IP Library Granted Patent US 12,670,148
Granted Patent B1
US 12,670,148 · App. 18/434,485 · Granted Jun 30, 2026

Data model selection and application based on data sources

Inventors: Alice Emily Neels (San Francisco, CA); Archana Sulochana Ganapathi (San Francisco, CA); Marc Vincent Robichaud (San Francisco, CA); Stephen Phillip Sorkin (San Francisco, CA); Steve Yu Zhang (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F16/2425G06F3/0482G06F16/245G06F16/24575G06F16/248G06F16/27G06F16/9535G06F40/186
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,670,148
App. No.
18/434,485
Granted
Jun 30, 2026
Kind
B1
Abstract

Embodiments include generating data models that may give semantic meaning for unstructured or structured data that may include data generated and/or received by search engines, including a time series engine. A method includes generating a data model for data stored in a repository. Generating the data model includes generating an initial query string, executing the initial query string on the data, generating an initial result set based on the initial query string being executed on the data, determining one or more candidate fields from one or results of the initial result set, generating a candidate data model based on the one or more candidate fields, iteratively modifying the candidate data model until the candidate data model models the data, and using the candidate data model as the data model.

Claims (32)

1 . A computer-implemented method, comprising:

generating a result set from data stored in a data repository using a query string, wherein the data stored in the data repository comprises a plurality of time-stamped, searchable events including a portion of unstructured raw machine data reflecting activity in an information technology environment;

determining a plurality of candidate data model object fields based upon the result set;

generating groupings for the plurality of candidate data model object fields based upon at least one field commonality among the plurality of candidate data model object fields of the result set; and

generating, using the result set from the query string, a data model that defines semantic meaning for at least a portion of the data stored in the data repository, that is maintained in an unmodified form, based upon the groupings for the plurality of candidate data model object fields determined based on the result set corresponding with the query string.

2 . The computer-implemented method of claim 1 , wherein determining the plurality of candidate data model object fields comprises causing a graphical user interface to be displayed that includes a list of candidate data model object fields, wherein the plurality of candidate data model object fields are selected from the list of candidate data model object fields via the graphical user interface.

3 . The computer-implemented method of claim 1 , wherein determining the plurality of candidate data model object fields comprises identifying a plurality of candidate field names in an unstructured data record corresponding to the result set.

4 . The computer-implemented method of claim 1 , wherein generating the data model based upon the groupings for the plurality of candidate data model object fields comprises iteratively modifying the groupings or the plurality of candidate data model object fields.

5 . The computer-implemented method of claim 1 , wherein determining the groupings of the plurality of candidate data model object fields comprises identifying records in the result set having at least one common field.

6 . The computer-implemented method of claim 1 , wherein determining the groupings of the plurality of candidate data model object fields comprises mapping at least one common field in the plurality of candidate data model object fields to a field in the data model.

7 . The computer-implemented method of claim 1 , further comprising identifying a parent-child relationship between records in the result set having one or more fields in common, wherein the parent-child relationship between the records is mapped to a field in the data model.

8 . The computer-implemented method of claim 1 , wherein determining the groupings of the plurality of candidate data model object fields comprises identifying a plurality of records associated with a single information technology event in the result set.

9 . The computer-implemented method of claim 1 , wherein generating the result set comprises identifying results based upon a report template and determining the plurality of candidate data model object fields based upon the result set comprises mapping the result set for a plurality of fields specified in the report template.

10 . One or more non-transitory computer readable media storing instructions that, when executed by one or more processors, cause the one or more processors to perform steps of:

generating a result set from data stored in a data repository using a query string, wherein the data stored in the data repository comprises a plurality of time-stamped, searchable events including a portion of unstructured raw machine data reflecting activity in an information technology environment;

determining a plurality of candidate data model object fields based upon the result set;

generating groupings for the plurality of candidate data model object fields based upon at least one field commonality among the plurality of candidate data model object fields of the result set; and

generating, using the result set from the query string, a data model that defines semantic meaning for at least a portion of the data stored in the data repository, that is maintained in an unmodified form, based upon the groupings for the plurality of candidate data model object fields determined based on the result set corresponding with the query string.

11 . The one or more non-transitory computer readable media of claim 10 , wherein determining the plurality of candidate data model object fields comprises causing a graphical user interface to be displayed that includes a list of candidate data model object fields, wherein the plurality of candidate data model object fields are selected from the list of candidate data model object fields via the graphical user interface.

12 . The one or more non-transitory computer readable media of claim 10 , wherein determining the plurality of candidate data model object fields comprises identifying a plurality of candidate field names in an unstructured data record corresponding to the result set.

13 . The one or more non-transitory computer readable media of claim 10 , wherein determining the groupings of the plurality of candidate data model object fields comprises identifying records in the result set having at least one common field.

14 . The one or more non-transitory computer readable media of claim 10 , wherein determining the groupings of the plurality of candidate data model object fields comprises mapping at least one common field in the plurality of candidate data model object fields to a field in the data model.

15 . The one or more non-transitory computer readable media of claim 10 , further comprising identifying a parent-child relationship between records in the result set having one or more fields in common, wherein the parent-child relationship between the records is mapped to a field in the data model.

16 . The one or more non-transitory computer readable media of claim 10 , wherein generating the result set comprises identifying results based upon a report template and determining the plurality of candidate data model object fields based upon the result set comprises mapping the result set for a plurality of fields specified in the report template.

17 . The one or more non-transitory computer readable media of claim 10 , further comprising generating a pivot report based upon the result set and the data model, wherein the data model specifies a cell calculation extracted from a report template.

18 . A computer system, comprising:

one or more memories; and

one or more processors for:

generating a result set from data stored in a data repository using a query string, wherein the data stored in the data repository comprises a plurality of time-stamped, searchable events including a portion of unstructured raw machine data reflecting activity in an information technology environment;

determining a plurality of candidate data model object fields based upon the result set;

generating groupings for the plurality of candidate data model object fields based upon at least one field commonality among the plurality of candidate data model object fields of the result set; and

generating, using the result set from the query string, a data model that defines semantic meaning for at least a portion of the data stored in the data repository, that is maintained in an unmodified form, based upon the groupings for the plurality of candidate data model object fields determined based on the result set corresponding with the query string.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2024
From: NEELS, ALICE EMILY; GANAPATHI, ARCHANA SULOCHANA; ROBICHAUD, MARCO VINCENT; SORKIN, STEPHEN PHILLIP; ZHANG, STEVE YU
To: SPLUNK INC.
Reel/Frame 067702/0254 →
Continuity (7)
Continuation 17734786 · May 2, 2022
Continuation 16204989 · Nov 29, 2018
Continuation 15421415 · Jan 31, 2017
Continuation 14815884 · Jul 31, 2015
Continuation 14611232 · Jan 31, 2015
Continuation 14067203 · Oct 30, 2013
Continuation 13607117 · Sep 7, 2012
References Cited (190)
US 5550971A · Brunner et al. · 1996 [cited by applicant]
US 5999933A · Mehta · 1999 [cited by applicant]
US 6205498B1 · Habusha et al. · 2001 [cited by applicant]
US 6208638B1 · Rieley et al. · 2001 [cited by applicant]
US 6484162B1 · Edlund et al. · 2002 [cited by applicant]
US 6650346B1 · Jaeger et al. · 2003 [cited by applicant]
US 6704688B2 · Aslam et al. · 2004 [cited by applicant]
US 7076482B2 · Bellew · 2006 [cited by applicant]
US 7529642B2 · Raymond · 2009 [cited by applicant]
US 7562069B1 · Chowdhury et al. · 2009 [cited by applicant]
US 7640496B1 · Chaulk · 2009 [cited by examiner]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8031634B1 · Artzi et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8380698B2 · Sundaranatha · 2013 [cited by applicant]
US 8412696B2 · Zhang et al. · 2013 [cited by applicant]
US 8422786B2 · Chenthamarakshan et al. · 2013 [cited by applicant]
US 8442982B2 · Jacobson et al. · 2013 [cited by applicant]
US 8516008B1 · Marquardt et al. · 2013 [cited by applicant]
US 8548973B1 · Kritt et al. · 2013 [cited by applicant]
US 8589403B2 · Marquardt et al. · 2013 [cited by applicant]
US 8682925B1 · Marquardt et al. · 2014 [cited by applicant]
US 8700658B2 · Rambhia et al. · 2014 [cited by applicant]
US 8707194B1 · Jenkins et al. · 2014 [cited by applicant]
US 8713000B1 · Elman et al. · 2014 [cited by applicant]
US 8725756B1 · Garg et al. · 2014 [cited by applicant]
US 8751486B1 · Neeman et al. · 2014 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8770658B2 · Grimm et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 8788526B2 · Neels et al. · 2014 [cited by applicant]
US 8868591B1 · Finkelstein et al. · 2014 [cited by applicant]
US 8910084B2 · Helfman et al. · 2014 [cited by applicant]
US 8983994B2 · Neels et al. · 2015 [cited by applicant]
US 9098497B1 · Brette · 2015 [cited by examiner]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9509765B2 · Pal et al. · 2016 [cited by applicant]
US 9569511B2 · Morin · 2017 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 20010018689A1 · Spence et al. · 2001 [cited by applicant]
US 20010023414A1 · Kumar et al. · 2001 [cited by applicant]
US 20010048374A1 · Blad · 2001 [cited by applicant]
US 20020054101A1 · Beatty · 2002 [cited by applicant]
US 20020181496A1 · Narasimhan et al. · 2002 [cited by applicant]
US 20030131215A1 · Bellew · 2003 [cited by applicant]
US 20030163463A1 · Cain · 2003 [cited by applicant]
US 20030187821A1 · Cotton et al. · 2003 [cited by applicant]
US 20030197743A1 · Hill · 2003 [cited by examiner]
US 20040078359A1 · Bolognese et al. · 2004 [cited by applicant]
US 20040111410A1 · Burgoon et al. · 2004 [cited by applicant]
US 20040181526A1 · Burdick et al. · 2004 [cited by applicant]
US 20040186826A1 · Choi et al. · 2004 [cited by applicant]
US 20040220965A1 · Harville et al. · 2004 [cited by applicant]
US 20040221226A1 · Lin et al. · 2004 [cited by applicant]
US 20040225641A1 · Dettinger et al. · 2004 [cited by applicant]
US 20040254919A1 · Giuseppini · 2004 [cited by applicant]
US 20040267770A1 · Lee · 2004 [cited by applicant]
US 20050015363A1 · Dessloch et al. · 2005 [cited by applicant]
US 20050050540A1 · Shaughnessy et al. · 2005 [cited by applicant]
US 20050182703A1 · D'hers et al. · 2005 [cited by applicant]
US 20050192921A1 · Chaudhuri · 2005 [cited by examiner]
US 20050203876A1 · Cragun et al. · 2005 [cited by applicant]
US 20050234894A1 · Tenazas · 2005 [cited by applicant]
US 20060004826A1 · Zartler et al. · 2006 [cited by applicant]
US 20060026145A1 · Beringer et al. · 2006 [cited by applicant]
US 20060041539A1 · Matchett et al. · 2006 [cited by applicant]
US 20060048101A1 · Krassovsky et al. · 2006 [cited by applicant]
US 20060053174A1 · Gardner et al. · 2006 [cited by applicant]
US 20060074621A1 · Rachman · 2006 [cited by applicant]
US 20060106763A1 · Dirisala · 2006 [cited by applicant]
US 20060112123A1 · Clark et al. · 2006 [cited by applicant]
US 20060123010A1 · Landry et al. · 2006 [cited by applicant]
US 20060136470A1 · Dettinger · 2006 [cited by examiner]
US 20060143159A1 · Chowdhury et al. · 2006 [cited by applicant]
US 20060148550A1 · Nee, Jr. et al. · 2006 [cited by applicant]
US 20060161816A1 · Gula et al. · 2006 [cited by applicant]
US 20060206454A1 · Forstall et al. · 2006 [cited by applicant]
US 20060248087A1 · Agrawal et al. · 2006 [cited by applicant]
US 20060253423A1 · McLane et al. · 2006 [cited by applicant]
US 20060259474A1 · Granito · 2006 [cited by applicant]
US 20060293979A1 · Cash et al. · 2006 [cited by applicant]
US 20070073743A1 · Bammi et al. · 2007 [cited by applicant]
US 20070078822A1 · Cucerzan · 2007 [cited by examiner]
US 20070078872A1 · Cohen · 2007 [cited by applicant]
US 20070112733A1 · Beyer et al. · 2007 [cited by applicant]
US 20070118491A1 · Baum et al. · 2007 [cited by applicant]
US 20070130111A1 · Stoudt · 2007 [cited by examiner]
US 20070198501A1 · Sundaranatha · 2007 [cited by applicant]
US 20070209080A1 · Ture et al. · 2007 [cited by applicant]
US 20070214164A1 · MacLennan et al. · 2007 [cited by applicant]
US 20070259709A1 · Kelly et al. · 2007 [cited by applicant]
US 20080059420A1 · Hsu et al. · 2008 [cited by applicant]
US 20080091690A1 · Ellersick · 2008 [cited by examiner]
US 20080104542A1 · Cohen et al. · 2008 [cited by applicant]
US 20080184110A1 · Barsness et al. · 2008 [cited by applicant]
US 20080215546A1 · Baum et al. · 2008 [cited by applicant]
US 20080222125A1 · Chowdhury et al. · 2008 [cited by applicant]
US 20080228743A1 · Kusnitz et al. · 2008 [cited by applicant]
US 20080270366A1 · Frank · 2008 [cited by applicant]
US 20080301095A1 · Zhu et al. · 2008 [cited by applicant]
US 20080319965A1 · Dettinger et al. · 2008 [cited by applicant]
US 20090013281A1 · Helfman et al. · 2009 [cited by applicant]
US 20090019020A1 · Dhillon et al. · 2009 [cited by applicant]
US 20090055370A1 · Dagum et al. · 2009 [cited by applicant]
US 20090069739A1 · Mohamed · 2009 [cited by applicant]
US 20090085769A1 · Thubert et al. · 2009 [cited by applicant]
US 20090094521A1 · Hung · 2009 [cited by examiner]
US 20090125546A1 · Iborra et al. · 2009 [cited by applicant]
US 20090182866A1 · Watanabe et al. · 2009 [cited by applicant]
US 20090300065A1 · Birchall · 2009 [cited by applicant]
US 20090319512A1 · Baker et al. · 2009 [cited by applicant]
US 20090326924A1 · Crider et al. · 2009 [cited by applicant]
US 20090327319A1 · Bertram et al. · 2009 [cited by applicant]
US 20100095018A1 · Khemani et al. · 2010 [cited by applicant]
US 20100100562A1 · Millsap · 2010 [cited by applicant]
US 20100161677A1 · Zurek et al. · 2010 [cited by applicant]
US 20100182321A1 · Cartan · 2010 [cited by applicant]
US 20100251100A1 · Delacourt · 2010 [cited by applicant]
US 20100275024A1 · Abdulhayoglu · 2010 [cited by applicant]
US 20100290617A1 · Nath · 2010 [cited by applicant]
US 20100299135A1 · Fritsch et al. · 2010 [cited by applicant]
US 20100306281A1 · Williamson · 2010 [cited by applicant]
US 20100332661A1 · Tameshige · 2010 [cited by applicant]
US 20110066585A1 · Subrahmanyam et al. · 2011 [cited by applicant]
US 20110082884A1 · Hollingsworth · 2011 [cited by applicant]
US 20110154296A1 · Marenco · 2011 [cited by applicant]
US 20110191373A1 · Botros et al. · 2011 [cited by applicant]
US 20110196851A1 · Vadlamani et al. · 2011 [cited by applicant]
US 20110218978A1 · Hong et al. · 2011 [cited by applicant]
US 20110235909A1 · Chenthamarakshan · 2011 [cited by examiner]
US 20110307905A1 · Essey et al. · 2011 [cited by applicant]
US 20110320459A1 · Chisholm · 2011 [cited by applicant]
US 20120079363A1 · Folting et al. · 2012 [cited by applicant]
US 20120117116A1 · Jacobson et al. · 2012 [cited by applicant]
US 20120120078A1 · Hubbard · 2012 [cited by applicant]
US 20120124503A1 · Coimbatore et al. · 2012 [cited by applicant]
US 20120159370A1 · Rode et al. · 2012 [cited by applicant]
US 20120185441A1 · Sankar et al. · 2012 [cited by applicant]
US 20120278336A1 · Malik et al. · 2012 [cited by applicant]
US 20120283948A1 · Demiryurek et al. · 2012 [cited by applicant]
US 20120284713A1 · Ostermeyer et al. · 2012 [cited by applicant]
US 20120296876A1 · Bacinschi et al. · 2012 [cited by applicant]
US 20120296878A1 · Nakae et al. · 2012 [cited by applicant]
US 20120324448A1 · Huetter et al. · 2012 [cited by applicant]
US 20130041824A1 · Gupta · 2013 [cited by applicant]
US 20130047270A1 · Lowery et al. · 2013 [cited by applicant]
US 20130054642A1 · Morin · 2013 [cited by examiner]
US 20130060912A1 · Rensin et al. · 2013 [cited by applicant]
US 20130073957A1 · Digiantomasso et al. · 2013 [cited by applicant]
US 20130080190A1 · Mansour et al. · 2013 [cited by applicant]
US 20130247133A1 · Price et al. · 2013 [cited by applicant]
US 20130262371A1 · Nolan · 2013 [cited by applicant]
US 20130311438A1 · Marquardt et al. · 2013 [cited by applicant]
US 20130318236A1 · Coates et al. · 2013 [cited by applicant]
US 20130318603A1 · Merza · 2013 [cited by applicant]
US 20130325840A1 · Kritt · 2013 [cited by examiner]
US 20130325893A1 · Asay et al. · 2013 [cited by applicant]
US 20130326620A1 · Merza et al. · 2013 [cited by applicant]
US 20140019448A1 · Leonard et al. · 2014 [cited by applicant]
US 20140019909A1 · Leonard et al. · 2014 [cited by applicant]
US 20140046976A1 · Zhang et al. · 2014 [cited by applicant]
US 20140074591A1 · Allen · 2014 [cited by examiner]
US 20140074887A1 · Neels et al. · 2014 [cited by applicant]
US 20140074889A1 · Neels et al. · 2014 [cited by applicant]
US 20140160238A1 · Mm et al. · 2014 [cited by applicant]
US 20140236889A1 · Vasan et al. · 2014 [cited by applicant]
US 20140236890A1 · Vasan et al. · 2014 [cited by applicant]
US 20140280894A1 · Reynolds et al. · 2014 [cited by applicant]
US 20140324862A1 · Bingham et al. · 2014 [cited by applicant]
US 20150019537A1 · Neels et al. · 2015 [cited by applicant]
US 20150026167A1 · Neels et al. · 2015 [cited by applicant]
US 20150169736A1 · MacPherson et al. · 2015 [cited by applicant]
US 20150278153A1 · Leonard et al. · 2015 [cited by applicant]
US 20150339344A1 · Neels et al. · 2015 [cited by applicant]
US 20160140743A1 · Neels et al. · 2016 [cited by applicant]
US 20160217599A1 · Neels et al. · 2016 [cited by applicant]
US 20160246495A1 · Neels et al. · 2016 [cited by applicant]
US 20160321369A1 · Neels et al. · 2016 [cited by applicant]
US 20190095062A1 · Neels et al. · 2019 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, 156 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”, Vancou… [cited by applicant]
http://docs.splunk.com/Documentation/PCI/2.1.1/ [000119] User/IncidentReviewdashboard, Last accessed, Aug. 5, 2014, 2 pages. [cited by applicant]
vSphere Monitoring and Performance, VMware, Inc., Update 1, vSphere 5.5, EN-001357-02, http://pubs. vmware .com/ vsphere-55/topic/com. vmware.ICbase/PDF/ vsphere-esxi-vcenter- server- 551-mon itoring-performance-guide.p… [cited by applicant]
Manning, Christopher D., “Introduction to Information Retrieval”, Cambridge University Press, Chapter 1, May 27, 2008, 504 pages. [cited by applicant]
Cohen et al., “MAD Skills: New Analysis Practices For Big Data”, Aug. 28, 2009, Proceedings of the VLDB Endowment, vol. 2, No. 2, Aug. 2009, pp. 1481-1492. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved on May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved on May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, 6 pages. [cited by applicant]