IP Library Granted Patent US 12,282,497
Granted Patent B1
US 12,282,497 · App. 18/201,042 · Granted Apr 22, 2025

Search result replication management in a search head cluster

Inventors: Anirban Rahut (Santa Clara, CA); Sundar Vasan (San Francisco, CA)
G06F16/285G06F16/27G06F16/951G06F16/9538
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,497
App. No.
18/201,042
Granted
Apr 22, 2025
Kind
B1
Abstract

Systems and methods for search result replication in a search head cluster of a data aggregation and analysis system. An example method may include receiving, by a search head leader of a search head cluster including multiple search heads, from a first search head of the plurality of search heads, a search result in response to a search query. The search head leader parses a registry comprising a set of replicas of the search result in the search head cluster to determine a replication count corresponding to a number of replicas of the search result. A determination is made that the replication count is greater than a target replication count. Based on the determination, a selected replica from the set of replicas is identified based at least in part on a recency of use of the selected replica and a deletion of the selected replica is initiated.

Claims (35)

1. A method comprising:

receiving, by a search head leader of a search head cluster comprising a plurality of search heads, from a first search head of the plurality of search heads, a search result in response to a search query, wherein the first search head performs a first reduce phase of a first map-reduce search computation of source data to generate the search result in response to the search query, wherein the search head cluster comprises the plurality of search heads that are each configured to execute a reduce phase of a map-reduce search, and wherein the reduce phase comprises combining results of a map phase of the map-reduce search to generate search results, the map phase executed by a plurality of indexers;

parsing, by the search head leader, a registry comprising a set of replicas of the search result in the search head cluster to determine a replication count corresponding to a number of replicas of the search result;

determining that the replication count is greater than a target replication count stored in a data store;

based on determining that the replication count is greater than the target replication count, identifying a selected replica from the set of replicas to remove based at least in part on the selected replica being associated with a lowest counter value stored in the data store as compared to counter values associated with other replicas from the set of replicas, the lowest counter value indicating a number of times the selected replica was accessed based on incrementing a counter each time the selected replica was accessed; and

transmitting an instruction to delete the selected replica;

wherein the method is performed by one or more processing devices.

2. The method of claim 1 , further comprising receiving, by the search head leader, a statistic associated with the lowest counter value of the selected replica.

3. The method of claim 2 , wherein the statistic is received by the search head leader in response to access of the selected replica of the set of replicas at a search head of the plurality of search heads.

4. The method of claim 1 , further comprising maintaining, by the search head leader, the counter associated with the selected replica of the set of replicas.

5. The method of claim 1 , further comprising deleting the selected replica from the registry.

6. The method of claim 1 , further comprising scheduling the deletion of the selected replica.

7. A computer system, comprising:

a memory; and

one or more processing devices, coupled to the memory, to:

receive, by a search head leader of a search head cluster comprising a plurality of search heads, from a first search head of the plurality of search heads, a search result in response to a search query, wherein the first search head performs a first reduce phase of a first map-reduce search computation of source data to generate the search result in response to the search query, wherein the search head cluster comprises the plurality of search heads that are each configured to execute a reduce phase of a map-reduce search, and wherein the reduce phase comprises combining results of a map phase of the map-reduce search to generate search results, the map phase executed by a plurality of indexers;

parse, by the search head leader, a registry comprising a set of replicas of the search result in the search head cluster to determine a replication count corresponding to a number of replicas of the search result;

determine that the replication count is greater than a target replication count stored in a data store;

based on determining that the replication count is greater than the target replication count, identify a selected replica from the set of replicas to remove based at least in part on the selected replica being associated with a lowest counter value stored in the data store as compared to counter values associated with other replicas from the set of replicas, the lowest counter value indicating a number of times the selected replica was accessed based on incrementing a counter each time the selected replica was accessed; and

transmit an instruction to delete the selected replica.

8. The computer system of claim 7 , wherein the processing device is further to receive a statistic associated with the lowest counter value of the selected replica.

9. The computer system of claim 8 , wherein the statistic is received by the search head leader in response to access of the selected replica of the set of replicas at a search head of the plurality of search heads.

10. The computer system of claim 7 , wherein the processing device is further to maintain the counter associated with the selected replica of the set of replicas.

11. The computer system of claim 7 , wherein the processing device to delete the selected replica from the registry.

12. The computer system of claim 7 , wherein the processing device to schedule the deletion of the selected replica.

13. A computer-readable non-transitory storage medium comprising executable instructions that, when executed by a computer system, cause the computer system to perform operations comprising:

receiving, by a search head leader of a search head cluster comprising a plurality of search heads, from a first search head of the plurality of search heads, a search result in response to a search query, wherein the first search head performs a first reduce phase of a first map-reduce search computation of source data to generate the search result in response to the search query, wherein the search head cluster comprises the plurality of search heads that are each configured to execute a reduce phase of a map-reduce search, and wherein the reduce phase comprises combining results of a map phase of the map-reduce search to generate search results, the map phase executed by a plurality of indexers;

parsing, by the search head leader, a registry comprising a set of replicas of the search result in the search head cluster to determine a replication count corresponding to a number of replicas of the search result;

determining that the replication count is greater than a target replication count stored in a data store;

based on determining that the replication count is greater than the target replication count, identifying a selected replica from the set of replicas to remove based at least in part on the selected replica being associated with a lowest counter value stored in the data store as compared to counter values associated with other replicas from the set of replicas, the lowest counter value indicating a number of times the selected replica was accessed based on incrementing a counter each time the selected replica was accessed; and

transmitting an instruction to delete the selected replica.

14. The computer-readable non-transitory storage medium of claim 13 , wherein the operations further comprise receiving a statistic associated with the lowest counter value of the selected replica.

15. The computer-readable non-transitory storage medium of claim 14 , wherein the statistic is received by the search head leader in response to access of the selected replica of the set of replicas at a search head of the plurality of search heads.

16. The computer-readable non-transitory storage medium of claim 13 , wherein the operations further comprise maintaining, by the search head leader, the counter associated with the selected replica of the set of replicas.

17. The computer-readable non-transitory storage medium of claim 13 , wherein the operations further comprise deleting the selected replica from the registry.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2025
From: VASAN, SUNDAR; RAHUT, ANIRBAN
To: SPLUNK INC.
Reel/Frame 070894/0633 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
Continuity (2)
Continuation 16159893 · Oct 15, 2018
Continuation 14449069 · Jul 31, 2014
References Cited (39)
US 5956722A · Jacobson · 1999 [cited by applicant]
US 6879995B1 · Chinta · 2005 [cited by applicant]
US 7222119B1 · Ghemawat · 2007 [cited by examiner]
US 8166039B1 · Haveliwala · 2012 [cited by applicant]
US 8412696B2 · Zhang · 2013 [cited by applicant]
US 8589403B2 · Marquardt · 2013 [cited by applicant]
US 8682925B1 · Marquardt · 2014 [cited by applicant]
US 9081843B2 · Leshchiner · 2015 [cited by applicant]
US 9356793B1 · Drobychev · 2016 [cited by examiner]
US 9495381B2 · Shvachko · 2016 [cited by applicant]
US 9804928B2 · Davis · 2017 [cited by examiner]
US 20080177767A1 · Lin · 2008 [cited by applicant]
US 20090204583A1 · Hechler · 2009 [cited by applicant]
US 20120226661A1 · Kenthapadi · 2012 [cited by examiner]
US 20130151535A1 · Dusberger · 2013 [cited by applicant]
US 20130318236A1 · Coates · 2013 [cited by applicant]
US 20130318603A1 · Merza · 2013 [cited by applicant]
US 20130326620A1 · Merza · 2013 [cited by applicant]
US 20140032579A1 · Merriman · 2014 [cited by applicant]
US 20140108415A1 · Bulkowski · 2014 [cited by examiner]
US 20140160238A1 · Yim · 2014 [cited by applicant]
US 20160034555A1 · Rahut · 2016 [cited by applicant]
Kyong Lee; Parallel Data Processing with MapReduce: A Survery; 2011; SIGMOD; pp. 11-20. [cited by examiner]
Eamonn J. Keogh et al.; Scaling up Dynamic Time Warping for Dataming Applications; ACM;2000; pp. 285-289. [cited by applicant]
Diego Ongaro; In Seach of an Understanable Consensus Algorithm; May 2014; pp. 1-18. [cited by applicant]
Bitincka, Ledion, et al., “Optimizing Data Analysis with a Semi-Structured Time Series Database”, Splunk Inc., 2010 pp. 1-9. [cited by applicant]
Carasso, David, “Exploring Splunk Search Processing Language (SPL) Primer and Cookbook”, Splunk Inc., 2012 CITO Research, New York, 154 Pages. [cited by applicant]
http:/fdocs.splunk.com/Documentation/PCI/2.1.1/ [000119] User/IncidentReviewdashboard, 2 Pages (Last accessed Aug. 5, 2014). [cited by applicant]
“VSphere Monitoring and Performance”, VMware, Inc., Update 1, vSphere 5.5, EN-001357-02, 2010-2014,pp. 1-174 http:/fpubs. vmware .com/ vsphere-55/topic/ com. vmware. IC base/ PDF /vsphere-esxi-vcenter-server-551-monitor… [cited by applicant]
U.S. Appl. No. 14/167,316, filed Jan. 29, 2014. [cited by applicant]
U.S. Appl. No. 14/266,812, filed Apr. 30, 2014. [cited by applicant]
U.S. Appl. No. 14/266,817, filed Apr. 30, 2014. [cited by applicant]
Diego Ongaro and John Ousterhout, In Search of an Understandable Consensus Algorithm (Extended Version), Stanford University, published May 20, 2014, 18 pages. [cited by applicant]
Jeffrey Dean and Sanjay Ghemawat, “MapReduce: Simplified Data Processing on Large Clusters”, Google, Inc., OSOi 2004, 13 pages. [cited by applicant]
USPTO, Office Action for U.S. Appl. No. 14/449,069, mailed Feb. 1, 2017. [cited by applicant]
USPTO, Final Office Action for U.S. Appl. No. 14/449,069, Jul. 20, 2017. [cited by applicant]
USPTO, Office Action for U.S. Appl. No. 14/449,069, Dec. 14, 2017. [cited by applicant]
USPTO, Notice of Allowance for U.S. Appl. No. 14/449,069, mailed Jul. 13, 2018. [cited by applicant]
Kyong-Ha Lee; “Parallel Data Processing with Map Reduce: A Survey” SIGMOD; 2011; pp. 11-21 (Year: 2011). [cited by applicant]