IP Library Granted Patent US 12,443,641
Granted Patent B2
US 12,443,641 · App. 18/419,179 · Granted Oct 14, 2025

Data identification using inverted indexes

Inventors: Jesse Miller (Piedmont, CA); Jason Szeto (Belmont, CA); Jose Solis (Mountain View, CA); Jindrich Dinga (Los Altos, CA); David Marquardt (San Francisco, CA)
G06F16/345G06F16/335G06F16/358G06T11/206G06T2200/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,443,641
App. No.
18/419,179
Granted
Oct 14, 2025
Kind
B2
Abstract

Systems and methods are disclosed involving user interface (UI) search tools for locating data, including tools for summarizing indexed raw machine data that organize and present results to enable expansion and exploration of initial summarizations. The initial summarizations may be explored and refined to help users determine how to identify and best focus a search on data subsets of greater interest.

Claims (49)

1. A method, comprising:

causing display, via a graphical user interface, of one or more identifiers of one or more groupings of events, each event including raw machine data corresponding with a timestamp, the one or more groupings of events being generated based on first filter criteria and categorization criteria, wherein the first filter criteria identifies a set of data, wherein the categorization criteria identifies one or more fields to categorize event references, wherein categorization criteria-value pairs correspond to unique combinations of the one or more fields and field values of the one or more fields, and wherein each grouping of the one or more groupings includes a respective group of event references corresponding to a respective group of events that have a same field-value for a field of the one or more fields and satisfy the first filter criteria;

in response to an interaction with a display object displayed via the graphical user interface and associated with a particular grouping of the one or more groupings, identifying, using an inverted index, one or more event references corresponding to one or more events that satisfy the first filter criteria and second filter criteria, wherein the second filter criteria is based on the particular grouping, and wherein the one or more event references correspond to a subset of data; and

causing display, via the graphical user interface, of an identifier of the one or more events.

2. The method of claim 1 , wherein causing display of the one or more identifiers comprises:

causing display of the one or more identifiers in response to execution of a query, wherein the query is associated with the first filter criteria and the categorization criteria, and wherein the set of data is processed as part of the query.

3. The method of claim 1 , wherein causing display of the one or more identifiers comprises:

causing display of the one or more identifiers further based on display criteria, wherein the display criteria comprises at least one of a sort order or a split by order.

4. The method of claim 1 , further comprising:

obtaining an input via the graphical user interface, wherein the input indicates the interaction with the display object.

5. The method of claim 1 , wherein at least one of the first filter criteria or the second filter criteria indicates at least one of a partition, a host, a source a sourcetype, a keyword, a field identifier, or a time range.

6. The method of claim 1 , wherein the inverted index comprises a plurality of entries, each entry of the plurality of entries comprising:

a respective token or a respective field-value pair; and

one or more respective event references, each event reference of the one or more respective event references indicative of a respective event that is associated with the respective token or a field-value corresponding to the respective field-value pair.

7. The method of claim 1 , wherein the inverted index indicates at least one of an origin or a partition associated with the one or more events.

8. The method of claim 1 , wherein the inverted index comprises an event reference array, the event reference array comprising, for each event reference of the one or more event references, a respective timestamp and a respective location identifier.

9. The method of claim 1 , wherein the raw machine data is generated by one or more components in an information technology environment.

10. The method of claim 1 , further comprising:

in response to a request received from a device, generating the one or more groupings.

11. The method of claim 1 , further comprising:

causing display of one or more graphical controls;

obtaining an input via the one or more graphical controls; and

generating the one or more groupings based on the input.

12. The method of claim 1 , further comprising:

causing display of one or more graphical controls;

obtaining an input via the one or more graphical controls; and

identifying the first filter criteria based on the input.

13. The method of claim 1 , further comprising:

causing display, via the graphical user interface, for each respective grouping of the one or more groupings, a respective count indicating a respective number of events associated with the respective grouping.

14. The method of claim 1 , wherein the one or more events correspond to a subset of a plurality of events that satisfy the first filter criteria and second filter criteria.

15. The method of claim 1 , further comprising:

processing the one or more events.

16. The method of claim 1 , further comprising:

categorizing the event references according to the categorization criteria; and

generating the one or more groupings based on categorizing the event references.

17. A computing system, comprising:

memory; and

one or more processing devices coupled to the memory and configured to:

cause display, via a graphical user interface, of one or more identifiers of one or more groupings of events, each event including raw machine data corresponding with a timestamp, the one or more groupings of events being generated based on first filter criteria and categorization criteria, wherein the first filter criteria identifies a set of data, wherein the categorization criteria identifies one or more fields to categorize event references, wherein categorization criteria-value pairs correspond to unique combinations of the one or more fields and field values of the one or more fields, and wherein each grouping of the one or more groupings includes a respective group of event references corresponding to a respective group of events that have a same field-value for a field of the one or more fields and satisfy the first filter criteria;

in response to an interaction with a display object displayed via the graphical user interface and associated with a particular grouping of the one or more groupings, identify, using an inverted index, one or more event references corresponding to one or more events that satisfy the first filter criteria and second filter criteria, wherein the second filter criteria is based on the particular grouping, and wherein the one or more event references correspond to a subset of the set of data; and

cause display, via the graphical user interface, of an identifier of the one or more events.

18. The computing system of claim 17 , wherein to cause display of the one or more identifiers, the one or more processing devices are further configured to:

cause display of the one or more identifiers in response to execution of a query, wherein the query is associated with the first filter criteria and the categorization criteria, and wherein the set of data is processed as part of the query.

19. Non-transitory computer readable media comprising computer-executable instructions, wherein execution of the computer-executable instructions by one or more processing devices causes the one or more processing devices to:

cause display, via a graphical user interface, of one or more identifiers of one or more groupings of events, each event including raw machine data corresponding with a timestamp, the one or more groupings of events being generated based on first filter criteria and categorization criteria, wherein the first filter criteria identifies a set of data, wherein the categorization criteria identifies one or more fields to categorize event references, wherein categorization criteria-value pairs correspond to unique combinations of the one or more fields and field values of the one or more fields, and wherein each grouping of the one or more groupings includes a respective group of event references corresponding to a respective group of events that have a same field-value for a field of the one or more fields and satisfy the first filter criteria;

in response to an interaction with a display object displayed via the graphical user interface and associated with a particular grouping of the one or more groupings, identify, using an inverted index, one or more event references corresponding to one or more events that satisfy the first filter criteria and second filter criteria, wherein the second filter criteria is based on the particular grouping, and wherein the one or more event references correspond to a subset of the set of data; and

cause display, via the graphical user interface, of an identifier of the one or more events.

20. The non-transitory computer readable media of claim 19 , wherein to cause display of the one or more identifiers, the execution of the computer-executable instructions by the one or more processing devices further causes the one or more processing devices to:

cause display of the one or more identifiers in response to execution of a query, wherein the query is associated with the first filter criteria and the categorization criteria, and wherein the set of data is processed as part of the query.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
Continuity (4)
Continuation 17861083 · Jul 8, 2022
Continuation 17079121 · Oct 23, 2020
Continuation 15479804 · Apr 5, 2017
Related Publication 20240419712A1 · Dec 19, 2024
References Cited (73)
US 6026398A · Brown et al. · 2000 [cited by applicant]
US 7921363B1 · Hao et al. · 2011 [cited by applicant]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8024329B1 · Rennison · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9514183B1 · Alla · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10853399B2 · Miller et al. · 2020 [cited by applicant]
US 11061918B2 · Miller et al. · 2021 [cited by applicant]
US 11106713B2 · Miller et al. · 2021 [cited by applicant]
US 11403333B2 · Miller et al. · 2022 [cited by applicant]
US 11880399B2 · Miller et al. · 2024 [cited by applicant]
US 20030046307A1 · Rivette · 2003 [cited by examiner]
US 20030101183A1 · Kabra et al. · 2003 [cited by applicant]
US 20040117377A1 · Moser et al. · 2004 [cited by applicant]
US 20040133564A1 · Gross et al. · 2004 [cited by applicant]
US 20040249810A1 · Das et al. · 2004 [cited by applicant]
US 20050021512A1 · Koenig · 2005 [cited by applicant]
US 20050262062A1 · Xia · 2005 [cited by applicant]
US 20060036408A1 · Templier et al. · 2006 [cited by applicant]
US 20070033104A1 · Collins et al. · 2007 [cited by applicant]
US 20070112727A1 · Jardine et al. · 2007 [cited by applicant]
US 20070156671A1 · Yip · 2007 [cited by applicant]
US 20070226640A1 · Holbrook et al. · 2007 [cited by applicant]
US 20070244849A1 · Predovic · 2007 [cited by applicant]
US 20080005118A1 · Shakib et al. · 2008 [cited by applicant]
US 20080104542A1 · Cohen · 2008 [cited by examiner]
US 20080288527A1 · Ames et al. · 2008 [cited by applicant]
US 20090063471A1 · Erickson · 2009 [cited by examiner]
US 20100211564A1 · Cohen et al. · 2010 [cited by applicant]
US 20110191373A1 · Botros et al. · 2011 [cited by applicant]
US 20110314400A1 · Mital et al. · 2011 [cited by applicant]
US 20120110515A1 · Abramoff et al. · 2012 [cited by applicant]
US 20120166416A1 · Murdock et al. · 2012 [cited by applicant]
US 20120180090A1 · Yoon · 2012 [cited by examiner]
US 20120278316A1 · Reznik · 2012 [cited by applicant]
US 20130041896A1 · Ghani et al. · 2013 [cited by applicant]
US 20130166547A1 · Pasumarthi et al. · 2013 [cited by applicant]
US 20130226922A1 · Labenski et al. · 2013 [cited by applicant]
US 20130238631A1 · Carmel et al. · 2013 [cited by applicant]
US 20140279856A1 · Srinivasan et al. · 2014 [cited by applicant]
US 20150169726A1 · Kara et al. · 2015 [cited by applicant]
US 20150180891A1 · Seward · 2015 [cited by examiner]
US 20150212663A1 · Papale et al. · 2015 [cited by applicant]
US 20150234905A1 · Carrasso · 2015 [cited by applicant]
US 20150332000A1 · Bess et al. · 2015 [cited by applicant]
US 20160034525A1 · Neels et al. · 2016 [cited by applicant]
US 20160224660A1 · Munk et al. · 2016 [cited by applicant]
US 20160225271A1 · Robichaud · 2016 [cited by applicant]
US 20160253387A1 · Tidwell · 2016 [cited by examiner]
US 20160307173A1 · Chauhan · 2016 [cited by examiner]
US 20160371375A1 · Sasidhar · 2016 [cited by applicant]
US 20170046127A1 · Fletcher et al. · 2017 [cited by applicant]
US 20170060856A1 · Turtle et al. · 2017 [cited by applicant]
US 20170124156A1 · Chernyak · 2017 [cited by applicant]
US 20170177672A1 · Geissinger · 2017 [cited by examiner]
US 20180293304A1 · Miller et al. · 2018 [cited by applicant]
US 20180293308A1 · Miller et al. · 2018 [cited by applicant]
US 20180293327A1 · Miller et al. · 2018 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20210042341A1 · Miller et al. · 2021 [cited by applicant]
U.S. Appl. No. 17/079,121, filed Oct. 23, 2020, Miller et al. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Carraso, Da Vid, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
SLAML 10 Reports, Workshop On Managing Systems via Log Analysis and Machine Learning Techniques, ;login: Feb. 2011 Conference Reports. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
Vaid, Workshop on Managing Systems via log Analysis and Machine Learning Techniques (SLAML '10), ;login: vol. 36, No. 1, Oct. 3, 2010, Vancouver, BC, Canada. [cited by applicant]