IP Library Granted Patent US 12,675,461
Granted Patent B1
US 12,675,461 · App. 18/170,445 · Granted Jul 7, 2026

Systems and methods for coordinated summarization of indexed data

Inventors: David Marquardt (San Jose, CA); Xiaowei Wang (San Jose, CA)
Assignee: Cisco Technology, Inc.
G06F16/2343G06F16/13G06F16/2228G06F16/2365G06F16/245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,675,461
App. No.
18/170,445
Filed
Feb 16, 2023
Granted
Jul 7, 2026
Kind
B1
Art Unit
2164
USPC
707/704
Abstract

Provided are systems and methods for concurrent summarization of indexed data. In some embodiments, two or more summary processes can be executed concurrently (e.g., in parallel) by an indexer to generate summaries for respective subsets of indexed data (e.g., partitions or buckets of indexed data) managed by the indexer.

Claims (65)

1 . A method of executing a scheduled summary request, said method comprising:

generating a set of time-stamped event records from raw machine data;

indexing and storing the set of time-stamped event records in two or more buckets of event records;

scheduling a summary request for a first bucket of the two or more buckets to be executed by a plurality of indexers;

locking a first summary directory associated with the first bucket;

writing first summary data for the first bucket to the first summary directory, wherein the first summary data comprises at least one summary file that includes a summary representing a statistic associated with data in the first bucket and an indication that an entirety of contents of the first bucket is summarized based on determining a completion of the set of time-stamped event records being stored to the first bucket and summarization of the set of time-stamped event records stored in the first bucket;

unlocking the first summary directory; and

responsive to the indication that the entirety of contents of the first bucket is summarized, writing second summary data for a second bucket to a second summary directory.

2 . The method of claim 1 , wherein the two or more buckets are stored in a memory of an indexer.

3 . The method of claim 2 , further comprising receiving the summary request at the indexer from one or more search heads.

4 . The method of claim 1 , wherein each of the two or more buckets is associated with a timespan and comprises time-stamped event records having a respective timestamp corresponding to a respective time in the timespan.

5 . The method of claim 1 , further comprising:

receiving, from an entity, a request for the second summary data; and

providing, to the entity, the second summary data for the second bucket responsive to the request, wherein the entity is configured to generate a result based at least in part on contents of the second summary data for the second bucket.

6 . The method of claim 1 , wherein the second summary data comprises a first subset of values of fields of events corresponding to a data model, and further comprising:

receiving, from an entity, a request for summary data; and

providing, to the entity, the second summary data, wherein the entity is configured to generate a set of values for the data model determined based at least in part on the first subset of values of fields.

7 . The method of claim 6 , wherein the summary request is scheduled responsive to enabling acceleration of the data model.

8 . The method of claim 1 , wherein the summary request is scheduled responsive to enabling acceleration of a report.

9 . The method of claim 1 , further comprising:

receiving a search request;

generating search results based at least in part on the first summary data for the first bucket; and

providing the search results in response to the search request.

10 . The method of claim 1 , further comprising:

responsive to an indication that the entirety of contents of the first bucket is not summarized, updating first summary data based on processing an un-summarized portion of the first bucket.

11 . The method of claim 1 , further comprising:

determining whether the second summary directory associated with the second bucket is not currently locked by a concurrent process prior to writing second summary data for the second bucket to the second summary directory.

12 . The method of claim 1 , further comprising:

responsive to the indication that the entirety of contents of the first bucket is not summarized, updating the first summary data based on processing an un-summarized portion of the first bucket.

13 . The method of claim 1 , further comprising:

determining whether the second summary directory associated with the second bucket is not currently locked by a concurrent process prior to writing the second summary data for the second bucket to the second summary directory.

14 . One or more non-transitory computer readable media storing instructions that, when executed by one or more processors, cause the one or more processors to perform steps of:

generating a set of time-stamped event records from raw machine data;

indexing and storing the set of time-stamped event records in two or more buckets of event records;

scheduling a summary request for a first bucket of the two or more buckets to be executed by a plurality of indexers;

locking a first summary directory associated with the first bucket;

writing first summary data for the first bucket to the first summary directory, wherein the first summary data comprises at least one summary file that includes a summary representing a statistic associated with data in the first bucket and an indication that an entirety of contents of the first bucket is summarized based on determining a completion of the set of time-stamped event records being stored to the first bucket and summarization of the set of time-stamped event records stored in the first bucket;

unlocking the first summary directory; and

responsive to the indication that the entirety of contents of the first bucket is summarized, writing second summary data for a second bucket to a second summary directory.

15 . The one or more non-transitory computer readable media of claim 12 , wherein each of the two or more buckets is associated with a timespan and comprises time-stamped event records having a respective timestamp corresponding to a respective time in the timespan.

16 . The one or more non-transitory computer readable media of claim 12 , wherein the steps further comprise:

receiving, from an entity, a request for the second summary data; and

providing, to the entity, the second summary data for the second bucket responsive to the request, wherein the entity is configured to generate a result based at least in part on contents of the second summary data for the second bucket.

17 . The one or more non-transitory computer readable media of claim 12 , wherein the second summary data comprises a first subset of values of fields of events corresponding to a data model, and further comprising:

receiving, from an entity, a request for summary data; and

providing, to the entity, the second summary data, wherein the entity is configured to generate a set of values for the data model determined based at least in part on the first subset of values of fields.

18 . The one or more non-transitory computer readable media of claim 17 , wherein the summary request is scheduled responsive to enabling acceleration of the data model.

19 . The one or more non-transitory computer readable media of claim 12 , wherein the summary request is scheduled responsive to enabling acceleration of a report.

20 . The one or more non-transitory computer readable media of claim 12 , wherein the steps further comprise:

receiving a search request;

generating search results based at least in part on the first summary data for the first bucket; and

providing the search results in response to the search request.

21 . A system, comprising:

one or more memories storing instructions; and

one or more processors for executing the instructions to:

generating a set of time-stamped event records from raw machine data;

indexing and storing the set of time-stamped event records in two or more buckets of event records;

scheduling a summary request for a first bucket of the two or more buckets to be executed by a plurality of indexers;

locking a first summary directory associated with the first bucket;

writing first summary data for the first bucket to the first summary directory, wherein the first summary data comprises at least one summary file that includes a summary representing a statistic associated with data in the first bucket and an indication that an entirety of contents of the first bucket is summarized based on determining a completion of the set of time-stamped event records being stored to the first bucket and summarization of the set of time-stamped event records stored in the first bucket;

unlocking the first summary directory; and

responsive to the indication that the entirety of contents of the first bucket is summarized, writing second summary data for a second bucket to a second summary directory.

22 . The system of claim 21 , wherein the one or more processors execute the instructions to:

receive, from an entity, a request for the second summary data; and

provide, to the entity, the second summary data for the second bucket responsive to the request, wherein the entity is configured to generate a result based at least in part on contents of the second summary data for the second bucket.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
Continuity (2)
Continuation 16298925 · Mar 11, 2019
Continuation 14694797 · Apr 23, 2015
References Cited (126)
US 5550971A · Brunner et al. · 1996 [cited by applicant]
US 5832484A · Sankaran · 1998 [cited by examiner]
US 6836894B1 · Hellerstein et al. · 2004 [cited by applicant]
US 6850952B2 · Tse · 2005 [cited by examiner]
US 6907422B1 · Predovic · 2005 [cited by applicant]
US 7149736B2 · Chkodrov · 2006 [cited by examiner]
US 7523191B1 · Thomas · 2009 [cited by examiner]
US 7581019B1 · Amir et al. · 2009 [cited by applicant]
US 7761426B2 · Boyd · 2010 [cited by examiner]
US 7774469B2 · Massa · 2010 [cited by examiner]
US 7860822B1 · Weinberger · 2010 [cited by examiner]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8271440B2 · Matsuzawa · 2012 [cited by examiner]
US 8516008B1 · Marquardt · 2013 [cited by examiner]
US 8560511B1 · Matthews · 2013 [cited by examiner]
US 8682886B2 · Sorkin · 2014 [cited by examiner]
US 8682925B1 · Marquardt · 2014 [cited by examiner]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 8805737B1 · Chen · 2014 [cited by examiner]
US 8898713B1 · Price · 2014 [cited by examiner]
US 9128985B2 · Marquardt et al. · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9437022B2 · Vander Broek · 2016 [cited by applicant]
US 9753974B2 · Marquardt et al. · 2017 [cited by applicant]
US 9842160B2 · Robichaud · 2017 [cited by applicant]
US 9977803B2 · Robichaud et al. · 2018 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10565005B2 · Stanfill · 2020 [cited by examiner]
US 20010042090A1 · Williams · 2001 [cited by examiner]
US 20020046273A1 · Lahr · 2002 [cited by examiner]
US 20020054101A1 · Beatty · 2002 [cited by applicant]
US 20020065976A1 · Kahn · 2002 [cited by examiner]
US 20020087743A1 · Givoly · 2002 [cited by examiner]
US 20020099691A1 · Lore · 2002 [cited by examiner]
US 20020188600A1 · Lindsay et al. · 2002 [cited by applicant]
US 20030014399A1 · Hansen et al. · 2003 [cited by applicant]
US 20040078359A1 · Bolognese et al. · 2004 [cited by applicant]
US 20040221226A1 · Lin et al. · 2004 [cited by applicant]
US 20040225641A1 · Dettinger et al. · 2004 [cited by applicant]
US 20040254919A1 · Giuseppini · 2004 [cited by applicant]
US 20050071320A1 · Chkodrov · 2005 [cited by examiner]
US 20050097556A1 · Code · 2005 [cited by examiner]
US 20050125325A1 · Chai · 2005 [cited by examiner]
US 20050203876A1 · Cragun et al. · 2005 [cited by applicant]
US 20060059238A1 · Slater · 2006 [cited by examiner]
US 20060074621A1 · Rachman · 2006 [cited by applicant]
US 20060242189A1 · Leetaru et al. · 2006 [cited by applicant]
US 20060253423A1 · McLane · 2006 [cited by examiner]
US 20070073743A1 · Bammi et al. · 2007 [cited by applicant]
US 20070209080A1 · Ture et al. · 2007 [cited by applicant]
US 20070214164A1 · MacLennan et al. · 2007 [cited by applicant]
US 20080059420A1 · Hsu et al. · 2008 [cited by applicant]
US 20080104542A1 · Cohen et al. · 2008 [cited by applicant]
US 20080228743A1 · Kusnitz et al. · 2008 [cited by applicant]
US 20090055370A1 · Dagum et al. · 2009 [cited by applicant]
US 20090063524A1 · Adler et al. · 2009 [cited by applicant]
US 20090070786A1 · Alves · 2009 [cited by examiner]
US 20090192983A1 · Elango · 2009 [cited by applicant]
US 20090193406A1 · Williams · 2009 [cited by applicant]
US 20090204588A1 · Hosono et al. · 2009 [cited by applicant]
US 20090228528A1 · Ercegovac et al. · 2009 [cited by applicant]
US 20090248691A1 · Vermette · 2009 [cited by examiner]
US 20090300065A1 · Birchall · 2009 [cited by applicant]
US 20090319512A1 · Baker et al. · 2009 [cited by applicant]
US 20100005080A1 · Pike · 2010 [cited by examiner]
US 20100074153A1 · Torsner · 2010 [cited by examiner]
US 20100095018A1 · Khemani et al. · 2010 [cited by applicant]
US 20100125645A1 · Hady · 2010 [cited by examiner]
US 20100228724A1 · Petri et al. · 2010 [cited by applicant]
US 20100251100A1 · Delacourt · 2010 [cited by applicant]
US 20100306281A1 · Williamson · 2010 [cited by applicant]
US 20110016123A1 · Pandey · 2011 [cited by examiner]
US 20110040733A1 · Sercinoglu et al. · 2011 [cited by applicant]
US 20110040745A1 · Zaydman et al. · 2011 [cited by applicant]
US 20110191373A1 · Botros et al. · 2011 [cited by applicant]
US 20110225143A1 · Khosravy et al. · 2011 [cited by applicant]
US 20110302151A1 · Abadi et al. · 2011 [cited by applicant]
US 20120008414A1 · Katz et al. · 2012 [cited by applicant]
US 20120042319A1 · Hildrum · 2012 [cited by examiner]
US 20120079363A1 · Folting et al. · 2012 [cited by applicant]
US 20120117116A1 · Jacobson et al. · 2012 [cited by applicant]
US 20120197914A1 · Harnett et al. · 2012 [cited by applicant]
US 20120203794A1 · Zhang et al. · 2012 [cited by applicant]
US 20120278336A1 · Malik et al. · 2012 [cited by applicant]
US 20120296889A1 · Davydok et al. · 2012 [cited by applicant]
US 20130054642A1 · Morin · 2013 [cited by examiner]
US 20130086092A1 · James et al. · 2013 [cited by applicant]
US 20130173306A1 · Sasidhar · 2013 [cited by applicant]
US 20130238631A1 · Carmel et al. · 2013 [cited by applicant]
US 20130311438A1 · Marquardt et al. · 2013 [cited by applicant]
US 20130311509A1 · Sorkin et al. · 2013 [cited by applicant]
US 20140040213A1 · Rossi · 2014 [cited by examiner]
US 20140214888A1 · Marquardt et al. · 2014 [cited by applicant]
US 20140344273A1 · Haines · 2014 [cited by examiner]
US 20140351819A1 · Shah · 2014 [cited by examiner]
US 20150039651A1 · Kinsely et al. · 2015 [cited by applicant]
US 20150154269A1 · Miller et al. · 2015 [cited by applicant]
US 20150156213A1 · Baker · 2015 [cited by examiner]
US 20150213631A1 · Vander Broek · 2015 [cited by applicant]
US 20160004750A1 · Marquardt et al. · 2016 [cited by applicant]
US 20160224532A1 · Miller et al. · 2016 [cited by applicant]
US 20160224618A1 · Robichaud et al. · 2016 [cited by applicant]
US 20160224626A1 · Robichaud et al. · 2016 [cited by applicant]
US 20160224643A1 · Robichaud · 2016 [cited by applicant]
US 20160285984A1 · Pinto Filipe · 2016 [cited by examiner]
US 20160299933A1 · Fillipi · 2016 [cited by examiner]
US 20160314163A1 · Marquardt et al. · 2016 [cited by applicant]
US 20170032550A1 · Vander Broek · 2017 [cited by applicant]
US 20170139964A1 · Marquardt et al. · 2017 [cited by applicant]
US 20170139965A1 · Marquardt et al. · 2017 [cited by applicant]
US 20170139996A1 · Marquardt et al. · 2017 [cited by applicant]
US 20170140013A1 · Marquardt et al. · 2017 [cited by applicant]
US 20180218037A1 · Marquardt et al. · 2018 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
X. Yun, G. Wu, G. Zhang, K. Li and S. Wang, “FastRAQ: A Fast Approach to Range-Aggregate Queries in Big Data Environments,” in IEEE Transactions on Cloud Computing, vol. 3, No. 2, pp. 206-218, Apr. 1-Jun. 2015, (Year: 2… [cited by examiner]
N. D. Mickulicz, R. Martins, P. Narasimhan and R. Gandhi, “When Good-Enough is Enough: Complex Queries at Fixed Cost, ” 2015 IEEE First International Conference on Big Data Computing Service and Applications, Redwood Ci… [cited by examiner]
Splunk, “Splunk Enterprise 8.0.0 Overview”, available online, retrieved May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk, “Splunk Cloud 8.0.2004 User Manual”, available online, retrieved May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk, “Splunk Quick Reference Guide”, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020, 6 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”, Vancou… [cited by applicant]
Saint-Paul et al., “General Purpose Database Summarization”, Proceedings of the 31st VLDB Conference, Aug. 30, 2005, pp. 733-744. [cited by applicant]
Carasso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, 156 pages. [cited by applicant]
Manning, Chrishtopher D., “Introduction to Informaion Retrieval”, Cambridge University Press Chapter 1, Apr. 1, 2009, 18 pages. [cited by applicant]