2021 in 12 pages. [cited by applicant]
Office Action in U.S. Appl. No. 16/147,181 dated Dec. 21, 2020 in 31 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 16/147,181 dated Jun. 25, 2021 in 28 pages. [cited by applicant]
Office Action in U.S. Appl. No. 16/147,181 dated Nov. 12, 2021 in 27 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 16/147,181 dated Aug. 19, 2022 in 10 pages. [cited by applicant]
Office Action in U.S. Appl. No. 16/148,918 dated May 18, 2020, in 12 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 16/148,918 dated Oct. 6, 2020, in 10 pages. [cited by applicant]
Office Action in U.S. Appl. No. 18/146,256 dated May 12, 2023 in 22 pages. [cited by applicant]
Office Action in U.S. Appl. No. 17/305,550 dated May 26, 2023 in 41 pages. [cited by applicant]
Beach, et.: Pro PowerShell for Amazon Web Services; 2nd edition (Year: 2019). [cited by applicant]
U.S. Appl. No. 18/504,491, filed Nov. 8, 2023, Liang et al. [cited by applicant]