IP Library Granted Patent US 12,197,962
Granted Patent B1
US 12,197,962 · App. 18/169,728 · Granted Jan 14, 2025

Resegmenting chunks of data based on one or more criteria to facilitate load balancing

Inventors: Jag Kerai (San Francisco, CA); Anish Shrigondekar (Sunnyvale, CA); Mitchell Blank, Jr. (San Francisco, CA); Hasan Alayli (San Francisco, CA)
Assignee: SPLUNK INC.
G06F9/5083G06F3/0604G06F3/064G06F3/0683
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,962
App. No.
18/169,728
Granted
Jan 14, 2025
Kind
B1
Abstract

Resegmenting chunks of data for load balancing is disclosed. A plurality of first chunks of data is received. The plurality of first chunks of data includes one or more entries that include raw data produced by a component of an information technology environment and that reflects activity in the information technology environment. The plurality of first chunks of data is resegmented into a plurality of second chunks of data based on a source type of the plurality of first chunks. A first subset of the plurality of second chunks of data is distributed to a first indexer of a set of indexers. An occurrence of a trigger event is determined, and in response to the trigger event, a second subset of the plurality of second chunks of data is distributed to a second indexer of the set of indexers.

Claims (50)

1. A method comprising:

receiving, at a forwarder device, a plurality of first chunks of data comprising one or more entries that include raw data that reflects activity in an information technology environment, wherein respective chunk boundaries of the plurality of first chunks are independent of entry boundaries of the one or more entries, wherein the entry boundaries occur in at least some of the plurality of first chunks, and wherein a first entry of the one or more entries bridges at least two successive chunks in the plurality of first chunks;

determining, at the forwarder device, based on one or more criteria for an entry boundary, a first entry boundary associated with the first entry included in a first chunk in the plurality of first chunks;

segmenting, at the forwarder device, the first chunk into an initial second chunk and a subsequent second chunk based on the first entry boundary;

marking, at the forwarder device, the initial second chunk as an end of entry for the first entry that bridges the at least two successive chunks;

generating a plurality of second chunks that includes the initial second chunk and the subsequent second chunk;

distributing a first subset of the plurality of second chunks to a first indexer of a set of indexers, wherein at least a portion of an incoming query is processed by the first indexer based on at least a portion of the first subset of the plurality of second chunks; and

switching, based at least in part on detecting that the first subset of the plurality of second chunks includes the initial second chunk that is marked as the end of entry, to distribute a second subset of the plurality of second chunks that begins at the subsequent second chunk to a second indexer of the set of indexers.

2. The method of claim 1 , wherein at least one of the one or more criteria comprises a source type associated with the plurality of first chunks.

3. The method of claim 1 , wherein at least one of the one or more criteria comprises a source of the raw data.

4. The method of claim 1 , wherein at least one of the one or more criteria comprises a textual pattern, and determining the first entry boundary comprises matching the textual pattern with data in the first chunk.

5. The method of claim 1 , further comprising:

determining a source type of the plurality of first chunks; and

accessing an entry boundary rule of a plurality of different entry boundary rules based on the source type, wherein the entry boundary rule includes at least one of the one or more criteria.

6. The method of claim 1 , wherein each second chunk of the plurality of second chunks begins or ends on a different entry boundary.

7. The method of claim 1 , wherein distributing the first subset of the plurality of second chunks to the first indexer comprises inserting successive second chunks included in the plurality of second chunks into an output queue associated with the first indexer.

8. The method of claim 1 , wherein at least some of the one or more entries comprise different lengths.

9. The method of claim 1 , wherein receiving the plurality of first chunks comprises receiving a file comprising the plurality of first chunks, wherein each first chunk comprises a block of data from the file.

10. One or more non-transitory computer readable media storing instructions that, when executed by one or more processors, cause the one or more processors to perform the steps of:

receiving, at a forwarder device, a plurality of first chunks of data comprising one or more entries that include raw data that reflects activity in an information technology environment, wherein respective chunk boundaries of the plurality of first chunks are independent of entry boundaries of the one or more entries, wherein the entry boundaries occur in at least some of the plurality of first chunks, and wherein a first entry of the one or more entries bridges at least two successive chunks in the plurality of first chunks;

determining, at the forwarder device, based on one or more criteria for an entry boundary, a first entry boundary associated with the first entry included in a first chunk in the plurality of first chunks;

segmenting, at the forwarder device, the first chunk into an initial second chunk and a subsequent second chunk based on the first entry boundary;

marking, at the forwarder device, the initial second chunk as an end of entry for the first entry that bridges the at least two successive chunks;

generating a plurality of second chunks that includes the initial second chunk and the subsequent second chunk;

distributing a first subset of the plurality of second chunks to a first indexer of a set of indexers, wherein at least a portion of an incoming query is processed by the first indexer based on at least a portion of the first subset of the plurality of second chunks; and

switching, based at least in part on detecting that the first subset of the plurality of second chunks includes the initial second chunk that is marked as the end of entry, to distribute a second subset of the plurality of second chunks that begins at the subsequent second chunk to a second indexer of the set of indexers.

11. The one or more non-transitory computer readable media of claim 10 , wherein at least one of the one or more criteria comprises a source type associated with the plurality of first chunks.

12. The one or more non-transitory computer readable media of claim 10 , wherein at least one of the one or more criteria comprises a source of the raw data.

13. The one or more non-transitory computer readable media of claim 10 , wherein at least one of the one or more criteria comprises a textual pattern, and determining the first entry boundary comprises matching the textual pattern with data in the first chunk.

14. The one or more non-transitory computer readable media of claim 10 , further comprising:

determining a source type of the plurality of first chunks; and

accessing an entry boundary rule of a plurality of different entry boundary rules based on the source type, wherein the entry boundary rule includes at least one of the one or more criteria.

15. The one or more non-transitory computer readable media of claim 10 ,

wherein each second chunk of the plurality of second chunks begins or ends on a different entry boundary.

16. The one or more non-transitory computer readable media of claim 10 , wherein distributing the first subset of the plurality of second chunks to the first indexer comprises inserting successive second chunks included in the plurality of second chunks into an output queue associated with the first indexer.

17. The one or more non-transitory computer readable media of claim 10 , wherein at least some of the one or more entries comprise different lengths.

18. The one or more non-transitory computer readable media of claim 10 , wherein receiving the plurality of first chunks comprises receiving a file comprising the plurality of first chunks, wherein each first chunk comprises a block of data from the file.

19. A computer-system, comprising:

one or more memories storing instructions; and

one or more processors for executing the instructions to:

receive, at a forwarder device, a plurality of first chunks of data comprising one or more entries that include raw data that reflects activity in an information technology environment, wherein respective chunk boundaries of the plurality of first chunks are independent of entry boundaries of the one or more entries, wherein the entry boundaries occur in at least some of the plurality of first chunks, and wherein a first entry of the one or more entries bridges at least two successive chunks in the plurality of first chunks;

determine, at the forwarder device, based on one or more criteria for an entry boundary, a first entry boundary associated with the first entry included in a first chunk in the plurality of first chunks;

segment, at the forwarder device, the first chunk into an initial second chunk and a subsequent second chunk based on the first entry boundary;

mark, at the forwarder device, the initial second chunk as an end of entry for the first entry that bridges the at least two successive chunks;

generate a plurality of second chunks that includes the initial second chunk and the subsequent second chunk;

distribute a first subset of the plurality of second chunks to a first indexer of a set of indexers, wherein at least a portion of an incoming query is processed by the first indexer based on at least a portion of the first subset of the plurality of second chunks; and

switch, based at least in part on detecting that the first subset of the plurality of second chunks includes the initial second chunk that is marked as the end of entry, to distribute a second subset of the plurality of second chunks that begins at the subsequent second chunk to a second indexer of the set of indexers.

20. The system of claim 19 , wherein the one or more processors execute the instructions to:

determine a source type of the plurality of first chunks; and

access an entry boundary rule of a plurality of different entry boundary rules based on the source type, wherein the entry boundary rule includes at least one of the one or more criteria.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2023
From: KERAI, JAG; SHRIGONDEKAR, ANISH; BLANK, MITCHELL, JR.; ALAYLI, HASAN
To: SPLUNK INC.
Reel/Frame 062778/0962 →
Continuity (3)
Continuation 17237904 · Apr 22, 2021
Continuation 16703236 · Dec 4, 2019
Continuation 15420590 · Jan 31, 2017
References Cited (28)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8515963B1 · Blank, Jr. · 2013 [cited by examiner]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9483579B2 · Marquess et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 20080022209A1 · Lyle · 2008 [cited by applicant]
US 20100180337A1 · Bajekal · 2010 [cited by applicant]
US 20130042008A1 · Das et al. · 2013 [cited by applicant]
US 20130332446A1 · Zhou et al. · 2013 [cited by applicant]
US 20140236889A1 · Vasan et al. · 2014 [cited by applicant]
US 20150319234A1 · Wang et al. · 2015 [cited by applicant]
US 20150332010A1 · Olson et al. · 2015 [cited by applicant]
US 20150347523A1 · Patel et al. · 2015 [cited by applicant]
US 20160162197A1 · Effern · 2016 [cited by examiner]
US 20170060469A1 · Luby · 2017 [cited by examiner]
US 20170139996A1 · Marquardt · 2017 [cited by examiner]
US 20170220256A1 · Balasubramonian et al. · 2017 [cited by applicant]
US 20180095782A1 · Driever et al. · 2018 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
Splunk, “Splunk Enterprise 8.0.0 Overview”, available online, retrieved May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk, “Splunk Cloud 8.0.2004 User Manual”, available online, retrieved May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk, “Splunk Quick Reference Guide”, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020, 6 pages. [cited by applicant]
Carasso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, 156 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-Structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”, Vancou… [cited by applicant]