IP Library › Granted Patent US 12,461,987
Granted Patent B1
US 12,461,987 · App. 18/428,955 · Granted Nov 4, 2025

System and interface for integrating related content

Inventors: Ian Edward Torbett (Benicia, CA); Samo Drole (Burnaby, CA); Amin Moshgabadi (San Diego, CA)
Assignee: Cisco Technology, Inc.
G06F16/986G06F16/9038
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,461,987
App. No.
18/428,955
Filed
Jan 31, 2024
Granted
Nov 4, 2025
Kind
B1
Art Unit
2154
USPC
707/722
Abstract

Systems and methods are provided for a data intake and query system providing a user interface including corresponding content from a system external to the data intake and query system, such as an observability system. On receipt of input from a client device, the data intake and query system may generate a user interface including the corresponding content. To generate the user interface, the data intake and query system may access a unique identifier corresponding to updated data for the external system. The data intake and query system may then determine whether the updated data includes corresponding data. If so, the data intake and query system may include visualizations based on the corresponding data.

Claims (62)

1 . A system comprised:

memory storing computer-executable instructions; and

a processor in communication with the memory, wherein the computer-executable instructions, when executed by the processor, cause the processor to:

process a request from a client device to access a page corresponding to events data;

in response to a query for a dataset entered on the page, transmit, to a server, a request for a storage location of source code for generating a visualization of metrics data that is associated with a geographic region of the dataset;

transmit, to a content delivery network (CDN), a request for the source code stored at the storage location received from the server;

in response to reception of the source code, insert the source code in a document object model (DOM) tree of the page, and execute the source code to access a first function;

add the first function and a second function to a global namespace in response to execution of the DOM tree, wherein the first function is associated with a first type of metric and the second function is associated with a second type of metric;

cause the client device to display an updated page, wherein the updated page depicts one or more events in the events data that satisfy the query;

in response to a selection of a first event in the one or more events: (i) call the first function using a field name and a field value associated with the first event to determine whether metrics data of the first type associated with at least one of the field name or the field value is present in an observability system, and (ii) call the second function using the field name and the field value associated with the first event to determine whether metrics data of the second type associated with at least one of the field name or the field value is present in the observability system; and

in response to an indication from the observability system that metrics data of the first type or metrics data of the second type associated with at least one of the field name or the field value is present, cause the client device to display a second updated page, wherein the second updated page depicts the field name, the field value, and a selectable link to view the metrics data in association with the first event.

2 . The system of claim 1 , wherein the computer-executable instructions, when executed, further cause the processor to receive the source code in response to the CDN authenticating that the system is allowed access to the source code.

3 . The system of claim 1 , wherein the computer-executable instructions, when executed, further cause the processor to:

in response to a selection of the selectable link, call the second function of the source code to retrieve the metrics data; and

cause the second updated page to depict the metrics data.

4 . The system of claim 1 , wherein the computer-executable instructions, when executed, further cause the processor to:

in response to a selection of the selectable link, call the second function of the source code to retrieve the metrics data;

extract a third function from the source code that instructs the system how to generate a visualization for depicting the metrics data; and

update the second updated page to depict the visualization and the metrics data in the visualization.

5 . The system of claim 1 , wherein the computer-executable instructions, when executed, further cause the processor to:

in response to a selection of the selectable link, call the second function of the source code to retrieve the metrics data;

extract a third function from the source code that instructs the system how to generate a visualization for depicting the metrics data; and

update the second updated page to depict the visualization in a sidebar of the second updated page and the metrics data in the visualization.

6 . The system of claim 1 , wherein the computer-executable instructions, when executed, further cause the processor to:

in response to a selection of the selectable link, call the second function of the source code to retrieve the metrics data;

extract a third function from the source code that instructs the system how to generate a visualization for depicting the metrics data; and

update the second updated page to depict the visualization in a pop-up window and the metrics data in the visualization.

7 . The system of claim 1 , wherein the second updated page further includes a selectable area, wherein the selectable area is configured to cause the display of a second user interface, wherein the second user interface is associated with the observability system.

8 . A computer-implemented method comprising:

receiving a request from a client device to access a page corresponding to events data;

in response to a query for a dataset entered on the page, transmitting, to a server, a request for a storage location of source code for generating a visualization of metrics data that is associated with a geographic region of the dataset;

transmitting, to a content delivery network (CDN), a request for the source code stored at the storage location received from the server;

in response to reception of the source code, inserting the source code in a document object model (DOM) tree of the page, and executing the source code to access a first function;

adding the first function and a second function to a global namespace in response to execution of the DOM tree, wherein the first function is associated with a first type of metric and the second function is associated with a second type of metric;

causing the client device to display an updated page, wherein the updated page depicts one or more events in the events data that satisfy the query;

in response to a selection of a first event in the one or more events: calling the first function using a field name and a field value associated with the first event to determine whether metrics data of the first type associated with at least one of the field name or the field value is present in an observability system, and (ii) calling the second function using the field name and the field value associated with the first event to determine whether metrics data of the second type associated with at least one of the field name or the field value is present in the observability system; and

in response to an indication from the observability system that metrics data of the first type or metrics data of the second type associated with at least one of the field name or the field value is present, causing the client device to display a second updated page, wherein the second updated page depicts the field name, the field value, and a selectable link to view the metrics data in association with the first event.

9 . The computer-implemented method of claim 8 , further comprising receiving the source code in response to the CDN authenticating that the system is allowed access to the source code.

10 . The computer-implemented method of claim 8 , further comprising:

in response to a selection of the selectable link, calling the second function of the source code to retrieve the metrics data; and

causing the second updated page to depict the metrics data.

11 . The computer-implemented method of claim 8 , further comprising:

in response to a selection of the selectable link, calling the second function of the source code to retrieve the metrics data;

extracting a third function from the source code that instructs the system how to generate a visualization for depicting the metrics data; and

updating the second updated page to depict the visualization and the metrics data in the visualization.

12 . The computer-implemented method of claim 8 , further comprising:

in response to a selection of the selectable link, calling the second function of the source code to retrieve the metrics data;

extracting a third function from the source code that instructs the system how to generate a visualization for depicting the metrics data; and

updating the second updated page to depict the visualization in a sidebar of the second updated page and the metrics data in the visualization.

13 . The computer-implemented method of claim 8 , further comprising:

in response to a selection of the selectable link, calling the second function of the source code to retrieve the metrics data;

extracting a third function from the source code that instructs the system how to generate a visualization for depicting the metrics data; and

updating the second updated page to depict the visualization in a pop-up window and the metrics data in the visualization.

14 . A non-transitory, computer-readable medium comprising computer-executable instructions for integrating content related to data generated by a data intake and query system, wherein the computer-executable instructions, when executed by a computer system, cause the computer system to:

process a request from a client device to access a page corresponding to events data;

in response to a query for a dataset entered on the page, transmit, to a server, a request for a storage location of source code for generating a visualization of metrics data that is associated with a geographic region of the dataset;

transmit, to a content delivery network (CDN), a request for the source code stored at the storage location received from the server;

in response to reception of the source code, insert the source code in a document object model (DOM) tree of the page, and execute the source code to access a first function;

add the first function and a second function to a global namespace in response to execution of the DOM tree, wherein the first function is associated with a first type of metric and the second function is associated with a second type of metric;

cause the client device to display an updated page, wherein the updated page depicts one or more events in the events data that satisfy the query;

in response to a selection of a first event in the one or more events: (i) call the first function using a field name and a field value associated with the first event to determine whether metrics data of the first type associated with at least one of the field name or the field value is present in an observability system, and (ii) call the second function using the field name and the field value associated with the first event to determine whether metrics data of the second type associated with at least one of the field name or the field value is present in the observability system; and

in response to an indication from the observability system that metrics data of the first type or metrics data of the second type associated with at least one of the field name or the field value is present, cause the client device to display a second updated page, wherein the second updated page depicts the field name, the field value, and a selectable link to view the metrics data in association with the first event.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2024
From: TORBETT, IAN EDWARD; DROLE, SAMO; MOSHGABADI, AMIN
To: SPLUNK INC.
Reel/Frame 066464/0498 →
References Cited (50)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 11250069B1 · Bianchi et al. · 2022 [cited by applicant]
US 11388211B1 · Breeden et al. · 2022 [cited by applicant]
US 11636160B2 · Bianchi et al. · 2023 [cited by applicant]
US 12026155B2 · Bigdelu · 2024 [cited by examiner]
US 20070239470A1 · Ronen · 2007 [cited by examiner]
US 20080140481A1 · Gold · 2008 [cited by applicant]
US 20090299976A1 · Dexter · 2009 [cited by applicant]
US 20100079488A1 · McGreevy et al. · 2010 [cited by applicant]
US 20110099500A1 · Smith et al. · 2011 [cited by applicant]
US 20140279865A1 · Kumar et al. · 2014 [cited by applicant]
US 20140317130A1 · Thope et al. · 2014 [cited by applicant]
US 20140336786A1 · Asenjo et al. · 2014 [cited by applicant]
US 20150154269A1 · Miller et al. · 2015 [cited by applicant]
US 20150186473A1 · Chen · 2015 [cited by examiner]
US 20160191351A1 · Smith · 2016 [cited by examiner]
US 20160274553A1 · Strohmenger et al. · 2016 [cited by applicant]
US 20160332297A1 · Sugaya · 2016 [cited by applicant]
US 20170078313A1 · Zhong et al. · 2017 [cited by applicant]
US 20180181657A1 · Giardina et al. · 2018 [cited by applicant]
US 20180262708A1 · Lee et al. · 2018 [cited by applicant]
US 20180268578A1 · Wittkopf et al. · 2018 [cited by applicant]
US 20180293304A1 · Miller et al. · 2018 [cited by applicant]
US 20180293327A1 · Miller et al. · 2018 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190245950A1 · Shcherbakov et al. · 2019 [cited by applicant]
US 20190294598A1 · Hsiao et al. · 2019 [cited by applicant]
US 20200019546A1 · Luo et al. · 2020 [cited by applicant]
US 20200067790A1 · Hsiao et al. · 2020 [cited by applicant]
US 20200110793A1 · Sullivan · 2020 [cited by examiner]
US 20200320092A1 · Malak et al. · 2020 [cited by applicant]
US 20250007812A1 · Hulick, Jr. · 2025 [cited by examiner]
US 20250013356A1 · Padhye · 2025 [cited by examiner]
CN 109542385A · 2019 [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Dynatrace.com, “Application Observability,” in 19 pages, Retrieved from dynatrace.com <URL: https://www.dynatrace.com/monitoring/platform/observability-solution/?utm_source=bing&utm_medium=cpc&utm_term=observability%20t… [cited by applicant]
SLAML 10 Reports, Workshop On Managing Systems via Log Analysis and Machine Learning Techniques. ;login: Feb. 2011—Conference Reports—vol. 36, No. 1, pp. 104-110. [cited by applicant]
Splunk.com, “Splexicon,” in 12 pages, Retrieved from Splunk.com <URL: https: https://docs.splunk.com/Splexicon:Source> on Jan. 24, 2024. [cited by applicant]
Splunk Enterprise Overview 8.0.0—splunk > turn data into doing—copyright 2020 Splunk Inc.—in 17 pages—Retrieved from Splunk Documentation <URL: https://docs.splunk.com/Documentationion> on May 20, 2020. [cited by applicant]
Splunk Cloud User Manual 8.0.2004—splunk> turn data in doing—copyright 2020 Splunk Inc.—in 66 pages—Retrieved from Splunk Documentation <URL: https://docs.splunk.com/Documentation> on May 20, 2020. [cited by applicant]
Splunk Observability Cloud, “Welcome to Splunk Observability Cloud,” in 6 pages, Retrieved from Splunk Documentation <URL: https://docs.splunk.com/observability/en/get-started/welcome.html#.˜.text=Splunk%20Observability… [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
U.S. Appl. No. 17/976,688, filed Oct. 28, 2022. [cited by applicant]
Cited By (1)
US 12,651,077