IP Library › Granted Patent US 12,505,594
Granted Patent B1
US 12,505,594 · App. 18/402,620 · Granted Dec 23, 2025

Streaming data visualizations

Inventors: Kelly Kong (Brooklyn, NY); Steven Shaun McIntyre (Queen Creek, AZ)
Assignee: Cisco Technology, Inc.
G06T11/206G06F16/24568G06F16/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,594
App. No.
18/402,620
Filed
Jan 2, 2024
Granted
Dec 23, 2025
Kind
B1
Examiner
SHENG, XIN
Art Unit
2619
USPC
345/440
Abstract

A device executes a visualization application program on a processor. Via the visualization application, a technique for visualizing data paths are performed. The technique includes receiving a data structure from a data intake and query system, where the data stream includes event stream data associated with the data path. The data path includes a set of entities, including an origin entity and a destination entity. The technique further includes generating visualizations of the origin entity, destination entity, and the event stream data. The visualization of the event stream data includes visualizations of events streaming between the visualization of the origin entity and visualization of the destination entity. The technique also includes causing the visualizations of the origin entity, destination entity, and the event stream data to be presented in an extended reality environment.

Claims (48)

1 . A computer-implemented method, comprising:

obtaining one or more logs of one or more events;

querying the one or more logs to extract data event information;

defining a first data path that identifies a transmission of a first set of events from the one or more events between a first set of entities, wherein the first set of events comprise events of a first event type;

defining a second data path that identifies a transmission of a second set of events from the one or more events between a second set of entities, wherein the second set of events comprise events of a second event type;

generating, based on the data event information, a data structure comprising at least the first data path and the second data path, the first data path including event stream data associated with the first data path and the second data path including event stream data associated with the second data path, wherein the first data path comprises the first set of entities, the first set of entities including an origin entity, a destination entity, and a host entity that recorded the data event information and wherein at least one entity in the first set of entities is different from an entity in the second set of entities; and

transmitting the data structure to a client device.

2 . The computer-implemented method of claim 1 , wherein the one or more events are associated with an event type.

3 . The computer-implemented method of claim 1 , wherein at least one of the origin entity or the destination entity comprises a machine.

4 . The computer-implemented method of claim 1 , wherein at least one of the origin entity or the destination entity comprises a group of machines.

5 . The computer-implemented method of claim 1 , wherein the event stream data associated with the first data path comprises, for each time period in a sequence of time periods, a count of one or more recorded events transmitted between the origin entity and the destination entity via the first data path.

6 . The computer-implemented method of claim 1 , wherein the first data path is defined based on a topology of a data stream pipeline, and wherein the topology of the data stream pipeline specifies the origin entity and the destination entity.

7 . The computer-implemented method of claim 1 , wherein the origin entity functions as a data source, the destination entity functions as a data sink, and one or more other entities included in the first set of entities function as branching paths for a data flow from the origin entity to the destination entity.

8 . The computer-implemented method of claim 1 , wherein the first set of entities further comprises at least one additional entity, and wherein the first data path includes:

a first path between the origin entity and the at least one additional entity, and

a second path between the destination entity and the at least one additional entity.

9 . The computer-implemented method of claim 1 , wherein the origin entity and the destination entity function as branching paths for a data flow.

10 . The computer-implemented method of claim 1 , wherein the data structure is generated by a data stream processor operating at a data intake and query system.

11 . The computer-implemented method of claim 1 , further comprising aggregating event data associated with a group of entities to generate aggregated stream data, wherein the group of entities includes at least two entities included in the set of entities that are associated with the origin entity, and wherein the data structure includes the aggregated stream data.

12 . The computer-implemented method of claim 1 , further comprising mapping one or more events associated with an event type to a status classification, wherein the status classification is associated with the data path.

13 . The computer-implemented method of claim 1 , wherein the host entity is different from the origin entity.

14 . The computer-implemented method of claim 1 , wherein the event stream data associated with the second data path comprises, for each time period in a sequence of time periods, a count of one or more recorded events transmitted between one or more entities in the second set of entities via the second data path.

15 . One or more non-transitory computer-readable storage media including instructions that, when executed by one or more processors, cause the one or more processors to perform the steps of:

obtaining one or more logs of one or more events;

querying the one or more logs to extract data event information;

defining a first data path that identifies a transmission of a first set of events from the one or more events between a first set of entities, wherein the first set of events comprise events of a first event type;

defining a second data path that identifies a transmission of a second set of events from the one or more events between a second set of entities, wherein the second set of events comprise events of a second event type;

generating, based on the data event information, a data structure comprising at least the first data path and the second data path, the first data path including event stream data associated with the first data path and the second data path including event stream data associated with the second data path, wherein the first data path comprises the first set of entities, the first set of entities including an origin entity, a destination entity, and a host entity that recorded the data event information and wherein at least one entity in the first set of entities is different from an entity in the second set of entities; and

transmitting the data structure to a client device.

16 . The one or more non-transitory computer-readable storage media of claim 15 , wherein the event stream data associated with the first data path comprises, for each time period in a sequence of time periods, a count of one or more recorded events transmitted between the origin entity and the destination entity in the first data path.

17 . The one or more non-transitory computer-readable storage media of claim 15 , wherein the first data path is defined based on a topology of a data stream pipeline, and wherein the topology of the data stream pipeline specifies the origin entity and the destination entity, and wherein the origin entity represents a data source, the destination entity represents a data sink, and other entities of the set of entities represent branching paths of a data flow from the origin entity to the destination entity.

18 . The one or more non-transitory computer-readable storage media of claim 15 , wherein the first set of entities further comprises a further entity, and wherein the first data path includes at least:

a first path between the origin entity and the further entity, and

a second path between the destination entity and the further entity.

19 . A computing device, comprising:

a memory storing instructions; and

a processor that is coupled to the memory and, when executing the instructions, is configured to perform the steps of:

obtaining one or more logs of one or more events;

querying the one or more logs to extract data event information;

defining a first data path that identifies a transmission of a first set of events from the one or more events between a first set of entities, wherein the first set of events comprise events of a first event type;

defining a second data path that identifies a transmission of a second set of events from the one or more events between a second set of entities, wherein the second set of events comprise events of a second event type;

generating, based on the data event information, a data structure comprising at least the first data path and the second data path, the first data path including event stream data associated with the first data path and the second data path including event stream data associated with the second data path, wherein the first data path comprises the first set of entities, the first set of entities including an origin entity, a destination entity, and a host entity that recorded the data event information and wherein at least one entity in the first set of entities is different from an entity in the second set of entities; and

transmitting the data structure to a client device.

20 . The computing device of claim 19 , wherein the event stream data associated with the first data path comprises, for each time period in a sequence of time periods, a count of one or more recorded events transmitted between the origin entity and the destination entity in the first data path.

21 . The computing device of claim 19 , wherein the first data path is defined based on a topology of a data stream pipeline, and wherein the topology of the data stream pipeline specifies the origin entity and the destination entity, and wherein the origin entity represents a data source, the destination entity represents a data sink, and other entities of the first set of entities represent branching paths of a data flow from the origin entity to the destination entity.

22 . The computing device of claim 19 , wherein the first set of entities further comprises a further entity, and wherein the first data path includes at least:

a first path between the origin entity and the further entity, and

a second path between the destination entity and the further entity.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2024
From: KONG, KELLY; MCINTYRE, STEVEN SHAUN
To: SPLUNK INC.
Reel/Frame 067702/0274 →
Continuity (2)
Continuation 17085954 · Oct 30, 2020
Provisional Application 63093630 · Oct 19, 2020
References Cited (25)
US 7920983B1 · Peleg et al. · 2011 [cited by applicant]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 20080126858A1 · Barras · 2008 [cited by examiner]
US 20140098104A1 · Kirknel · 2014 [cited by examiner]
US 20160219078A1 · Porras · 2016 [cited by examiner]
US 20170139974A1 · Javed et al. · 2017 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
Coltekin et al (“Geospatial Information Visualization and Extended Reality Displays”, 2019) (Year: 2019). [cited by examiner]
Turan, Sefer. “Visualizing Flows in Event Logs.” (Year: 2014). [cited by examiner]
Wongsuphasawat, Krist, and David Gotz. “Exploring flow, factors, and outcomes of temporal event sequences with the outflow visualization.” IEEE Transactions on Visualization and Computer Graphics 18.12 (2012): 2659-2668… [cited by examiner]
Song, Boyeon, et al. “Visualization of security event logs across multiple networks and its application to a CSOC.” Cluster Computing 22 (2019): 1861-1872. (Year: 2019). [cited by examiner]
Duncan (“Using Wireshark Identifying Hosts and Users”, 2019, https://web.archive.org/web/20190402054253/https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/) (Year: 2019). [cited by examiner]
Solarwindsinc (“How to Set Up a NetFlow Traffic Analyzer Alert”, 2019, https://www.youtube.com/watch?v=NEEINrlz2z8#:˜:text=Learn%20more:%20https://slrwnds.com/TTT%2DSetUpNTA%20Learn%20how%20to%20use%20the%20SolarWinds%C… [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved on May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved on May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, 6 pages. [cited by applicant]
Carasso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, 156 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at“Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”, Vancouv… [cited by applicant]
Coltekin et al., “Geospatial Information Visualization and Extended Reality Displays”, https://link.springer.com/chapter/10.1 007/978-981-32-9915-3_7, Nov. 20, 2019, 41 pages. [cited by applicant]