IP Library Granted Patent US 12,681,809
Granted Patent B1
US 12,681,809 · App. 18/505,977 · Granted Jul 14, 2026

Data structure for managing captaincy qualification for search heads

Inventors: Ankit Jain (San Francisco, CA); Manu Jose, Jr. (San Francisco, CA); Bharath Kishore Reddy Aleti (San Francisco, CA); Amritpal Singh Bath (San Francisco, CA); Yuan Xu (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F11/1464G06F11/142G06F11/302G06F11/3089G06F11/3419G06F11/3495G06F16/211G06F16/27H04L41/069H04L43/106
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,681,809
App. No.
18/505,977
Filed
Nov 9, 2023
Granted
Jul 14, 2026
Kind
B1
Examiner
HOANG, KEN
Art Unit
2168
USPC
707/736
Abstract

The provides solutions for determining an elected search head captain is unqualified for the position, identifying a more qualified search head, and transferring the captain position to the more qualified search head. A method is provided that includes referencing qualification parameters in an elected search head captain, determining whether the newly elected search head captain is qualified for the position based on the parameters, identifying a more qualified search head to be the search head captain if the newly elected search head captain is determined to be unqualified for the position, and transferring the position of captain to the more qualified search head. The qualification parameters may include, for example, a pre-determined static flag set by an administrator of the search environment, and configuration replication status that corresponds to the most recent configuration state of the search head as recorded by the previous search head captain.

Claims (31)

1 . A method for managing captaincy qualification for search heads, the method comprising:

in a search head cluster comprising a search head captain and a plurality of search heads of a search environment, receiving, at the search head captain, a periodic communication from each search head of the plurality of search heads in the search environment, wherein the periodic communication comprises a configuration replication status corresponding to a respective search head of the plurality of search heads, and wherein the configuration replication status indicates whether the respective search head qualifies to be the search head captain based on a comparison of a first timestamp of a last configuration replication in the search head captain with a second timestamp of a most recent configuration replication in at least the respective search head, wherein each search head of the plurality of search heads in the search head cluster coordinates with other search heads in the search head cluster to execute searches on one or more indexers comprised within a data intake and query system;

determining a timestamp corresponding to the configuration replication status from the respective search head; and

updating a data structure with the timestamp and the configuration replication status from the respective search head, wherein each of the plurality of search heads is configured to access the data structure to determine if the respective search head is qualified to be the search head captain.

2 . The method of claim 1 , wherein the configuration replication status corresponds to a most recent configuration state of the respective search head.

3 . The method of claim 1 , wherein a first search head of the plurality of search heads that becomes the search head captain of the search head cluster references the data structure to determine if the first search head is qualified to become the search head captain based on the respective configuration replication status as updated by a previous search head captain.

4 . The method of claim 1 , wherein the data structure is implemented as a lookup table.

5 . The method of claim 1 , wherein the data structure is implemented as a key-value structure.

6 . The method of claim 1 , wherein the timestamp corresponding to the configuration replication status is based on a timing associated with a receipt of the periodic communication from the respective search head.

7 . The method of claim 1 , further comprising:

maintaining a persistent communication channel between the search head captain and each of the plurality of search heads for receiving periodic communications, at the search head captain, from each of the plurality of search heads.

8 . The method of claim 7 , wherein the persistent communication channel comprises a heartbeat monitoring thread.

9 . The method of claim 1 , wherein the periodic communication further comprises a preferred captain flag which comprises a static indication of whether the respective search head has been pre-selected by an administrator of the search environment as a preferred search head to be the search head captain for the search head cluster.

10 . The method of claim 1 , wherein the periodic communication further comprises a preferred captain flag, wherein the preferred captain flag comprises a Boolean indication of whether the respective search head has been pre-selected as a preferred search head to be the search head captain for the search head cluster.

11 . The method of claim 1 , wherein the periodic communication further comprises a preferred captain flag, wherein the preferred captain flag comprises a static indication of whether the respective search head has been pre-selected as a preferred search head to be the search head captain for the search head cluster based on at least one of: a physical locality of the preferred search head, and a computing capability of the preferred search head.

12 . The method of claim 1 , wherein the configuration replication status is based on a last interaction between the respective search head and the search head captain of the search head cluster.

13 . The method of claim 1 , wherein the configuration replication status is based on a first timestamp of a last interaction between the respective search head and the search head captain of the search head cluster.

14 . The method of claim 1 , wherein the configuration replication status is indicative of whether a last interaction between the respective search head and the search head captain of the search head cluster exceeds a pre-determined threshold duration.

15 . The method of claim 1 , wherein the configuration replication status is indicative of whether a first timestamp of a last interaction between the respective search head and the search head captain of the search head cluster exceeds a pre-determined threshold duration relative to timestamps of last interactions between other search heads of the search head cluster and the search head captain.

16 . A non-transitory computer-readable medium having computer-readable program code embodied therein for causing a computer system to perform a method for managing captaincy qualification for search heads, the method comprising:

in a search head cluster comprising a search head captain and a plurality of search heads of a search environment, receiving, at the search head captain, a periodic communication from each search head of the plurality of search heads in the search environment, wherein the periodic communication comprises a configuration replication status corresponding to a respective search head of the plurality of search heads, and wherein the configuration replication status indicates whether the respective search head qualifies to be the search head captain based on a comparison of a first timestamp of a last configuration replication in the search head captain with a second timestamp of a most recent configuration replication in at least the respective search head, wherein each search head of the plurality of search heads in the search head cluster coordinates with other search heads in the search head cluster to execute searches on one or more indexers comprised within a data intake and query system;

determining a timestamp corresponding to the configuration replication status from the respective search head; and

updating a data structure with the timestamp and the configuration replication status from the respective search head, wherein each of the plurality of search heads is configured to access the data structure to determine if the respective search head is qualified to be the search head captain.

17 . The non-transitory computer-readable medium of claim 16 , wherein the configuration replication status corresponds to a most recent configuration state of the respective search head.

18 . The non-transitory computer-readable medium of claim 16 , wherein the periodic communication further comprises a preferred captain flag which comprises a static indication of whether the respective search head has been pre-selected by an administrator of the search environment as a preferred search head to be the search head captain for the search head cluster.

19 . The non-transitory computer-readable medium of claim 16 , wherein the data structure is implemented as a lookup table.

20 . A system comprising:

a processing device comprised in a search head captain of a search head cluster of a search environment, wherein the search head cluster comprises a search head captain and a plurality of search heads, the processing device being configured to:

receive a periodic communication from each search head of the plurality of search heads in the search environment, wherein the periodic communication comprises a configuration replication status corresponding to a respective search head of the plurality of search heads, and wherein the configuration replication status indicates whether the respective search head qualifies to be the search head captain based on a comparison of a first timestamp of a last configuration replication in the search head captain with a second timestamp of a most recent configuration replication in at least the respective search head, wherein each search head of the plurality of search heads in the search head cluster coordinates with other search heads in the search head cluster to execute searches on one or more indexers comprised within a data intake and query system;

determine a timestamp corresponding to the configuration replication status from the respective search head; and

update a data structure with the timestamp and the configuration replication status from the respective search head, wherein each of the plurality of search heads is configured to access the data structure to determine if the respective search head is qualified to be the search head captain.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2023
From: JOSE, MANU, JR.; JAIN, ANKIT; ALETI, BHARATH KISHORE REDDY; BATH, AMRITPAL SINGH; XU, YUAN
To: SPLUNK INC.
Reel/Frame 065656/0364 →
Continuity (2)
Continuation 17161480 · Jan 28, 2021
Continuation 15582441 · Apr 28, 2017
References Cited (44)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 7984043B1 · Waas · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8682925B1 · Marquardt et al. · 2014 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 8856583B1 · Visser et al. · 2014 [cited by applicant]
US 9069607B1 · Gopalakrishna Alevoor et al. · 2015 [cited by applicant]
US 9128779B1 · Gladkikh et al. · 2015 [cited by applicant]
US 9130832B1 · Boe et al. · 2015 [cited by applicant]
US 9158811B1 · Choudhary et al. · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10956278B2 · Jain et al. · 2021 [cited by applicant]
US 20060080657A1 · Goodman · 2006 [cited by applicant]
US 20090049010A1 · Bodapati · 2009 [cited by applicant]
US 20090112780A1 · Chen et al. · 2009 [cited by applicant]
US 20100030840A1 · O'Shea et al. · 2010 [cited by applicant]
US 20110045830A1 · Wu · 2011 [cited by applicant]
US 20120059823A1 · Barber et al. · 2012 [cited by applicant]
US 20150046610A1 · Aster · 2015 [cited by examiner]
US 20160034490A1 · Woo · 2016 [cited by examiner]
US 20160034555A1 · Rahut et al. · 2016 [cited by applicant]
US 20160034566A1 · Rahut · 2016 [cited by applicant]
US 20160092558A1 · Ago et al. · 2016 [cited by applicant]
US 20160286564A1 · Berggren et al. · 2016 [cited by applicant]
US 20160366206A1 · Shemer et al. · 2016 [cited by applicant]
US 20170091183A1 · Kenchammana-Hosekote et al. · 2017 [cited by applicant]
US 20170091215A1 · Beard et al. · 2017 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20210149773A1 · Jain et al. · 2021 [cited by applicant]
WO WO2012163211A1 · 2012 [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved on May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved on May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, 6 pages. [cited by applicant]
Carasso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, 156 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”, Vancou… [cited by applicant]
Splunk, Splunk Documentation 6.3 .3 Web.archive.org/web/20160305094905/http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Whatisdistributedsearch, 2016, 134 pages. [cited by applicant]
Loughran, Steve A., “Hadoop and Kerberos: The Madness Beyond the Gate”, http://wwwfreetechbooks.com/hadoop-and-kerberos-themadness-beyond-the-gale-t921.html, Mar. 1, 2016, 98 pages. [cited by applicant]
Sarma et al., “Energy Efficient Clustering Using Jumper Firefly Algorithm in Wireless Sensor Networks”, arXiv preprint 1405.1818, vol. 10, No. 11, 2014, pp. 525-532. [cited by applicant]
Chen et al., “Clustering Algorithms for Ad Hoc Wireless Networks”, Ad hoc and sensor networks, 2004, 17 pages. [cited by applicant]
Fu, Song, “Failure-Aware Resource Management For High-Availability Computing Clusters With Distributed Virtual Machines”, Journal of Parallel and Distributed Computing, vol. 70, 2010, pp. 384-393. [cited by applicant]
Hacker et al., “Flexible Resource Allocation For Reliable Virtual Cluster Computing Systems”, Proceedings of International Conference for High Performance Computing, Networking, Storage and Analysis, Nov. 12-18, 2011, 1… [cited by applicant]