IP Library Granted Patent US 11,971,778
Granted Patent B1
US 11,971,778 · App. 18/299,469 · Granted Apr 30, 2024

Anomaly detection from incoming data from a data stream

Inventors: Jacob Barton Leverich (San Francisco, CA); Shang Cai (San Francisco, CA); Hongyang Zhang (San Francisco, CA); Mihai Ganea (San Francisco, CA); Alex Cruise (San Francisco, CA)
Assignee: Splunk Inc.
G06F11/079G06F11/0709G06F11/0793
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,971,778
App. No.
18/299,469
Granted
Apr 30, 2024
Kind
B1
Abstract

A continuous anomaly detection service receives data stream and performs continuous anomaly detection on the incoming data streams. This continuous anomaly detection is performed based on anomaly detection definitions, which define a signal used for anomaly detection and an anomaly detection configuration. These anomaly detection definitions can be modified, such that continuous anomaly detection continues to be performed for the data stream and the signal, based on the new anomaly detection definition.

Claims (34)

1. A computer-implemented method comprising:

extracting, from a chunk of incoming data from a data stream, one or more signal chunks;

generating one or more time-stamped data points from the data stream based on the one or more signal chunks;

inserting the one or more time-stamped data points from the data stream into a signal buffer storing a sequential set of time-series data points for an anomaly detection definition; and

analyzing the sequential set of time-series data points from the signal buffer to determine a corresponding anomaly result for the anomaly detection definition.

2. The computer-implemented method of claim 1 , wherein the extracting of the one or more signal chunks from the chunk of incoming data is by a router in communication with a definition manager that controls how the router routes data based on an anomaly detection configuration for the anomaly detection definition.

3. The computer-implemented method of claim 1 , further comprising extracting, from the chunk of incoming data, different signal chunks for different anomaly detection definitions and routing the different signal chunks to different signal buffers for the different anomaly detection definitions.

4. The computer-implemented method of claim 1 , further comprising issuing a backfill request based on a determination that a minimum required number of data points is not present.

5. The computer-implemented method of claim 1 , wherein the extracting of the one or more signal chunks from the chunk of incoming data is by a router, wherein a definition manager is configured to issue chunk routing requests for the router to route the one or more signal chunks extracted from the chunk of incoming data to the signal buffer, and to issue backfill requests for a backfill manager to retrieve and route one or more historical data points to the signal buffer.

6. The computer-implemented method of claim 1 , wherein the generating of the one or more time-stamped data points from the data stream comprises routing the one or more signal chunks to a reorder buffer associated with the signal buffer and reordering the one or more signal chunks in the reorder buffer based on timestamps extracted for the one or more signal chunks from the chunk of incoming data.

7. The computer-implemented method of claim 1 , further comprising pre-loading or backfilling the signal buffer with one or more historical data points based on a determination that a minimum required number of data points is not present, and ordering the one or more historical data points and the one or more time-stamped data points in the signal buffer in sequential order.

8. A non-transitory computer-readable storage medium comprising instructions stored thereon which, when executed by one or more processors, cause the one or more processors to perform operations comprising:

extracting, from a chunk of incoming data from a data stream, one or more signal chunks;

generating one or more time-stamped data points from the data stream based on the one or more signal chunks;

inserting the one or more time-stamped data points from the data stream into a signal buffer storing a sequential set of time-series data points for an anomaly detection definition; and

analyzing the sequential set of time-series data points from the signal buffer to determine a corresponding anomaly result for the anomaly detection definition.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the extracting of the one or more signal chunks from the chunk of incoming data is by a router in communication with a definition manager that controls how the router routes data based on an anomaly detection configuration for the anomaly detection definition.

10. The non-transitory computer-readable storage medium of claim 8 , the operations further comprising extracting, from the chunk of incoming data, different signal chunks for different anomaly detection definitions and routing the different signal chunks to different signal buffers for the different anomaly detection definitions.

11. The non-transitory computer-readable storage medium of claim 8 , the operations further comprising issuing a backfill request based on a determination that a minimum required number of data points is not present.

12. The non-transitory computer-readable storage medium of claim 8 , wherein the extracting of the one or more signal chunks from the chunk of incoming data is by a router, wherein a definition manager is configured to issue chunk routing requests for the router to route the one or more signal chunks extracted from the chunk of incoming data to the signal buffer, and to issue backfill requests for a backfill manager to retrieve and route one or more historical data points to the signal buffer.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the generating of the one or more time-stamped data points from the data stream comprises routing the one or more signal chunks to a reorder buffer associated with the signal buffer and reordering the one or more signal chunks in the reorder buffer based on timestamps extracted for the one or more signal chunks from the chunk of incoming data.

14. The non-transitory computer-readable storage medium of claim 8 , the operations further comprising pre-loading or backfilling the signal buffer with one or more historical data points based on a determination that a minimum required number of data points is not present, and ordering the one or more historical data points and the one or more time-stamped data points in the signal buffer in sequential order.

15. A system comprising:

at least one processor; and

at least one memory having instructions stored thereon which, when executed by the at least one processor, cause the at least one processor to perform operations comprising:

extracting, from a chunk of incoming data from a data stream, one or more signal chunks;

generating one or more time-stamped data points from the data stream based on the one or more signal chunks;

inserting the one or more time-stamped data points from the data stream into a signal buffer storing a sequential set of time-series data points for an anomaly detection definition; and

analyzing the sequential set of time-series data points from the signal buffer to determine a corresponding anomaly result for the anomaly detection definition.

16. The system of claim 15 , wherein the extracting of the one or more signal chunks from the chunk of incoming data is by a router in communication with a definition manager that controls how the router routes data based on an anomaly detection configuration for the anomaly detection definition.

17. The system of claim 15 , the operations further comprising extracting, from the chunk of incoming data, different signal chunks for different anomaly detection definitions and routing the different signal chunks to different signal buffers for the different anomaly detection definitions.

18. The system of claim 15 , the operations further comprising issuing a backfill request based on a determination that a minimum required number of data points is not present.

19. The system of claim 15 , wherein the extracting of the one or more signal chunks from the chunk of incoming data is by a router, wherein a definition manager is configured to issue chunk routing requests for the router to route the one or more signal chunks extracted from the chunk of incoming data to the signal buffer, and to issue backfill requests for a backfill manager to retrieve and route one or more historical data points to the signal buffer.

20. The system of claim 15 , wherein the generating of the one or more time-stamped data points from the data stream comprises routing the one or more signal chunks to a reorder buffer associated with the signal buffer and reordering the one or more signal chunks in the reorder buffer based on timestamps extracted for the one or more signal chunks from the chunk of incoming data.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2023
From: LEVERICH, JACOB BARTON; CAI, SHANG; ZHANG, HONGYANG; GANEA, MAHAI; CRUISE, ALEX
To: SPLUNK INC.
Reel/Frame 063305/0115 →
Continuity (3)
Continuation 16722673 · Dec 20, 2019
Continuation 16176186 · Oct 31, 2018
Continuation 15206126 · Jul 8, 2016